Description
The OpenSSF Scorecard identified that static code analysis (SAST) is not currently being run on all commits in the ScanAPI repository.
Running SAST tools on every commit helps detect potential vulnerabilities early in the development process and ensures consistent code quality and security coverage across the project.
📊 Scorecard Findings
Raw Output
Reason
SAST tool is not run on all commits -- score normalized to 7
Details
Warn: 23 commits out of 29 are checked with a SAST tool
✅ Tasks
🔗 References
Description
The OpenSSF Scorecard identified that static code analysis (SAST) is not currently being run on all commits in the ScanAPI repository.
Running SAST tools on every commit helps detect potential vulnerabilities early in the development process and ensures consistent code quality and security coverage across the project.
📊 Scorecard Findings
Raw Output
✅ Tasks
🔗 References