Objective
Track the remaining non-vulnerability OpenSSF Scorecard posture findings.
Pinned snapshot: 9afd71e701fbd3e04f05b715f63a4d36b1c1b45c
Review date: 2026-10-26
Scorecard run: https://github.com/BlueDot-IT/SignalGate/actions/runs/33341359414
Current controls
main has strict checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, force-push/deletion prevention, and required CI, ClusterFuzzLite, and CodeQL checks.
Findings
Alert #14 Vulnerabilities is excluded from governance acceptance. Its time-bounded risk is tracked in #15 and implemented by #16. Reassess no later than 2026-10-31.
Objective
Track the remaining non-vulnerability OpenSSF Scorecard posture findings.
Pinned snapshot:
9afd71e701fbd3e04f05b715f63a4d36b1c1b45cReview date: 2026-10-26
Scorecard run: https://github.com/BlueDot-IT/SignalGate/actions/runs/33341359414
Current controls
mainhas strict checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, force-push/deletion prevention, and required CI, ClusterFuzzLite, and CodeQL checks.Findings
2026-10-24T23:40:25Z.2/25; preserve mandatory exact-head reviews and recheck the trend.Alert #14 Vulnerabilities is excluded from governance acceptance. Its time-bounded risk is tracked in #15 and implemented by #16. Reassess no later than 2026-10-31.