mitre / hipcheck

Automatically assess and score software repositories for supply chain risk.
https://mitre.github.io/hipcheck/
Apache License 2.0
62 stars 3 forks source link

Dogfood Hipcheck by running it against our own dependencies #172

Open alilleybrinker opened 2 months ago

alilleybrinker commented 2 months ago

(This would likely be made easier by landing #171 first)

To prove out the value of Hipcheck, we ought to, perhaps in CI or on some regular cadence, run Hipcheck against its own dependencies. This would help us to gather more hands-on experience with using Hipcheck "in production," and also show our belief in the value of Hipcheck to maintainers.