Tool
OpenSSF Scorecard is an open-source security assessment tool developed as part of the Open Source Security Foundation. It evaluates open-source projects and dependencies for software supply-chain risks through automated checks covering source code, build processes, dependencies, testing, and project maintenance. Each check produces a score and risk level, which are combined into an aggregate security-posture score with remediation guidance. Scorecard can run automatically through a GitHub Action on repositories a user controls or manually through its command-line interface, which can assess other repositories and allows users to select checks and control result detail.
1 use taken from transcripts — each links to the moment in the video.
Provides automated checks used in a software delivery pipeline to evaluate open-source security practices.
1 in the library.