Objective
Track the remaining non-vulnerability OpenSSF Scorecard posture findings.
Pinned snapshot: e2a4790c323b85f249dee62c75d1fc620844251c
Review date: 2026-10-26
Scorecard run: https://github.com/BlueDot-IT/GhostMCP/actions/runs/33341365560
Current controls
main has strict checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, linear history, and force-push/deletion prevention.
Findings
Alert #12 Vulnerabilities is excluded from governance acceptance. It remains open pending merge of #12 and a successful post-merge Scorecard scan.
Objective
Track the remaining non-vulnerability OpenSSF Scorecard posture findings.
Pinned snapshot:
e2a4790c323b85f249dee62c75d1fc620844251cReview date: 2026-10-26
Scorecard run: https://github.com/BlueDot-IT/GhostMCP/actions/runs/33341365560
Current controls
mainhas strict checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, linear history, and force-push/deletion prevention.Findings
2026-10-24T23:40:11Z.6/29; preserve mandatory exact-head reviews and recheck the trend.Alert #12 Vulnerabilities is excluded from governance acceptance. It remains open pending merge of #12 and a successful post-merge Scorecard scan.