ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.26k stars 462 forks source link

Feature: Support for GCB in the Packaging check #2058

Open laurentsimon opened 1 year ago

laurentsimon commented 1 year ago

We only support GH action in the check. It'd be useful to support other builders, like GCB. Seems easy enough to parse the yaml file and check the step's name, https://cloud.google.com/artifact-registry/docs/configure-cloud-build

This is pretty useful to help with prioritization of SLSA adoption too. Once we know where repositories build, we can target them for GH Action or GCB SLSA builders or ...

github-actions[bot] commented 9 months ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 6 months ago

This issue is stale because it has been open for 60 days with no activity.