Open
Description
We should reconsider enabling the Scorecard action, considering especially that:
- A Scorecard for Apache Log4j is computed anyway, since Scorecards are computed for 1 million critical projects. Running the action ourselves we have more control on what the public sees.
- We enabled mandatory PR reviews, so random pushes to our default branch will not decrease our score.
Blocked by ossf/scorecard-webapp#554
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Ready