Issues: ossf/scorecard
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Integrate GitHub Actions Results into BigQuery DatasetFeature
api
bigquery
enhancement
New feature or request
#3041
opened May 19, 2023 by
naveensrinivasan
Feature: Improve Signed-release for npm package
enhancement
New feature or request
Signed-Releases
#3038
opened May 18, 2023 by
laurentsimon
Feature: allow job-level write-permissions only when job steps are properly hash-pinned
enhancement
New feature or request
Token-Permissions
#3022
opened May 16, 2023 by
diogoteles08
Feature: Pinned-Dependencies do not understand variables in Dockerfile
enhancement
New feature or request
Pinned-Dependencies
#2988
opened May 10, 2023 by
szuecs
make public data set available outside GCP
bigquery
enhancement
New feature or request
#2986
opened May 10, 2023 by
ctr49
Search: unsupported feature
bug
Something isn't working
documentation
Improvements or additions to documentation
#2985
opened May 10, 2023 by
darker008
Any plan for supporting other platform?
enhancement
New feature or request
platforms
#2982
opened May 10, 2023 by
fredgan
Introducing Scorecard result viewer
enhancement
New feature or request
UI
#2979
opened May 9, 2023 by
tegioz
Allow configuring the path of the New feature or request
Vulnerabilities
osv-scanner.toml file
enhancement
#2963
opened May 6, 2023 by
mrinalwadhwa
Update Scorecard documentation to clarify stance of AI code review/generation
Code-Review
enhancement
New feature or request
#2954
opened May 4, 2023 by
ashishkurmi
Feature: Code-Review does not detect zappr enforcement
Code-Review
enhancement
New feature or request
#2952
opened May 4, 2023 by
szuecs
Feature: Improve error message when branch protection check fails because of the use of GITHUB_TOKEN
Branch-Protection
enhancement
New feature or request
#2946
opened May 4, 2023 by
ashishkurmi
BUG: internal error parsing Dockerfile
bug
Something isn't working
Pinned-Dependencies
#2932
opened May 2, 2023 by
lucasgonze
Feature: re-visit outcome definition in findings
enhancement
New feature or request
finding
#2928
opened Apr 28, 2023 by
laurentsimon
Feature: Token-Permissions should be more forgiving with permission declarations for single-job workflows
enhancement
New feature or request
Token-Permissions
#2927
opened Apr 28, 2023 by
pnacht
BUG: Pinned-Dependencies assumes that Dockerfile commands can be parsed as Something isn't working
Pinned-Dependencies
sh
bug
#2911
opened Apr 25, 2023 by
Porges
Move big .csv files to a separate repo
enhancement
New feature or request
maintenance
#2909
opened Apr 25, 2023 by
david-a-wheeler
BUG: Dockerfile named build stages with incomplete remediation report
bug
Something isn't working
Pinned-Dependencies
#2906
opened Apr 25, 2023 by
gabibguti
Feature: Remove CII-Best-Practices check
CII-Best-Practices
enhancement
New feature or request
#2904
opened Apr 25, 2023 by
gabibguti
e2e tests: use ginkgo's New feature or request
GitHub Actions
good first issue
Good for newcomers
tests
--flake-attempts flag instead of nick-invision/retry
enhancement
#2897
opened Apr 21, 2023 by
spencerschrock
Feature: Decrease score of Dependency-Update Tool check if dependabot is not configured to run on GitHub Actions
Dependency-Update-Tool
enhancement
New feature or request
#2888
opened Apr 19, 2023 by
diogoteles08
Feature: Add support for Nuget commands which use lock files
enhancement
New feature or request
Pinned-Dependencies
#2865
opened Apr 13, 2023 by
balteravishay
BUG: docker-compose file with YAML directive breaking
bug
Something isn't working
Pinned-Dependencies
#2853
opened Apr 11, 2023 by
gabibguti
Feature: Token-Permissions should ignore New feature or request
Token-Permissions
on: pull_request workflows
enhancement
#2850
opened Apr 11, 2023 by
pnacht
BUG: Scoring Dependecy-Update-Tool when there isn't file-based evidence
bug
Something isn't working
Dependency-Update-Tool
#2845
opened Apr 10, 2023 by
spencerschrock
Previous Next
ProTip!
What’s not been updated in a month: updated:<2023-04-19.

