Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Add OpenSSF ScoreCard to Coder #14879

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
michaelbrewer opened this issue Sep 30, 2024 · 3 comments · Fixed by #15012
Closed

Add OpenSSF ScoreCard to Coder #14879

michaelbrewer opened this issue Sep 30, 2024 · 3 comments · Fixed by #15012
Assignees
Labels
docs Area: coder.com/docs

Comments

@michaelbrewer
Copy link
Contributor

When working with OpenSource at enterprise companies; governance, compliance and security comes up, adding OpenSSF ScoreCard - https://openssf.org/. Could be a good way to address that, especially when it comes to auditing

example open source repo that does this well and they also have a good docs describing how the processes work:

Screenshot 2024-09-30 at 8 34 54 AM

https://docs.powertools.aws.dev/lambda/python/latest/security/

@bpmct
Copy link
Member

bpmct commented Sep 30, 2024

Thanks for suggesting, we'll definitely look into this cc @matifali

@matifali matifali self-assigned this Sep 30, 2024
@matifali matifali added the docs Area: coder.com/docs label Oct 2, 2024
matifali added a commit that referenced this issue Oct 5, 2024
matifali added a commit that referenced this issue Oct 7, 2024
Closes #14879 

We will keep improving the score. Currently, Coder gets 7.0/10.0.
@michaelbrewer
Copy link
Contributor Author

Awesome turn around. Useful to keep track of this and helps with our risk assessment.

matifali added a commit that referenced this issue Oct 14, 2024
Use specific commit SHAs for GitHub actions across various workflows to
enhance reliability and reproducibility. This change ensures that
actions run against a known version, reducing the risk of unexpected
issues due to updates in the third-party action repositories.

This contributes to improving the score in #14879
@matifali matifali removed the feature label Oct 14, 2024
@matifali
Copy link
Member

matifali commented Nov 4, 2024

We have improved our score to 8.5 now.
A continual improvement towards this goal is documented here: coder/internal#89

matifali added a commit that referenced this issue Nov 15, 2024
Enables [build
attestation](https://docs.docker.com/build/metadata/attestations/slsa-provenance/)
for the docker-base image.
Contributes to #14879 and coder/internal#89

As an experiment, we are only doing it with the coder-base image for
now.
matifali added a commit that referenced this issue Feb 14, 2025
This should bump OpenSSF Score added in #14879
matifali added a commit that referenced this issue Feb 14, 2025
This should bump OpenSSF Score added in #14879
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs Area: coder.com/docs
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants