Update OpenSSF badge link in README.md - #436
Conversation
OpenSSF have provided a way to link to a nicer page of your OpenSSF score. `https://api.securityscorecards.dev/projects/github.com/apache/commons-validator` -> `https://scorecard.dev/viewer/?uri=github.com/apache/commons-validator` So rather than a json blob, the link can now go to a nicely formatted page which also links to information on some of the items on what is needed to improve the score.
|
I was working through a list of the dependencies in our app to encourage some of our engineers to submit PRs to some of the libraries we depend on, and noticed this badge. Having recently worked on it for a project I was curious about your scores and realised the link didn't go to the nicely formatted page. As for scoring, if you sign up to even work on the "passing" badge you gain points, even if you don't complete it. I'm sure it would be pretty simple for you to pass or score a high score for the passing level https://www.bestpractices.dev/en/criteria/0 Just happy to see one of our dependencies has looked into this pretty cool tool too :). |
|
Hello @AlanGraham |
|
Ah cool will take a look at that, was carrying on through list and see https://github.com/apache/commons-text/blob/master/README.md also has the issue, assume that would fix there too :). |
|
Created apache/commons-build-plugin#425 |
|
Closing in favor of apache/commons-build-plugin#425 |
OpenSSF have provided a way to link to a nicer page of your OpenSSF score.
https://api.securityscorecards.dev/projects/github.com/apache/commons-validator->https://scorecard.dev/viewer/?uri=github.com/apache/commons-validatorSo rather than a json blob, the link can now go to a nicely formatted page which also links to information on some of the items on what is needed to improve the score.
Thanks for your contribution to Apache Commons! Your help is appreciated!
Before you push a pull request, review this list:
mvn; that'smvnon the command line by itself.