Skip to content

Conversation

@mhucka
Copy link
Contributor

@mhucka mhucka commented Oct 12, 2025

This a security and code quality workflow that we run in other Quantumlib repos. The OpenSSF Scorecard is a code-scanning system recommended by Google's GitHub OSS team. Once it starts running, Scorecard will report findings in the Security tab of this repo as well as create and update a report page at the following URL: https://scorecard.dev/viewer/?uri=github.com/quantumlib/tesseract-decoder. It will be invoked on a weekly schedule.

@mhucka mhucka requested review from LalehB, noajshu and viathor October 12, 2025 05:39
@mhucka mhucka added area/health Project health, code health, and similar meta-level concerns area/devops Involves build systems, Make files, Bazel files, continuous integration, and/or other DevOps topics labels Oct 12, 2025
@mhucka mhucka requested a review from a team as a code owner November 4, 2025 15:51
@mhucka mhucka removed the area/devops Involves build systems, Make files, Bazel files, continuous integration, and/or other DevOps topics label Nov 4, 2025
@mhucka mhucka changed the title Add OSV and Scorecard code scanners Add OSV and Scorecard code scanner workflows Nov 9, 2025
Turns out it's unecessary because some of the other scanners use the
same database and will catch mostly the same things.
Update for changes made recently.
@mhucka mhucka changed the title Add OSV and Scorecard code scanner workflows Add Scorecard code scanner workflow Feb 2, 2026
@mhucka mhucka merged commit 53ef89d into quantumlib:main Feb 2, 2026
3 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/health Project health, code health, and similar meta-level concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants