kelektiv / node-cron

Cron for NodeJS.
MIT License
8.4k stars 621 forks source link

improve repo's ossf scorecard's score #714

Closed sheerlox closed 10 months ago

sheerlox commented 11 months ago

Scorecard is an automated tool that assesses a number of important heuristics ("checks") associated with software security and assigns each check a score of 0-10. You can use these scores to understand specific areas to improve in order to strengthen the security posture of your project. You can also assess the risks that dependencies introduce, and make informed decisions about accepting these risks, evaluating alternative solutions, or working with the maintainers to make improvements.

We are currently scoring 5.3/10:

OpenSSF Scorecard

Find below the checks we need to improve on and the associated remediation steps.

Poor scoring checks

image

How to improve check scores

sheerlox commented 11 months ago

@intcreator could you please try to install the Renovate app to the repository? I think you might have the necessary rights.

I'll prepare a PR for all the other points, which should get our score up to about 9.

sheerlox commented 11 months ago

also regarding the security policy, we'd need an email address and PGP key accessible to the (main) maintainers. I'm unsure how to go about this, please let me know if you have any ideas!

ncb000gt commented 10 months ago

:tada: This issue has been resolved in version 3.1.5 :tada:

The release is available on:

Your semantic-release bot :package::rocket: