Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSF Scorecard data #18

Open
andrew opened this issue Jul 1, 2024 · 2 comments
Open

OpenSSF Scorecard data #18

andrew opened this issue Jul 1, 2024 · 2 comments
Labels
enhancement New feature or request help wanted Extra attention is needed

Comments

@andrew
Copy link
Member

andrew commented Jul 1, 2024

I'd like to get the data from https://securityscorecards.dev/ into an ecosyste.ms service so I can do queries across the data and also integrate it into the packages and repos services.

In future we may calculate the scores ourselves as OpenSSF only covers a small percentage of all the most important open source repositories.

@andrew andrew added enhancement New feature or request help wanted Extra attention is needed labels Jul 1, 2024
@JustinGOSSES
Copy link

JustinGOSSES commented Jul 16, 2024

Possibly useful for this issue, at least for exploration purposes, is a not well advertised prototype OSSF API that pulls in scorecard and some of the other OSSF API results, plus a few additional things like average dependency age and libYears behind https://riskapi.ashydesert-4ee1f08e.westus3.azurecontainerapps.io/apidocs/

@andrew
Copy link
Member Author

andrew commented Jul 16, 2024

@JustinGOSSES thanks, I saw this a few weeks ago as well, keeping an eye on it to see what raw data is missing from ecosyste.ms that would be used to make this high level assesments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

2 participants