argo-events icon indicating copy to clipboard operation
argo-events copied to clipboard

Bring CLOMonitor Score to 100%

Open hernanpl opened this issue 1 year ago • 2 comments

This repo is signed up as part of the KubeCon Security Slam. I'm bringing to your attention the checklist from the official CLOMonitor page for Argo -- it refreshes every hour, so it should be up-to-date.

CLOMonitor report

Summary

Repository: argo-events URL: https://github.com/argoproj/argo-events Checks sets: CODE Score: 85

Checks passed per category

Category Score
Documentation 100%
License 75%
Best Practices 94%
Security 75%
Legal n/a

Checks

Documentation [100%]

License [75%]

  • [x] Apache-2.0 (docs)
  • [x] Approved license (docs)
  • [ ] License scanning (docs)

Best Practices [94%]

Security [75%]

  • [x] Binary artifacts (docs)
  • [x] Code review (docs)
  • [x] Dangerous workflow (docs)
  • [x] Dependency update tool (docs)
  • [x] Maintained (docs)
  • [x] Software bill of materials (SBOM) (docs)
  • [x] Security policy (docs)
  • [ ] Signed releases (docs)
  • [x] Token permissions (docs)

For more information about the checks sets available and how each of the checks work, please see the CLOMonitor's documentation.

hernanpl avatar Oct 14 '22 21:10 hernanpl