dvidelabs / flatcc

FlatBuffers Compiler and Library in C for C
Apache License 2.0
631 stars 180 forks source link

Improve Github repository security #276

Closed bjosv closed 2 months ago

bjosv commented 2 months ago

This PR updates our CI setup according to the secure software development best practices recommended by the Open Source Security Foundation (OpenSSF). The overall goal is to strengthen the (supply chain) security posture.

The following changes are included:

For future reference, additional Github guidelines and info about permissions.

mikkelfj commented 2 months ago

Excellent and very timely wrt. xz ...

bjosv commented 2 months ago

Yes, xz is somewhat an eye-opener..for me atleast.

These changes seems to improve OpenSSF scorecard from Aggregate score: 4.2 / 10 to Aggregate score: 6.5 / 10 (using public data), quite ok.

mikkelfj commented 2 months ago

@bjosv Prophetic, look at the date: https://www.youtube.com/watch?v=9qljpi5jiMQ&t=875s

bjosv commented 2 months ago

Wow :) Thanks for the link, I didn't know the history with Azure Pipelines. So that's the reason for some weirdness..