Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Meet the best practice criteria of CNCF (CLOmonitor) #1860

Open
7 tasks
FeynmanZhou opened this issue Oct 11, 2024 · 0 comments
Open
7 tasks

Meet the best practice criteria of CNCF (CLOmonitor) #1860

FeynmanZhou opened this issue Oct 11, 2024 · 0 comments

Comments

@FeynmanZhou
Copy link
Collaborator

FeynmanZhou commented Oct 11, 2024

CNCF CLOMonitor is a tool that periodically checks open source projects repositories to verify they meet certain project health best practices. Ratify scores 89 on CLOMonitor. But there are a few failed items evaluated by CLOMonitor. We could fix these items to get a higher score and improve the security posture of Ratify project.
image

Security

  • Dependencies policy: The project provides a policy that describes how dependencies are consumed and updated check docs
  • Security insights: The project provides an OpenSSF Security Insights manifest file check docs
  • Signed releases: The project cryptographically signs release artifacts check docs

Best practice and license check

  • Summary Table: Projects should provide some information for the Landscape Summary Table check docs
  • License scanning: scans and automatically identifies, manages and addresses open source licensing issues check docs
  • Artifact Hub badge: Projects can list their content on Artifact Hub to improve their discoverability check docs
  • ratify-web repo: The project should have released at least one version in the last year. Keep regular release each year.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant