Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CI: Report scoring differences for PRs that modify scorecard checks #2462

Closed
raghavkaul opened this issue Nov 18, 2022 · 1 comment · Fixed by #3640
Closed

CI: Report scoring differences for PRs that modify scorecard checks #2462

raghavkaul opened this issue Nov 18, 2022 · 1 comment · Fixed by #3640
Assignees
Labels
kind/enhancement New feature or request

Comments

@raghavkaul
Copy link
Contributor

Is your feature request related to a problem? Please describe.
As discussed during the 11/17 OpenSSF scorecard meeting, contributor who make changes to scorecard could potentially drastically alter scorecard scores. It should be easier to determine how a change impacts scorecard scores on top projects.

Describe the solution you'd like
Contributions to scorecard should have an easy way to analyze how their branch changes would affect scorecard scoring on a set of repos, and self-reporting this should be part of the pull request guidelines.

Describe alternatives you've considered
One alternative was raised to run this analysis as part of any CI jobs, however, this may exhaust the GitHub API token quota and cause us to get rate limited.

Additional context
@shissam hints that they may have done prior work automating the process of inspecting score diffs for their PRs in this discussion.

@github-actions
Copy link

Stale issue message - this issue will be closed in 7 days

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants