遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/5621)
<a href="https://www.bestpractices.dev/projects/5621"><img src="https://www.bestpractices.dev/projects/5621/badge"></a>
Scorecard is an automated tool that assesses a number of important heuristics ("checks") associated with software security and assigns each check a score of 0-10. You can use these scores to understand specific areas to improve in order to strengthen the security posture of your project. You can also assess the risks that dependencies introduce, and make informed decisions about accepting these risks, evaluating alternative solutions, or working with the maintainers to make improvements.
https://github.com/ossf/scorecard/blob/main/CONTRIBUTING.md
警告:需要更长的理由。
Linters enabled and blocking for code submissions: https://github.com/ossf/scorecard/blob/main/.github/workflows/lint.yml
后退