apache / apache/logging-log4j2
Reintroduce the Scorecard workflow
Open
- Dominant language
- Java
- Stars
- 3.6k
- Forks
- 1.7k
- Avg merge
- 21h 30m
- Merged PRs (30d)
- 27
Description
We should reconsider enabling the Scorecard action, considering especially that:
- A Scorecard for Apache Log4j is computed anyway, since [Scorecards are computed for 1 million critical projects](https://github.com/ossf/scorecard?tab=readme-ov-file#public-data). Running the action ourselves we have more control on what the public sees.
- We enabled mandatory PR reviews, so random pushes to our default branch will not decrease our score.
Blocked by ossf/scorecard-webapp#554
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.