Issues
- 3
CI check to check the results of CI tests
#4191 opened by CsatariGergely - 5
- 1
restore ability to see individual PR results for SAST and Code-Review and document it
#4245 opened by spencerschrock - 3
Feature: scorecard.Run() should accept an http.RoundTripper to be used for all outgoing http requests
#4256 opened by jeffmendoza - 3
Feature scorecard.Run() should take a leveled logging object/interface instead of or alternatively to log level.
#4257 opened by jeffmendoza - 2
Update Code Section Format in Readme
#4272 opened by Jordin221 - 1
Proposal: Align Scorecard checks with S2C2F Maturity Level 2 requirements
#4296 opened by adriandiglio - 2
- 1
- 3
- 1
Apparently GlobaLeaks CI-Tests seems not recognized.
#4393 opened by evilaliv3 - 1
Idea: Add some more projects to /projects.csv
#4392 opened by hejjoe - 1
OpenSSF Scorecard report viewer does not handle nested gitlab groups correctly
#4402 opened by stexandev - 1
Proposal: Improved experience for large-scale (multi-org, multi-repo) deployment of Scorecard
#4339 opened by lelia - 4
Feature: Check custom CII Best Practices URL
#4315 opened by jmgate - 1
Wrong link in /docs/checks.md file
#4362 opened by AleX04Nov - 2
BUG Pinned Dependency checks for nuget/.Net does not consider implicit restore
#4381 opened by balteravishay - 2
- 0
Feature: Checks should support powershell scripts
#4253 opened by balteravishay - 0
Support Composer (PHP) Package Manager
#4378 opened by maennchen - 0
- 2
Feature: Document whether scorecard should be used as a requirement for organizations consuming OSS
#4219 opened by sudo-bmitch - 1
Public GH repo is getting 422 Validation Failed
#4352 opened by diberry - 3
- 0
- 2
Feature: Recognize Woodpecker-CI as a well-known CI
#4210 opened by 6543 - 2
- 2
- 2
Feature: support gitea forge
#4209 opened by 6543 - 2
BUG: Missing data for repository
#4329 opened by nitrocode - 1
Revisit scoring for Security Policy check
#4215 opened by justaugustus - 2
Feature: Support for Azure DevOps
#4177 opened by JamieMagee - 2
- 0
BUG: CI-Tests and SAST internal error for private repository, full permissions granted
#4307 opened by byangtri - 1
Internal Go error when scanning a package internal to my own gitlab instance
#4303 opened by andrew-lovato - 1
Investigate GitHub commit status failures
#4273 opened by spencerschrock - 2
Incorrectly formatted example link
#4247 opened by JeremiahAHoward - 1
- 2
BUG: Contributor check can be false positive
#4175 opened by Zxilly - 1
- 3
Add Adrianne Marcum (@afmarcum) as a triager
#4205 opened by justaugustus - 3
BUG githubrepo.Client.GetOrgRepoClient() does not use parent Client transport
#4255 opened by jeffmendoza - 1
- 5
- 3
CI-Tests doesn't support Azure Pipelines
#4185 opened by gdong1 - 4
BUG Sonarcloud not detected consistently
#4237 opened by matmair - 3
Bug: tools/go.mod has invalid Go version 1.22
#4241 opened by jpmcb - 1
BUG - Pinned-Dependencies has false positive on multi-stage Dockerfile
#4220 opened by fproulx-boostsecurity - 5
- 1
BUG: scroreboard cannot recognize the GitHub Attestations
#4174 opened by Zxilly