← All repos

scorecard-action

Official GitHub Action for OpenSSF Scorecard.

githubgithub-actionsopenssf-scorecardsecuritysupply-chain
Browse cluster: Static Analysis & Code Quality
642commits
29contributors
4languages

Tech stack & purpose

Scorecard-action is the official GitHub Action for OpenSSF Scorecard, a tool that assesses the security posture of open-source projects. The action runs security scans on repositories and integrates results into GitHub's code scanning dashboard through SARIF format output, supporting public repositories and private repositories with GitHub Advanced Security. Built primarily in Go and Bash, the project includes components for installing the action across multiple repositories via command-line tooling and comprehensive end-to-end testing infrastructure. The Open Source Security Foundation (OSSF) maintains this project, which supports various GitHub workflow triggers and offers result publishing through REST APIs and repository badges.

Languages

Go
96.5%
Dockerfile
2.1%
JavaScript
0.9%
Makefile
0.6%

Contributors