ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.41k stars 484 forks source link

What's the main difference between Scorecard and SLSA? #1839

Closed fredgan closed 2 years ago

fredgan commented 2 years ago

Hi, For the Scorecard said:

We created Scorecards to give consumers of open-source projects an easy way to judge whether their dependencies are safe.

For the SLSA said:

SLSA levels are like a common language to talk about how secure software, supply chains and their component parts really are.

It seems like they are alike. If so, why both are introduced? Which should be used to the user? Thanks~

github-actions[bot] commented 2 years ago

Stale issue message