[php-src] Issue #9778: Add the OpenSSF Scorecard GitHub Action
| From: | pnacht | Date: | Tue, 18 Oct 2022 21:00:52 +0000 |
| Subject: | [php-src] Issue #9778: Add the OpenSSF Scorecard GitHub Action | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-242625@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/9778
Author: pnacht
### Description
Hello, I'm working on behalf of Google and the [Open Source Security Foundation][ossf] to help
essential open-source projects improve their supply-chain security. Given how crucial PHP is to the
modern internet, the OpenSSF has naturally identified it as one of the 100 most critical open source
projects.
I saw the oss-fuzz badge on your README. oss-fuzz is just one of many tools Google and the OpenSSF
have developed to improve the safety of the open-source community.
Would you consider adopting another OpenSSF tool called [Scorecards][sc]? Scorecards runs dozens of
automated security [checks][checks] to help maintainers better understand their project's
supply-chain security posture. It is most commonly adopted as the [Scorecard GitHub Action][sc-gha].
It is lightweight and runs on every change to the repository's main branch. The results of its
checks are available on the project's [security
dashboard](https://github.com/php/php-src/security), and include suggestions on how to solve any
issues (see an example below). This Action has been adopted by 1800+ projects already, having some
prominent users like [Tensorflow][tensorflow], [Angular][angular] and [Flutter][flutter].
Would you be interested in a PR that adds this Action? Optionally, it can also publish your results
to the OpenSSF REST API, which allows a [badge][badge] with the project's score to be added to
its README.
In case of doubts or concerns you can check out the [Scorecards FAQ][faq]. Anyway, feel free to
reach me out.
![Detail of a Token-Permissions alert, indicating the specific file and remediation
steps][img-detail]
[angular]: https://github.com/angular/angular
[badge]: https://openssf.org/blog/2022/09/08/show-off-your-security-score-announcing-scorecards-badges/
[checks]: https://github.com/ossf/scorecard#scorecard-checks
[ossf]: https://openssf.org/
[sc]: https://github.com/ossf/scorecard
[sc-blog]: https://github.blog/2022-01-19-reducing-security-risk-oss-actions-opensff-scorecards-v4/
[sc-gha]: https://github.com/ossf/scorecard-action
[faq]: https://github.com/ossf/scorecard/blob/main/docs/faq.md#frequently-asked-questions
[flutter]: https://github.com/flutter/flutter
[tensorflow]: https://github.com/tensorflow/tensorflow
[img-detail]: https://user-images.githubusercontent.com/15221358/190184600-ee8d3b39-077e-416a-8711-1b5fb01cf0b3.png