[php-src] Issue #9778: Add the OpenSSF Scorecard GitHub Action

From: Date: Tue, 18 Oct 2022 21:00:52 +0000
Subject: [php-src] Issue #9778: Add the OpenSSF Scorecard GitHub Action
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242625@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9778 Author: pnacht ### Description Hello, I'm working on behalf of Google and the [Open Source Security Foundation][ossf] to help essential open-source projects improve their supply-chain security. Given how crucial PHP is to the modern internet, the OpenSSF has naturally identified it as one of the 100 most critical open source projects. I saw the oss-fuzz badge on your README. oss-fuzz is just one of many tools Google and the OpenSSF have developed to improve the safety of the open-source community. Would you consider adopting another OpenSSF tool called [Scorecards][sc]? Scorecards runs dozens of automated security [checks][checks] to help maintainers better understand their project's supply-chain security posture. It is most commonly adopted as the [Scorecard GitHub Action][sc-gha]. It is lightweight and runs on every change to the repository's main branch. The results of its checks are available on the project's [security dashboard](https://github.com/php/php-src/security), and include suggestions on how to solve any issues (see an example below). This Action has been adopted by 1800+ projects already, having some prominent users like [Tensorflow][tensorflow], [Angular][angular] and [Flutter][flutter]. Would you be interested in a PR that adds this Action? Optionally, it can also publish your results to the OpenSSF REST API, which allows a [badge][badge] with the project's score to be added to its README. In case of doubts or concerns you can check out the [Scorecards FAQ][faq]. Anyway, feel free to reach me out. ![Detail of a Token-Permissions alert, indicating the specific file and remediation steps][img-detail] [angular]: https://github.com/angular/angular [badge]: https://openssf.org/blog/2022/09/08/show-off-your-security-score-announcing-scorecards-badges/ [checks]: https://github.com/ossf/scorecard#scorecard-checks [ossf]: https://openssf.org/ [sc]: https://github.com/ossf/scorecard [sc-blog]: https://github.blog/2022-01-19-reducing-security-risk-oss-actions-opensff-scorecards-v4/ [sc-gha]: https://github.com/ossf/scorecard-action [faq]: https://github.com/ossf/scorecard/blob/main/docs/faq.md#frequently-asked-questions [flutter]: https://github.com/flutter/flutter [tensorflow]: https://github.com/tensorflow/tensorflow [img-detail]: https://user-images.githubusercontent.com/15221358/190184600-ee8d3b39-077e-416a-8711-1b5fb01cf0b3.png

« previous php.bugs (#242625) next »