Repository navigation
Add scorecards config - #1302
Conversation
|
friendly ping. Can you provide feedback or suggestions? |
nickfyson
left a comment
There was a problem hiding this comment.
Thanks for this PR and apologies for the delay!
A few points/queries, but the main one if that we'll need a suitable SVG icon to use as the logo for the UI tile on the setup page. 🙂
|
cc @olivekl |
fc16a2f to
588b44b
Compare
Thank you @nickfyson for the update on the text, it looks better! I agree it'd look better with a tighter rounding box. Is this something we should do ourselves or you have some expertise to help with that? |
|
@laurentsimon I'm afraid not, I think getting a more suitable output would be most easily done from whatever source exported the current SVG! 😕 |
thanks. I'll wait till @josepalafox is back because I think he's working on it, and I'd like to avoid duplicating the work. |
|
I am not. Sounds like we need help from marketing at OSSF. The logo is a little small but it looks ok to launch with imho. |
938afd2 to
54c5923
Compare
@inferno-chromium whom can I talk to to tweak the logo? |
Original designer at 99Designs left. We would have to create another contract with 99Designs to create a new logo for this specific usecase. Jenn (jbonner@) at LF can help with contract on this. |
157b687 to
23b4603
Compare
23b4603 to
d0dba52
Compare
|
one question I have is where will users see the template workflow from this workflow. I looked at https://github.com/marketplace/actions/anchore-container-scan which is defined in the starter-workflows, but when I click "use latest version" it only shows |
|
Unfortunately Stater workflows and Marketplace are two separate entities
right now. The Marketplace entry is the generic action that just runs that
scanner, usually we ask partners to embed the additional workflow in the
description there. The stater-workflow will be accessible through the
GH.com UI in the actions tab.
…On Tue, Jan 4, 2022 at 11:14 AM laurentsimon ***@***.***> wrote:
one question I have is where will users be prompted with this workflow. I
looked at https://github.com/marketplace/actions/anchore-container-scan
which is defined in the starter-workflows, but when I click "use latest
version" it only shows uses: ... not the entire workflow template in this
repo.
I was expecting that clicking the button would start a new pull request on
a repo of my choice with the content of the workflow template from this
repo.
—
Reply to this email directly, view it on GitHub
<#1302 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AALPN2EHMP5HITDI3HHV4STUUNBIHANCNFSM5JZWFCKA>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
--
Jose Palafox
Technical Partnerships and Engineering @ GitHub
***@***.***
503.877.2403
|
thanks for the info. It would be great to have the maketplace use the starter-workflows too: that's where I personally go to search for actions, not in the Action settings. Thanks everyone for helping review the PR and for answering my questions! |
|
how long does it take for the action to be available in the Action tab? |
|
.com deploys happen pretty regularly should be imminent in the next 24-48.
…On Tue, Jan 4, 2022, 11:20 laurentsimon ***@***.***> wrote:
how long does it take for the action to be available in the Action tab?
—
Reply to this email directly, view it on GitHub
<#1302 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AALPN2HA6PCY4C52UDLTVRLUUNB65ANCNFSM5JZWFCKA>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
|

Pre-requisites
cc @josepalafox
Tasks
For all workflows, the workflow:
.ymlfile with the language or platform as its filename, in lower, kebab-cased format (for example,docker-image.yml). Special characters should be removed or replaced with words as appropriate (for example, "dotnet" instead of ".NET").For Code Scanning workflows, the workflow:
code-scanningdirectory.not sure what this means.
code-scanning/properties/*.properties.jsonfile (for example,code-scanning/properties/codeql.properties.json), with properties set as follows:name: Name of the Code Scanning integration.organization: Name of the organization producing the Code Scanning integration.description: Short description of the Code Scanning integration.categories: Array of languages supported by the Code Scanning integration.iconName: Name of the SVG logo representing the Code Scanning integration. This SVG logo must be present in theiconsdirectory.cc @josepalafox is working on this.
pushtobranches: [ $default-branch, $protected-branches ]andpull_requesttobranches: [ $default-branch ]. We also recommend ascheduletrigger ofcron: $cron-weekly(for example,codeql.yml).Some general notes:
actionsorganization, orThere is a disclaimer, as suggested offline with @josepalafox
closes ossf/scorecard-action#24
closes ossf/scorecard#1105