Skip to content

Add scorecards config - #1302

Merged
nickfyson merged 12 commits into
actions:mainfrom
laurentsimon:feat/scorecard
Jan 4, 2022
Merged

nickfyson merged 12 commits into
actions:mainfrom
laurentsimon:feat/scorecard

Conversation

@laurentsimon

@laurentsimon laurentsimon commented Dec 10, 2021 •

Copy link
Copy Markdown
Contributor

Pre-requisites

  • Prior to submitting a new workflow, please apply to join the GitHub Technology Partner Program: partner.github.com/apply.

cc @josepalafox

Tasks

For all workflows, the workflow:

  • Should be contained in a .yml file with the language or platform as its filename, in lower, kebab-cased format (for example, docker-image.yml). Special characters should be removed or replaced with words as appropriate (for example, "dotnet" instead of ".NET").
  • Should use sentence case for the names of workflows and steps (for example, "Run tests").
  • Should be named only by the name of the language or platform (for example, "Go", not "Go CI" or "Go Build").
  • Should include comments in the workflow for any parts that are not obvious or could use clarification.

For Code Scanning workflows, the workflow:

not sure what this means.

  • Should include a matching code-scanning/properties/*.properties.json file (for example, code-scanning/properties/codeql.properties.json), with properties set as follows:
    • name: Name of the Code Scanning integration.
    • organization: Name of the organization producing the Code Scanning integration.
    • description: Short description of the Code Scanning integration.
    • categories: Array of languages supported by the Code Scanning integration.
    • iconName: Name of the SVG logo representing the Code Scanning integration. This SVG logo must be present in the icons directory.

cc @josepalafox is working on this.

  • Should run on push to branches: [ $default-branch, $protected-branches ] and pull_request to branches: [ $default-branch ]. We also recommend a schedule trigger of cron: $cron-weekly (for example, codeql.yml).

Some general notes:

  • This workflow must only use actions that are produced by GitHub, in the actions organization, or
  • This workflow must only use actions that are produced by the language or ecosystem that the workflow supports. These actions must be published to the GitHub Marketplace. We require that these actions be referenced using the full 40 character hash of the action's commit instead of a tag. Additionally, workflows must include the following comment at the top of the workflow file:
    # This workflow uses actions that are not certified by GitHub.
    # They are provided by a third-party and are governed by
    # separate terms of service, privacy policy, and support
    # documentation.
    
  • Automation and CI workflows should not send data to any 3rd party service except for the purposes of installing dependencies.

There is a disclaimer, as suggested offline with @josepalafox

  • Automation and CI workflows cannot be dependent on a paid service or product.

closes ossf/scorecard-action#24
closes ossf/scorecard#1105

@laurentsimon
laurentsimon requested a review from a team as a code owner December 10, 2021 17:53
@github-actions github-actions Bot added the code-scanning Related to workflows that show on the Code Scanning setup page label Dec 10, 2021
@laurentsimon

Copy link
Copy Markdown
Contributor Author

friendly ping. Can you provide feedback or suggestions?

@nickfyson nickfyson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this PR and apologies for the delay!

A few points/queries, but the main one if that we'll need a suitable SVG icon to use as the logo for the UI tile on the setup page. 🙂

Comment thread code-scanning/properties/scorecards.properties.json Outdated
Comment thread code-scanning/scorecards.yml Outdated
Comment thread code-scanning/properties/scorecards.properties.json
Comment thread code-scanning/scorecards.yml
Comment thread code-scanning/scorecards.yml Outdated
@laurentsimon

Copy link
Copy Markdown
Contributor Author

cc @olivekl

@nickfyson nickfyson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I made some suggested changes to the metadata wording, and with those applied this is how the tile looks..

The logo isn't ideal in this setting, but I think it could be okay...? 😀

Comment thread code-scanning/properties/scorecards.properties.json
Comment thread code-scanning/properties/scorecards.properties.json
@laurentsimon

Copy link
Copy Markdown
Contributor Author

I made some suggested changes to the metadata wording, and with those applied this is how the tile looks..

The logo isn't ideal in this setting, but I think it could be okay...? 😀

Thank you @nickfyson for the update on the text, it looks better! I agree it'd look better with a tighter rounding box. Is this something we should do ourselves or you have some expertise to help with that?

@nickfyson

Copy link
Copy Markdown
Contributor

@laurentsimon I'm afraid not, I think getting a more suitable output would be most easily done from whatever source exported the current SVG! 😕

@laurentsimon

Copy link
Copy Markdown
Contributor Author

@laurentsimon I'm afraid not, I think getting a more suitable output would be most easily done from whatever source exported the current SVG! 😕

thanks. I'll wait till @josepalafox is back because I think he's working on it, and I'd like to avoid duplicating the work.

@josepalafox

Copy link
Copy Markdown

I am not. Sounds like we need help from marketing at OSSF. The logo is a little small but it looks ok to launch with imho.

@laurentsimon

Copy link
Copy Markdown
Contributor Author

I am not. Sounds like we need help from marketing at OSSF. The logo is a little small but it looks ok to launch with imho.

@inferno-chromium whom can I talk to to tweak the logo?

@inferno-chromium

Copy link
Copy Markdown

I am not. Sounds like we need help from marketing at OSSF. The logo is a little small but it looks ok to launch with imho.

@inferno-chromium whom can I talk to to tweak the logo?

Original designer at 99Designs left. We would have to create another contract with 99Designs to create a new logo for this specific usecase. Jenn (jbonner@) at LF can help with contract on this.

@laurentsimon

laurentsimon commented Jan 4, 2022 •

Copy link
Copy Markdown
Contributor Author

one question I have is where will users see the template workflow from this workflow. I looked at https://github.com/marketplace/actions/anchore-container-scan which is defined in the starter-workflows, but when I click "use latest version" it only shows uses: ... not the entire workflow template in this repo.
I was expecting that clicking the button would start a new pull request on a repo of my choice with the content of the workflow template from this repo.

@nickfyson nickfyson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀

@josepalafox

josepalafox commented Jan 4, 2022 via email

Copy link
Copy Markdown

@nickfyson
nickfyson merged commit 51e7c8e into actions:main Jan 4, 2022
@laurentsimon

Copy link
Copy Markdown
Contributor Author

Unfortunately Stater workflows and Marketplace are two separate entities right now. The Marketplace entry is the generic action that just runs that scanner, usually we ask partners to embed the additional workflow in the description there. The stater-workflow will be accessible through the GH.com UI in the actions tab.
…
On Tue, Jan 4, 2022 at 11:14 AM laurentsimon @.> wrote: one question I have is where will users be prompted with this workflow. I looked at https://github.com/marketplace/actions/anchore-container-scan which is defined in the starter-workflows, but when I click "use latest version" it only shows uses: ... not the entire workflow template in this repo. I was expecting that clicking the button would start a new pull request on a repo of my choice with the content of the workflow template from this repo. — Reply to this email directly, view it on GitHub <#1302 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AALPN2EHMP5HITDI3HHV4STUUNBIHANCNFSM5JZWFCKA . You are receiving this because you were mentioned.Message ID: @.>
-- Jose Palafox Technical Partnerships and Engineering @ GitHub @.*** 503.877.2403

thanks for the info. It would be great to have the maketplace use the starter-workflows too: that's where I personally go to search for actions, not in the Action settings.

Thanks everyone for helping review the PR and for answering my questions!

@laurentsimon

Copy link
Copy Markdown
Contributor Author

how long does it take for the action to be available in the Action tab?

@josepalafox

josepalafox commented Jan 4, 2022 via email

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

code-scanning Related to workflows that show on the Code Scanning setup page

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Submit starter-workflows GitHub action verified, on market place and available in the tool list

6 participants