Skip to content

Add workflow for OpenSSF Scorecard #862

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

mhucka
Copy link
Member

@mhucka mhucka commented Feb 21, 2025

Scorecard (https://github.com/ossf/scorecard) is an automated tool that assesses a number of important checks associated with software security and assigns each check a score of 0-10. It creates a report at https://scorecard.dev/viewer/?uri=github.com/tensorflow/quantum

Scorecard (https://github.com/ossf/scorecard) is an automated tool
that assesses a number of important checks associated with software
security and assigns each check a score of 0-10. It creates a report
at https://scorecard.dev/viewer/?uri=github.com/tensorflow/quantum
@mhucka mhucka marked this pull request as ready for review February 21, 2025 04:26
@mhucka mhucka enabled auto-merge February 21, 2025 04:26
Copy link
Collaborator

@MichaelBroughton MichaelBroughton left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure security is a huge priority for a library that is so research driven, but this seems simple enough so LGTM.

# Scorecard is an automated tool that assesses a number of important heuristics
# associated with software security and assigns each check a score of 0-10. The
# use of Scorecard is suggested in Google's internal GitHub guidance
# (go/github-docs).
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove internal links.

@mhucka
Copy link
Member Author

mhucka commented Apr 21, 2025

Closing this because I've reworked this and related workflows. Will open a new PR.

@mhucka mhucka closed this Apr 21, 2025
auto-merge was automatically disabled April 21, 2025 22:47

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants