-
Notifications
You must be signed in to change notification settings - Fork 440
Open
Labels
Component:MetaEverything about bats developmentEverything about bats developmentPriority: HighBroken behavior in specific environments like in parallel mode or only on some operating systemsBroken behavior in specific environments like in parallel mode or only on some operating systemsSize: LargeChanges across several filesChanges across several filesType: Enhancement
Description
Use https://github.com/ossf/scorecard and fix at least all issues >= HIGH.
Following todos from our report under https://api.securityscorecards.dev/projects/github.com/bats-core/bats-core / https://securityscorecards.dev/viewer/?uri=github.com/bats-core/bats-core:
- Branch-Protection: ??? -> manual check
- Code-Review (HIGH): 3 (2/6 PRs)
- Dependency-Update-Tool (HIGH): 0
- Token Permissions (HIGH): 0
Binary-Artifacts: 10 Branch-Protection: -1 CI-Tests: 5 CII-Best-Practices: 0 Code-Review: 1 Contributors: 10 Dangerous-Workflow: 10 Dependency-Update-Tool: 0 Fuzzing: 0 License: 9 Maintained: 10 Packaging: 10 Pinned-Dependencies: 5 SAST: 0 Security-Policy: 0 Signed-Releases: -1 Token-Permissions: 0 Vulnerabilities: 10
Total score right now: 5.3
Metadata
Metadata
Assignees
Labels
Component:MetaEverything about bats developmentEverything about bats developmentPriority: HighBroken behavior in specific environments like in parallel mode or only on some operating systemsBroken behavior in specific environments like in parallel mode or only on some operating systemsSize: LargeChanges across several filesChanges across several filesType: Enhancement