networkservicemesh / networkservicemesh/api
api: Update NSM state on CNCF landscape
Open
@NikitaSkrynnik is already working on this.
Since Aug 22, 2024.
- Dominant language
- Go
- Stars
- 18
- Forks
- 22
- Avg merge
- 27m
- Merged PRs (30d)
- 3
Description
Decomposition
Documentation
- Contributing - add a file
contributing: https://clomonitor.io/docs/topics/checks/#contributing - Maintainers - add a file
maintainers: https://clomonitor.io/docs/topics/checks/#maintainers
License
- License scanning - add a link in
README.md: https://clomonitor.io/docs/topics/checks/#license-scanning
Best Practices
- Artifact Hub badge - add a link to artifacthub.io in
README.mdand probably update NSM state on artifacthub.io: https://clomonitor.io/docs/topics/checks/#artifact-hub-badge - OpenSSF best practices badge - add a link to OpenSSF best practice in
README.md: https://clomonitor.io/docs/topics/checks/#openssf-best-practices-badge - OpenSSF Scorecard badge - add OpenSSF Scorecard badge and probably add OpenSSF GitHub Action: https://clomonitor.io/docs/topics/checks/#openssf-scorecard-badge
Security
- Dependencies policy - ?
- Dependency update tool - use dependabot or renovatebot to update dependencies in the repo: https://clomonitor.io/docs/topics/checks/#dependency-update-tool-from-openssf-scorecard
- Maintained - actively maintain the repo: https://clomonitor.io/docs/topics/checks/#maintained-from-openssf-scorecard
- Software bill of materials - ?
- Security insights - add a file
SECURITY-INSIGHTS.yml: https://clomonitor.io/docs/topics/checks/#security-insights (spec: https://github.com/ossf/security-insights-spec/blob/v1.0.0/specification.md) - Security policy - add a file "
security: https://clomonitor.io/docs/topics/checks/#security-policy - Signed releases - cryptographically sign release artifacts: https://github.com/ossf/scorecard/blob/main/docs/checks.md#signed-releases
- Token permissions - all GitHub workflow tokens should be read-only: https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.