Skip to content

CI: Report scoring differences for PRs that modify scorecard checks #2462

@raghavkaul

Description

@raghavkaul

Is your feature request related to a problem? Please describe.
As discussed during the 11/17 OpenSSF scorecard meeting, contributor who make changes to scorecard could potentially drastically alter scorecard scores. It should be easier to determine how a change impacts scorecard scores on top projects.

Describe the solution you'd like
Contributions to scorecard should have an easy way to analyze how their branch changes would affect scorecard scoring on a set of repos, and self-reporting this should be part of the pull request guidelines.

Describe alternatives you've considered
One alternative was raised to run this analysis as part of any CI jobs, however, this may exhaust the GitHub API token quota and cause us to get rate limited.

Additional context
@shissam hints that they may have done prior work automating the process of inspecting score diffs for their PRs in this discussion.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions