
They added, “From here, Allstar takes the next step and allows maintainers to opt into automated enforcement of specific checks. From these scores, users can understand specific areas to improve in order to strengthen the security posture of their project,” explained Google’s Mike Maraya and Jeff Mendoza. “Security Scorecards checks a number of important heuristics (currently 18), such as whether the project uses branch protection, cryptographically signs release artifacts, or requires code review. If they don’t match, the application applies user-defined enforcement actions. Allstar is a companion to Security Scorecards, an automated risk assessment tool for repositories and their dependencies that was also contributed by Google.Īllstart continuously checks GitHub API states and file contents against defined security policies. The new application, named Allstar, was developed by Google and released through OpenSSF, of which the tech giant is a founding member.

The Open Source Security Foundation (OpenSSF) on Wednesday announced the availability of a new GitHub app that can be used to automatically and continuously enforce security best practices for GitHub projects.
