Skip to content

Support for SECURITY INSIGHTS #2305

@luigigubello

Description

@luigigubello

Is your feature request related to a problem? Please describe.
In the open-source ecosystem, developers can share the code on different platforms (GitHub, Bitbucket, self-hosted, etc), and they have various ways to communicate the same things related to security (e.g. how to report a vulnerability). SECURITY INSIGHTS could help the scorecard to reduce false-positive, by double-checking information on this file, if it is present, being independent on the project hosting platform.
SECURITY INSIGHTS can help to offer a tool that supports other platforms (not just GitHub, see issue #40), improving the quality of information, and reducing potential false-positive (tweet).

Describe the solution you'd like
SECURITY INSIGHTS is a YAML file that developers can add to their repository, and it contains valuable security-friendly information, that can help contributors, security researchers, and developers to contribute to the project. Hosting platforms have different APIs and features, so this file could be used to reduce false-positive or to get information for every project, not just projects hosted on Github.

Additional context
See the slides presented to the CNCF Tag group.
GitHub repo: https://github.com/ossf/security-insights-spec

Thanks 🌈

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions