Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Add a GitHub Actions workflow (ossf/scorecard-action@v2 with a read-only PAT) to generate a complete OSSF Scorecard and resolve the Branch-Protection “?” score.
https://scorecard.dev/viewer/?uri=github.com%2Ffuture-architect%2Fvuls
Executed exactly as per the instructions in the OSSF Scorecard Action marketplace guide.
https://github.com/marketplace/actions/ossf-scorecard-action
Security enhancements:
.github/workflows/scorecard.yml
to perform supply-chain security analysis using the OpenSSF Scorecard action. This includes checks for branch protection and maintenance updates.read-all
by default and additional permissions for security events and ID tokens as needed.actions/checkout
(v4.2.2).ossf/scorecard-action
(v2.4.1), with support for SARIF results and optional publishing of results for public repositories.Type of change
How Has This Been Tested?
not tested
Checklist:
make fmt
make test
Is this ready for review?: YES