{"repo":"ossf/scorecard-action","free":true,"listed":false,"github":"https://github.com/ossf/scorecard-action","clone":"git clone https://github.com/ossf/scorecard-action.git","description":"Official GitHub Action for OpenSSF Scorecard.","language":"Go","stars":408,"topics":["github","github-actions","security","supply-chain","openssf-scorecard"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Scorecards' GitHub action Official GitHub Action for OSSF Scorecards. The Scorecards GitHub Action is free for all public repositories. Private repositories are supported if they have GitHub Advanced Security. Private repositories without GitHub Advanced Security can run Scorecards from the command line by following the standard installation instructions. Breaking changes in v2 Starting from scorecard-action:v2, GITHUB TOKEN permissions or job permissions needs to include id-token: write for publish results: true . This is needed to access GitHub's OIDC token which verifies the authenticity of the result when publishing it. See details here If publishing results, scorecard-action:v2 also imposes new requirements on both the workflow and the job running the ossf/scorecard-action step. For full details see here. Installation - Workflow Setup - Authentication View Results - REST API - Scorecard Badge - Code Scanning Alerts - Verify Runs - Troubleshooting Manual Action Setup - Inputs - Publishing Results - Workflow Restrictions - Uploading Artifacts - Workflow Example Reporting vulnerabilities The following GitHub triggers are supported: push , schedule (default branch only). The pull request and workflow dispatch triggers are experimental. Running the Scorecard action on a fork repository is not supported. GitHub Enterprise repositories are not supported. Installation Workflow Setup (Required) 1. From your GitHub project's main page, click “Security” in the top ribbon. 2. Select","default_branch":null,"files":null,"tree":[],"storefront":"/r/ossf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ossf/scorecard-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}