Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
hey @allenrobel,
here is a list of files that the OSPO requires or recommends you to be added to your repository, please review and let me know if there are any questions. The only mandatory file is
.github/workflows/scorecard.yml
which will run Scorecard against your repository and provide us with a score and you with some recommendations on security best practices.All other files are recommended, but feel free to cherry pick those where you think you want to add them. For example the markdownlinter will require you to update a lot of *.md files in your repo.
Thanks!