{"repo":"ossf/scorecard-monitor","free":true,"listed":false,"github":"https://github.com/ossf/scorecard-monitor","clone":"git clone https://github.com/ossf/scorecard-monitor.git","description":"Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts","language":"JavaScript","stars":49,"topics":["github-actions","open-source-management","openssf-scorecard","security","security-audit","security-tools"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"OpenSSF Scorecard Monitor Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts. This project is part of OpenSSF Scorecard. Read the announcement for more details. 🔮 About If you're feeling overwhelmed by an avalanche of scorecards across your organizations, you can breathe easy: automation is here to make your life easier! Scorecard Monitor streamlines the process of keeping track of them all by providing a comprehensive report in Markdown and a local database in JSON with all the scores. To stay on top of any changes in the scores, you can also choose to get notifications through Github Issues. ✅ Requirements Please ensure that any repository you wish to track with Scorecard Monitor has already been analyzed by OpenSSF Scorecard at least once. This can be accomplished using the official GitHub Action or the Scorecard CLI. It's also possible that some repositories in your organization are already being automatically tracked by OpenSSF in this CSV file via weekly cronjob. One caveat: Automatically tracked projects do not include certain checks in their analysis ( CI-Tests,Contributors,Dependency-Update-Tool,Webhooks ). If you're not sure whether a specific project is already using OpenSSF Scorecard, you can always spot-check with the following URL pattern: https://securityscorecards.dev/viewer/?uri=github.com/ / (substitute and as appropriate). The Scorecard API is also able to fetch scores for a ","default_branch":null,"files":null,"tree":[],"storefront":"/r/ossf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ossf/scorecard-monitor/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}