Skip to content

security: track and reconcile remaining OpenSSF Scorecard findings #17

Description

@jason-allen-oneal

Objective

Track the remaining non-vulnerability OpenSSF Scorecard posture findings.

Pinned snapshot: 9afd71e701fbd3e04f05b715f63a4d36b1c1b45c
Review date: 2026-10-26
Scorecard run: https://github.com/BlueDot-IT/SignalGate/actions/runs/33341359414

Current controls

main has strict checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, force-push/deletion prevention, and required CI, ClusterFuzzLite, and CodeQL checks.

Findings

Alert #14 Vulnerabilities is excluded from governance acceptance. Its time-bounded risk is tracked in #15 and implemented by #16. Reassess no later than 2026-10-31.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions