Run OpenSSF Scorecard against a GitHub repository and interpret the weighted score output

domain: securityscorecards.dev · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install the scorecard binary from the OpenSSF Scorecard GitHub releases or use 'go install' to build it
  2. Set the GITHUB_AUTH_TOKEN environment variable to a GitHub personal access token with read-only public repo access
  3. Run 'scorecard --repo github.com/org/repo' and wait for all checks to complete
  4. Review the per-check scores out of 10 and the overall weighted score; higher-weight checks like Dangerous-Workflow and Token-Permissions have more impact on the aggregate
  5. Use '--format json' to capture machine-readable results for trend tracking or dashboard ingestion
  6. Identify checks with low scores and use the 'reason' field in the output to understand what remediation is needed

Known gotchas

Related routes

Compute an OpenSSF Scorecard score for a GitHub repository and surface results in CI
securityscorecards.dev · 5 steps · unrated
Retrieve a GitHub repository's published OpenSSF Scorecard score via the public Scorecard REST API without running a local scan
api.securityscorecards.dev · 5 steps · unrated
Configure the OpenSSF Scorecard GitHub Action to run on every pull request and publish results to GitHub Code Scanning
securityscorecards.dev · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans