ossf/OpenSSF Scorecard Monitor

Monitor OpenSSF Scorecard evolution over time

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
scopeFile that includes the list of repositories to monitor. Required when not using local-results-path.no
databaseFile that stores the state of the scorecardyes
reportFile that stores the report of the scorecardyes
auto-commitAutomatically commit the changes to the repositoryno
auto-pushAutomatically push the changes to the repositoryno
generate-issueAutomatically generate an issue with the discrepanciesno
issue-titleTitle of the issue to be generatednoOpenSSF Scorecard Report Updated!
issue-assigneesList of assignees for the issue to be generatedno
issue-labelsList of labels for the issue to be generatedno
discovery-enabledEnable the automatic update of the scope fileno
discovery-orgsList of organizations to be included in the scope fileno
report-tags-enabledEnable the use of tags in the reportno
report-start-tagStart tag to be used in the reportno<!-- OPENSSF-SCORECARD-MONITOR:START -->
report-end-tagEnd tag to be used in the reportno<!-- OPENSSF-SCORECARD-MONITOR:END -->
github-tokenToken to access the repositoryyes
max-request-in-parallelMaximum number of HTTP requests to be executed in parallelno10
render-badgeRender the OpenSSF Scorecard badge in the reportnofalse
report-toolTool to be included as link in the reportnoscorecard-visualizer
results-pathPath to a Scorecard results JSON file. When provided, scores are read from this file instead of the public Scorecard API. The file should contain an array of Scorecard JSON v2 result objects (e.g., from scorecard --format=json2, scorecard --org, or Allstar). When set, the scope input is not required.no
namedescription
scoresScore data in JSON format