From 0e64b2e1343c023a984133c8d22e1ee83dc283d5 Mon Sep 17 00:00:00 2001 From: Denis_Drobyshev Date: Fri, 18 Sep 2026 22:04:53 +0300 Subject: [PATCH] Let somebody else grade the supply chain Every badge in this README is produced by this repository's own CI. A project grading itself is the assertion this organisation says it does not accept, and the supply chain is exactly where that matters: whether releases are signed, whether actions are pinned, whether a dangerous trigger is in use, how fast a dependency gets patched. None of it is visible by reading the code. OpenSSF Scorecard measures those weekly and publishes the result, so the badge is somebody else's number. Findings land in code scanning beside CodeQL's. The actions in this workflow are pinned by commit rather than by tag, because the workflow that grades supply chains should not be the one taking a moving tag on trust. --- .github/workflows/scorecard.yml | 56 +++++++++++++++++++++++++++++++++ README.md | 1 + README.ru.md | 1 + 3 files changed, 58 insertions(+) create mode 100644 .github/workflows/scorecard.yml diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 0000000..6ca0bf8 --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,56 @@ +name: Scorecard + +# OpenSSF Scorecard grades the things a reader cannot check by reading the code: +# whether releases are signed, whether actions are pinned, whether a dangerous +# workflow trigger is in use, how quickly dependencies are patched. It is the +# one measure of this repository that is produced by somebody else, which is +# most of its value -- every other badge here is generated by this project's own +# CI, and a project grading its own supply chain is the assertion this +# organisation says it does not accept. +# +# The score is published so the badge resolves, and the findings land in the +# repository's code scanning dashboard beside CodeQL's. +on: + push: + branches: [master] # the default branch is the only one Scorecard supports + schedule: + - cron: "30 1 * * 6" # weekly, Saturday 01:30 UTC + workflow_dispatch: + +permissions: read-all + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-latest + permissions: + security-events: write # upload the SARIF to code scanning + id-token: write # OIDC token, so the published result is attributable + + steps: + # Actions in this workflow are pinned by commit, not by tag: Scorecard's + # own Pinned-Dependencies check is the reason, and a workflow that grades + # supply chains should not be the one taking a moving tag on trust. + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run analysis + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + + - name: Upload the SARIF as an artifact + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: scorecard-sarif + path: results.sarif + retention-days: 5 + + - name: Upload to code scanning + uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + with: + sarif_file: results.sarif diff --git a/README.md b/README.md index 11d6c95..20b308c 100644 --- a/README.md +++ b/README.md @@ -7,6 +7,7 @@ [![CI](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml) [![CodeQL](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml) [![Coverage](https://codecov.io/gh/DrobyshevDev/mlango/branch/master/graph/badge.svg)](https://codecov.io/gh/DrobyshevDev/mlango) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/DrobyshevDev/mlango/badge)](https://scorecard.dev/viewer/?uri=github.com/DrobyshevDev/mlango) [![PyPI](https://img.shields.io/pypi/v/mlango)](https://pypi.org/project/mlango/) [![Python](https://img.shields.io/pypi/pyversions/mlango)](https://pypi.org/project/mlango/) [![License](https://img.shields.io/pypi/l/mlango)](https://opensource.org/licenses/MIT) diff --git a/README.ru.md b/README.ru.md index 228f7e1..2dd936c 100644 --- a/README.ru.md +++ b/README.ru.md @@ -7,6 +7,7 @@ [![CI](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml) [![CodeQL](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml) [![Coverage](https://codecov.io/gh/DrobyshevDev/mlango/branch/master/graph/badge.svg)](https://codecov.io/gh/DrobyshevDev/mlango) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/DrobyshevDev/mlango/badge)](https://scorecard.dev/viewer/?uri=github.com/DrobyshevDev/mlango) [![PyPI](https://img.shields.io/pypi/v/mlango)](https://pypi.org/project/mlango/) [![Python](https://img.shields.io/pypi/pyversions/mlango)](https://pypi.org/project/mlango/) [![License](https://img.shields.io/pypi/l/mlango)](https://opensource.org/licenses/MIT)