Skip to content

#326 - Add OpenSSF Scorecard, Best Practices, and SECURITY.md#331

Merged
udlose merged 2 commits into
mainfrom
security/326
Jan 24, 2026
Merged

#326 - Add OpenSSF Scorecard, Best Practices, and SECURITY.md#331
udlose merged 2 commits into
mainfrom
security/326

Conversation

@udlose
Copy link
Copy Markdown
Owner

@udlose udlose commented Jan 24, 2026

Resolves #326

PR Classification

Documentation and security policy enhancement.

PR Summary

This pull request improves repository security practices and documentation by updating workflow permissions, adding security badges, and introducing a formal security policy.

  • scorecard.yml: Enhanced permissions for private repos and set up fine-grained PAT for branch protection.
  • README.md: Added OpenSSF Scorecard, Best Practices, and Wakatime badges; introduced a Security section referencing the new policy.
  • SECURITY.md: Added a comprehensive security policy detailing vulnerability reporting and disclosure procedures.

Updated scorecard.yml to include recommended read permissions for private repos and set repo_token to use a fine-grained PAT for branch protection compatibility. Added OpenSSF Scorecard and Best Practices badges to README for improved security visibility. Reformatted contributor badge for clarity.
Added a WakaTime badge to the README for coding stats. Introduced a new Security section in the README with responsible disclosure instructions, and added SECURITY.md detailing supported versions, vulnerability reporting, and disclosure policy.
@udlose udlose self-assigned this Jan 24, 2026
@udlose udlose added documentation Improvements or additions to documentation github_actions Pull requests that update GitHub Actions code security Security vulnerability labels Jan 24, 2026
@udlose udlose added this to the 2.0.0 milestone Jan 24, 2026
@udlose udlose merged commit 8c14299 into main Jan 24, 2026
10 of 11 checks passed
@udlose udlose deleted the security/326 branch January 24, 2026 05:14
@udlose udlose removed this from the 2.0.0 milestone Jan 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation github_actions Pull requests that update GitHub Actions code security Security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add OSSF Scorecard GitHub Workflow Action

1 participant