AlanGraham commented on PR #436:
URL: 
https://github.com/apache/commons-validator/pull/436#issuecomment-5569608279

   I was working through a list of the dependencies in our app to encourage 
some of our engineers to submit PRs to some of the libraries we depend on, and 
noticed this badge. Having recently worked on it for a project I was curious 
about your scores and realised the link didn't go to the nicely formatted page.
   
   As for scoring, if you sign up to even work on the "passing" badge you gain 
points, even if you don't complete it. I'm sure it would be pretty simple for 
you to pass or score a high score for the passing level 
https://www.bestpractices.dev/en/criteria/0
   The Token-Permissions one links to a security bot which can audit and raise 
PRs to write the appropriate permissions too
   
https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions
   
   Just happy to see one of our dependencies has looked into this pretty cool 
tool too :).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to