Closed laurentsimon closed 8 months ago
We (scorecard team) run scorecard weekly on 200k repos.
This documentation proposes an alternative: let repo owners run scorecard in a GitHub workflow. How do we trust the results then?
This is what the proposal is about, by using OIDC flow.
Great idea! This should help us a lot with scaling!
Assigning to @asraa since she's helping with this.
This issue is stale because it has been open for 60 days with no activity.
We (scorecard team) run scorecard weekly on 200k repos.
This documentation proposes an alternative: let repo owners run scorecard in a GitHub workflow. How do we trust the results then?
This is what the proposal is about, by using OIDC flow.