Issues
- 8
- 2
- 4
- 4
Unlicense not accepted as FSF or OSI approved
#4144 opened - 3
- 6
Add @lelia as triager
#4136 opened - 1
- 1
- 3
Why stepsecurity is refereneced so much?
#4081 opened - 5
- 1
Feature: Recognize Cirrus-CI as a well-known CI
#4075 opened - 1
Feature: Service Status Page
#4074 opened - 4
✨Creating the Scorecard Universe ✨
#4073 opened - 1
- 4
BUG: Unrecognized CI/CDs
#4050 opened - 3
- 3
BUG: Patch Maintainers Annotations
#4048 opened - 3
- 7
BUG: Code-Review missing review markers
#4038 opened - 4
- 4
- 2
Cleanup old error names before full v5 release
#4033 opened - 4
- 7
update the SPDX license list
#4031 opened - 3
- 1
Specify a user agent for OSV.dev
#4029 opened - 1
the `Signed-Releases` remediation steps encourage manual manipulation of the source code archives
#4018 opened - 1
Contribution account age as a factor
#4000 opened - 1
BUG: Issues with contributor scoring
#3996 opened - 9
- 4
- 2
- 5
OpenSSF - CII Best Practices badge not detected
#3983 opened - 4
CI-tests used in Ledmon project was not detected
#3976 opened - 1
- 4
Add @LappleApple as triager
#3962 opened - 2
- 3
Feature: Add machine-readable remediation to the hasDangerousWorkflowScriptInjection probe
#3950 opened - 1
- 2
- 5
- 3
- 2
BUG docs haven't been updated to say that Signed-Releases looks for `.sigstore` bundles.
#3914 opened - 6
- 0
Feature: Skip .git folder in localdir client
#3908 opened - 0
cleanup branch protection tests
#3904 opened - 4
scorecard started reducing score for vulnerabilities in unrelated packages that aren't imported
#3891 opened - 3
Supporting Spack package manager
#3873 opened - 5
BUG: License LGPL-2.1-only not discovered
#3869 opened - 2