You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* ✨ Improved Security Policy Check (ossf#2137)
* Examines and awards points for linked content (URLs / Emails)
* Examines and awards points for hints of disclosure and vulnerability practices
* Examines and awards points for hints of elaboration of timelines
Signed-off-by: Scott Hissam <[email protected]>
* Repaired Security Policy to correctly use linked content length for evaluation
Signed-off-by: Scott Hissam <[email protected]>
* gofmt'ed changes
Signed-off-by: Scott Hissam <[email protected]>
* Repaired the case in the evaluation which was too sensitive to content length over the length of the linked content for urls and emails
Signed-off-by: Scott Hissam <[email protected]>
* added unit test cases for the new content-based Security Policy checks
Signed-off-by: Scott Hissam <[email protected]>
* reverted the direct (mistaken) change to checks.md and updated the checks.yaml for generate-docs
Signed-off-by: Scott Hissam <[email protected]>
* ✨ Improved Security Policy Check (ossf#2137) (revisted based on comments)
* replaced reason strings with log.Info & log.Warn (as seen in --show-details)
* internal assertion check for nil (*pinfo) and empty pfile
* internal switched to FileTypeText over FileTypeSource
* internal implement type SecurityPolicyInformationType/SecurityPolicyInformation revised SecurityPolicyData to support only one file
* revised expected unit-test results and revised unit-test to reflect the new SecurityPolicyData type
Signed-off-by: Scott Hissam <[email protected]>
* revised the score value based on observation of one *or more* url(s) or one email(s) found; unit tests update accordingly
Signed-off-by: Scott Hissam <[email protected]>
* revised the score value based on observation of one *or more* url(s) or one email(s) found; unit tests update accordingly
Signed-off-by: Scott Hissam <[email protected]>
* revised the score value based on observation of one *or more* url(s) or one email(s) found; e2e tests update accordingly
Signed-off-by: Scott Hissam <[email protected]>
* Addressed PR comments; added telemetry for policy hits in security policy file to track hits by line number
Signed-off-by: Scott Hissam <[email protected]>
* Resolved merge conflict with checks.yaml
Signed-off-by: Scott Hissam <[email protected]>
* updated raw results to emit all the raw information for the new security policy check
Signed-off-by: Scott Hissam <[email protected]>
* Resolved merge conflicts and lint errors with json_raw_results.go
Signed-off-by: Scott Hissam <[email protected]>
* Addressed review comments to reorganize security policy data struct to support the potential for multiple security policy files.
Signed-off-by: Scott Hissam <[email protected]>
* Added logic to the security policy to process multiple security policy files only after future improvements to aggregating scoring across such files are designed. For now the security policy behaves as originally designed to stop once one of the expected policy files are found in the repo
Signed-off-by: Scott Hissam <[email protected]>
* added comments regarding the capacity to support multiple policy files and removed unneeded break statements in the code
Signed-off-by: Scott Hissam <[email protected]>
* Addressed review comments to remove the dependency on the path in the filename from the code and introduced FileSize to checker.File type and removed the SecurityContentLength which was used to hold that information for the new security policy assessment
Signed-off-by: Scott Hissam <[email protected]>
* restored reporting full security policy path and filename for policies found in the org level repos
Signed-off-by: Scott Hissam <[email protected]>
* Resolved conflicts in checks.yaml for documentation
Signed-off-by: Scott Hissam <[email protected]>
* ✨ CLI for scorecard-attestor (ossf#2309)
* Reorganize
Signed-off-by: Raghav Kaul <[email protected]>
* Working commit
Signed-off-by: Raghav Kaul <[email protected]>
* Compile with local scorecard; go mod tidy
Signed-off-by: Raghav Kaul <[email protected]>
* Add signing code
Heavily borrowed from https://github.com/grafeas/kritis/blob/master/cmd/kritis/signer/main.go
Signed-off-by: Raghav Kaul <[email protected]>
* Update deps
* Naming
* Makefile
Signed-off-by: Raghav Kaul <[email protected]>
* Edit license, add lint.yml
Signed-off-by: Raghav Kaul <[email protected]>
* checks: go mod tidy, license
Signed-off-by: Raghav Kaul <[email protected]>
* Address PR comments
* Split into checker/signer files
* Naming convention
Signed-off-by: Raghav Kaul <[email protected]>
* License, remove golangci.yml
Signed-off-by: Raghav Kaul <[email protected]>
* Address PR comments
* Use cobra
Signed-off-by: Raghav Kaul <[email protected]>
* Add tests for root command
Signed-off-by: Raghav Kaul <[email protected]>
* Filter out checks that aren't needed for policy evaluation
Signed-off-by: Raghav Kaul <[email protected]>
* Add `make` targets for attestor; submit coverage stats
Signed-off-by: Raghav Kaul <[email protected]>
* Improvements
* Use sclog instead of glog
* Remove unneeded subcommands
* Formatting
Signed-off-by: Raghav Kaul <[email protected]>
* Flags: Make note-name constant and fix messaging
Signed-off-by: Raghav Kaul <[email protected]>
* Remove SupportedRequestTypes
Signed-off-by: Raghav Kaul <[email protected]>
* go mod tidy
Signed-off-by: Raghav Kaul <[email protected]>
* go mod tidy, makefile
Signed-off-by: Raghav Kaul <[email protected]>
* Fix GH actions run
Signed-off-by: Raghav Kaul <[email protected]>
Signed-off-by: Raghav Kaul <[email protected]>
Signed-off-by: Scott Hissam <[email protected]>
* removed whitespace before stanza for Run attestor e2e
Signed-off-by: Scott Hissam <[email protected]>
* resolved code review and doc review comments
Signed-off-by: Scott Hissam <[email protected]>
* repaired the link for the maintainer's guide for supporting the coordinated vulnerability disclosure guidelines
Signed-off-by: Scott Hissam <[email protected]>
Signed-off-by: Scott Hissam <[email protected]>
0 commit comments