Security scorecards for open source projects
opensource.googleblog.com
opensource.googleblog.com
./scorecard --repo=github.com/bookstackapp/bookstack
<removed status text>
RESULTS
-------
Active: Pass 10
CI-Tests: Pass 8
CII-Best-Practices: Fail 10
Code-Review: Fail 10
Contributors: Pass 10
Frozen-Deps: Pass 10
Fuzzing: Fail 3
Pull-Requests: Pass 7
SAST: Fail 0
Security-Policy: Fail 10
Signed-Releases: Fail 0
Signed-Tags: Pass 10
Results appear fair and accurate. I am confused though in how this project is intended to work at a higher level. The blogpost states:> The goal of the Scorecards project is to auto-generate a “security score” for open source projects to help users as they decide the trust, risk, and security posture for their use case.
Will there be a centralised site to gather and display scores for open source projects? Or will it be up to the open source projects themselves to integrate this into their pages and, if so, what does that look like? Some kind of badge or a listing of the results as above? Just trying to understand how end-users will be interpreting the results in a consistent and trusted manner.
Also, this scorecard doesn’t look for CVEs or problems in particular versions. It seems like it’s much more important that there’s a valid vulnerability in version 1.04 that I’m using than the current version has code reviews for everything.
The reason I care is that I wish there was some stamp of approval on pypi packages that would make it easier for me to trust particular packages and releases.
I like the idea, I think it will just be tough to work out the right heuristics.
Also the name is “scorecard” that again connotes that a high score is good. I don’t get a 10/10 on my assignment because I did my homework, said hello to the teacher each morning, and was polite to my classmates.
Those are all positive things and if I wanted to measure students they may be a part of the grade. But if I only graded on these factors that’s not terribly useful.
Process measures are good when it’s not possible to measure outcome, but I think in this situation more outcome measures could be factored in.
The work to capture current vuln state is tracked in https://github.com/ossf/scorecard/issues/52