Home
Quickly assess open source projects for risky practices
OpenSSF Scorecard - Security health metrics for Open Source - ossf/scorecard
Quickly assess open source projects for risky practices
Quickly assess open source projects for risky practices
Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.
🗹 Source the Best Ingredients: Evaluate before using / Trust the source: Prefer actions from trusted organisations (or GitHub org itself) 🗹 Measure precisely: Limit permissions and access to the…