Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

✨ Enable Scorecard badge #178

Merged
merged 4 commits into from
Aug 9, 2022
Merged

✨ Enable Scorecard badge #178

merged 4 commits into from
Aug 9, 2022

Conversation

azeemshaikh38
Copy link
Contributor

Summary

Enable the beta version of scorecard-action:v2 which adds a Scorecard badge to the repo.

Release Note

NONE

Documentation

NONE

@woodruffw woodruffw assigned woodruffw and unassigned woodruffw Jul 31, 2022
@woodruffw woodruffw added the qa quality assurance label Jul 31, 2022
Signed-off-by: Azeem Shaikh <[email protected]>
Signed-off-by: Azeem Shaikh <[email protected]>
Signed-off-by: Azeem Shaikh <[email protected]>
@woodruffw
Copy link
Member

/gcbrun

@woodruffw
Copy link
Member

LGTM structurally, although I have a (weak) preference for waiting for v2 to be stabilized and officially released before we merge it here.

cc @di however; if you're content as-is then I have no objections 🙂

@woodruffw
Copy link
Member

/gcbrun

@azeemshaikh38
Copy link
Contributor Author

LGTM structurally, although I have a (weak) preference for waiting for v2 to be stabilized and officially released before we merge it here.

cc @di however; if you're content as-is then I have no objections 🙂

If it helps, this version is already installed and running on cosign, rekor and fulcio :)

@di di merged commit 713bd8c into sigstore:main Aug 9, 2022
@di
Copy link
Member

di commented Aug 9, 2022

@woodruffw
Copy link
Member

Looks like https://api.securityscorecards.dev/projects/github.com/sigstore/sigstore-python is 404? Is that expected?

I think it was waiting for the action to finish; it returns JSON for me now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
qa quality assurance
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants