ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.27k stars 463 forks source link

✨Creating the Scorecard Universe ✨ #4073

Open justaugustus opened 2 months ago

justaugustus commented 2 months ago

With the recent adoption of the Scorecard project charter, we as @ossf/scorecard-maintainers / Steering Committee have a few administrative tasks that need to be completed.

Each heading here will be broken into separate tracking issues, but consider this the umbrella issue for the Scorecard Universe (affectionately coined by @SecurityCRob).

(Note that this items are a rough copy/paste from this week's maintainer's meeting (2024-04-30) and are subject to change as we build out the governance story.)

Project & Steering Committee formation

Adopting Allstar

Adopting Monitor and API Visualizer

OpenSSF Project Lifecycle

cc: @afmarcum

justaugustus commented 2 months ago

Follow-up items from today's Scorecard meeting:

afmarcum commented 2 months ago

Adopting Allstar How do we make this official?

From Slack discussion with @justaugustus and @SecurityCRob: Informing the WG is all that is needed.

Once the group is ready, submit issues in the Best Practices WG and Securing Critical Projects WG repos informing of the change. Probably need one in the Allstar repo too, if there isn't one already referencing this issue.

Notify operations@openssf.org to update foundation content as well.

justaugustus commented 1 month ago

Allstar updates: