ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.36k stars 473 forks source link

Update Scorecard documentation to clarify stance of AI code review/generation #2954

Open ashishkurmi opened 1 year ago

ashishkurmi commented 1 year ago

Is your feature request related to a problem? Please describe. A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] During this week's scorecard meeting, we discussed the potential of utilizing AI-based code review systems to support projects with single maintainers in achieving a favorable score for the code review scorecard check. The consensus was to treat such systems similarly to Static Application Security Testing (SAST) tools for now. @david-a-wheeler has kindly volunteered to incorporate text into the scorecard to explicitly clarify the community's stance on AI-based development tools. This issue has been created to track the progress of this work.

Describe the solution you'd like Scorecard documentation has text clarifying the impact of AI based dev tools on Scorecard scores.

Describe alternatives you've considered A clear and concise description of any alternative solutions or features you've considered.

Additional context Add any other context or screenshots about the feature request here.

github-actions[bot] commented 11 months ago

Stale issue message - this issue will be closed in 7 days

github-actions[bot] commented 9 months ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 3 months ago

This issue has been marked stale because it has been open for 60 days with no activity.