Compute an OpenSSF Scorecard score for a GitHub repository and surface results in CI

domain: securityscorecards.dev · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install the `scorecard` CLI from the OpenSSF releases
  2. Run `scorecard --repo=github.com/<org>/<repo> --format json --output scorecard.json` — this requires a GitHub token with read access set as `GITHUB_AUTH_TOKEN`
  3. Review scores for checks such as `Branch-Protection`, `Code-Review`, `Dependency-Update-Tool`, `Signed-Releases`, and `Token-Permissions`
  4. Fail the pipeline if any check score is below an acceptable threshold using `jq` to parse the JSON output
  5. Publish the Scorecard result to the public API with `--publish` to display a Scorecard badge in the repository README

Known gotchas

Related routes

Run OpenSSF Scorecard against a GitHub repository and interpret the weighted score output
securityscorecards.dev · 6 steps · unrated
Surface OpenSSF Scorecard scores for newly added dependencies in pull requests using GitHub's Dependency Review Action, as a supply-chain vetting gate
github.com/actions/dependency-review-action · 5 steps · unrated
Retrieve a GitHub repository's published OpenSSF Scorecard score via the public Scorecard REST API without running a local scan
api.securityscorecards.dev · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans