Skip to content

ci: add OpenSSF Scorecard analysis - #1214

Open
jamadeo wants to merge 1 commit into
mainfrom
jamadeo/add-openssf-scorecard
Open

ci: add OpenSSF Scorecard analysis#1214
jamadeo wants to merge 1 commit into
mainfrom
jamadeo/add-openssf-scorecard

Conversation

@jamadeo

@jamadeo jamadeo commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Adds a pinned OpenSSF Scorecard workflow to assess the repository’s supply-chain security posture.

Motivation and Context

Good security/hygiene practice

How Has This Been Tested?

Run on PR

Breaking Changes

n/a

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

@jamadeo
jamadeo requested a review from a team as a code owner August 25, 2026 18:17
@github-actions github-actions Bot added T-CI Changes to CI/CD workflows and configuration T-config Configuration file changes labels Aug 25, 2026
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-CI Changes to CI/CD workflows and configuration T-config Configuration file changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants