Setup OpenSSF scorecards and fix issues

Open
#530 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Stale
Tech stack
python
Domain
ci-cd, security

Research direction

The issue names no files, tests, or entry points. Start by reviewing the OpenSSF scorecard report and the seven listed advisories, then inspect the taskgraph dependency and CI configuration; done means scorecards are set up and the reported vulnerabilities are resolved or explicitly addressed.

Written by the indexing model from the issue text.

Description

Pulling in Taskcluster via https://github.com/mozilla/neqo/pull/1935 made neqo's OSSF score drop because of unpatched vulnerabilities in taskcluster:

Reason
7 existing vulnerabilities detected
Details
Warn: Project is vulnerable to: GHSA-jjg7-2v4v-x38h
Warn: Project is vulnerable to: GHSA-h5c8-rqwp-cp95
Warn: Project is vulnerable to: GHSA-h75v-3vvj-5mfj
Warn: Project is vulnerable to: GHSA-9wx4-h78v-vm56
Warn: Project is vulnerable to: GHSA-34jh-p97f-mpxf
Warn: Project is vulnerable to: GHSA-g4mx-q9vg-27p4 / PYSEC-2023-212
Warn: Project is vulnerable to: GHSA-v845-jxx5-vc9f / PYSEC-2023-192

Dominant language
Python
Stars
26
Forks
55
Avg merge
2d 6m
Merged PRs (30d)
15

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from taskcluster/taskgraph

All issues in taskcluster/taskgraph

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.