ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.46k stars 489 forks source link

Feature: map checks to CIS supply-chain security benchmark #2028

Open laurentsimon opened 2 years ago

laurentsimon commented 2 years ago

See this guide https://github.com/aquasecurity/chain-bench/blob/main/docs/CIS-Software-Supply-Chain-Security-Guide-v1.0.pdf

It may be useful to map our checks to this framework

naveensrinivasan commented 2 years ago

We should discuss about this in our bi-weekly sync.

laurentsimon commented 2 years ago

I don't know anything about the benchmark or its popularity

github-actions[bot] commented 1 year ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 9 months ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 5 months ago

This issue has been marked stale because it has been open for 60 days with no activity.