Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use deps.dev for OpenSSF scorecard results link #3368

Merged
merged 2 commits into from
Mar 23, 2023

Conversation

parlough
Copy link
Member

@parlough parlough commented Mar 21, 2023

This is linked to by the OpenSSF scorecard badge at the top of the README. The previous link was to unformatted JSON. Instead, this links to deps.dev which formats the results and in the future may include other information.

Previous link: https://api.securityscorecards.dev/projects/github.com/dart-lang/dartdoc
New link: https://deps.dev/project/github/dart-lang%2Fdartdoc

@jcollins-g
Copy link
Contributor

A resync should fix the test errors.

@jcollins-g
Copy link
Contributor

adding @devoncarew as a reviewer; I don't know what this link is or what it is for exactly so I'm not sure I can say for sure that this is correct. The new destination definitely looks better, though.

@devoncarew
Copy link
Member

That 2nd page does look better. Do you have another example of a repo (dart or flutter) linking to deps.dev, or, does securityscorecards.dev have a more user-friendly URL / page? cc @sealesj

@parlough
Copy link
Member Author

parlough commented Mar 23, 2023

Do you have another example of a repo (dart or flutter) linking to deps.dev, or, does securityscorecards.dev have a more user-friendly URL / page?

Yep, I believe all the Flutter repositories (with scorecards) do, for example flutter/flutter. Recently we requested the dart-lang repos with scorecards be added to the deps.dev dataset so we could link there too, for example, dart-lang/linter and dart-lang/site-www.

securityscorecards.dev does not have a user-friendly page yet: ossf/scorecard-webapp#206

@devoncarew devoncarew merged commit 592dc59 into dart-lang:master Mar 23, 2023
@parlough parlough deleted the misc/openssf-deps-dev branch March 23, 2023 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants