-
Notifications
You must be signed in to change notification settings - Fork 609
Description
Is your feature request related to a problem? Please describe.
In the open-source ecosystem, developers can share the code on different platforms (GitHub, Bitbucket, self-hosted, etc), and they have various ways to communicate the same things related to security (e.g. how to report a vulnerability). SECURITY INSIGHTS could help the scorecard to reduce false-positive, by double-checking information on this file, if it is present, being independent on the project hosting platform.
SECURITY INSIGHTS can help to offer a tool that supports other platforms (not just GitHub, see issue #40), improving the quality of information, and reducing potential false-positive (tweet).
Describe the solution you'd like
SECURITY INSIGHTS is a YAML file that developers can add to their repository, and it contains valuable security-friendly information, that can help contributors, security researchers, and developers to contribute to the project. Hosting platforms have different APIs and features, so this file could be used to reduce false-positive or to get information for every project, not just projects hosted on Github.
Additional context
See the slides presented to the CNCF Tag group.
GitHub repo: https://github.com/ossf/security-insights-spec
Thanks 🌈
Metadata
Metadata
Assignees
Labels
Type
Projects
Status