Skip to content

security: track and reconcile remaining OpenSSF Scorecard findings #12

Description

@jason-allen-oneal

Objective

Track the four remaining OpenSSF Scorecard findings without representing temporal, historical, or external-governance signals as undiscovered source vulnerabilities.

Pinned evidence snapshot: e9090ef18aac3f48549187acb2095e7c14d138c9
Snapshot date: 2026-08-30
Review date: 2026-10-26
Latest Scorecard run: https://github.com/BlueDot-IT/DarkPrompt/actions/runs/33341356387

Current controls

main uses classic branch protection with strict required checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, and force-push/deletion prevention. Required checks are Python 3.10, Python 3.11, Python 3.13, package, analyze (python), and CodeQL.

Findings and acceptance criteria

Maintained — alert #3

https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/3

The repository was created at 2026-07-26T23:21:31Z and crosses Scorecard's 90-day threshold at 2026-10-24T23:21:31Z.

  • Let the Sunday 2026-10-25 Scorecard schedule run after the threshold.
  • On 2026-10-26, confirm whether the alert auto-closes.
  • Investigate only if it remains open after a successful post-threshold analysis.

Code-Review — alert #4

https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/4

The current instance reports 2/28 approved changesets. Historical changesets cannot be retroactively approved, while current main protection requires one approval.

  • Preserve the current review, stale-review, admin-enforcement, and conversation-resolution controls.
  • Require exact-head approval for future non-exempt PRs.
  • Recheck the Scorecard ratio on 2026-10-26.
  • Consider Code Owner and last-push approval requirements if the repository gains additional maintainers.

CII-Best-Practices — alert #5

https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/5

No OpenSSF Best Practices badge enrollment or badge reference is currently detected.

  • Assign an owner for the external questionnaire.
  • Complete or explicitly defer enrollment.
  • If enrolled, add the canonical badge link to the README.
  • Confirm a subsequent Scorecard run detects the badge.

Fuzzing — alert #6

https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/6

No recognized fuzz integration or local fuzz harness exists. This alert remains open until the control exists.

  • Select a detector-recognized integration such as ClusterFuzzLite or OSS-Fuzz after reviewing action/container provenance.
  • Add deterministic harnesses for pack YAML/model validation, media-payload parsing, regex redaction/evaluation, and other pure input boundaries.
  • Seed corpora from sample_pack/ and security_pack_v1/.
  • Add bounded PR and scheduled runs with crash artifacts and regression tests.
  • Confirm the latest Scorecard analysis closes alert Schedule Codex Security scan weekly #6.

Closure

Re-query open code-scanning alerts at the then-current immutable main SHA. Close this issue only when every item is fixed, superseded with evidence, or explicitly risk-accepted by the repository owner.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions