ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.45k stars 487 forks source link

Feature: Add instructions on how to dismiss alerts #2543

Open pnacht opened 1 year ago

pnacht commented 1 year ago

Is your feature request related to a problem? Please describe. Some maintainers we've approached to add Scorecard have raised concerns about being repeatedly "pestered" by an alert they disagree with/won't fix.

Describe the solution you'd like It might be useful to have a reference in our FAQ to the GitHub docs on how to dismiss alerts.

I'd be happy to write a PR adding this.

However, I don't actually know what the behavior is when dismissing non-code alerts (Code-Review, Branch-Protection). The GitHub docs mention that when an alert is dismissed, "the same code won't generate an alert", but what if the alert is not code-based?

github-actions[bot] commented 1 year ago

Stale issue message - this issue will be closed in 7 days

spencerschrock commented 1 year ago

Exempting from stale issue bot, anything that cuts down on spam seems worth doing.

github-actions[bot] commented 10 months ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 4 months ago

This issue has been marked stale because it has been open for 60 days with no activity.

SilasVM commented 1 month ago

Hey @spencerschrock, I have a team ready to work on this issue, however, we noticed it doesn't have the good first issue label on it. Do you think this could also be a good introductory issue to the project?

We're also not entirely sure how to reproduce the alerts mentioned, so any guidance on that would be dually appreciated.

Thank you for your time.