microcks / microcks/.github

Bring all monitored repositories to 100% in CLOMonitor

Open
#104 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
8
Forks
41
Avg merge
1d 1h
Merged PRs (30d)
7

Description

The CLOMonitor audit conducted on 2026-09-18 reports an overall Microcks score of **98.49% (A)**. Fourteen of the twenty monitored repositories are already at 100%.

The remaining work is:

- [ ] `hub.microcks.io`: publish a recent release.
- [ ] `microcks-backstage-provider`: publish a recent release.
- [ ] `microcks-jenkins-plugin`: publish a recent release.
- [ ] `import-github-action`: publish a recent release and address the SBOM and signed-release checks.
- [ ] `test-github-action`: publish a recent release and address the SBOM and signed-release checks.
- [ ] `microcks-docker-desktop-extension`:
- Publish a recent release.
- Provide or document an SBOM.
- Sign the release artifacts or provide provenance.
- Define restrictive `GITHUB_TOKEN` permissions in `.github/workflows/build-verify.yml`.

For the two source-only GitHub Actions, maintainers should decide whether to produce signed release artifacts and SBOMs or declare documented exemptions in each repository's `.clomonitor.yml` when those checks are not applicable.

References:

- [Microcks CLOMonitor report](https://clomonitor.io/projects/cncf/microcks)
- [CLOMonitor check and exemption definitions](https://github.com/cncf/clomonitor/blob/main/docs/checks.md)

Completion criteria: every monitored repository reports 100% after the next CLOMonitor refresh.

Contributor guide

Open the contributing guide

Research direction

Start with the linked CLOMonitor report and the named repositories, comparing each repository's release status and compliance checks. Inspect .github/workflows/build-verify.yml in microcks-docker-desktop-extension and the .clomonitor.yml files for the two source-only GitHub Actions. Done means every monitored repository reports 100% after the next CLOMonitor refresh.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, devops, release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
50/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.