Skip to content

Does scorecard send info about my project somewhere? #3428

Answered by raghavkaul
flickerfly asked this question in Q&A
Discussion options

You must be logged in to vote

I wouldn't think so. We capture metrics in checker/check_runner.go but for basic CLI runs we don't set an exporter, so I don't think those go anywhere over a network. It's really just for metrics in the cron, which only scans public GitLab projects. In terms of side channel-y meanings of "send information," scorecard makes HTTP requests to the GitLab project's REST and GraphQL endpoints, from osv.dev (for the Vulnerabilities check) and from bestpractices.coreinfrastructure.org for the CII-Best-Practices check.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@flickerfly
Comment options

Answer selected by flickerfly

This comment was marked as off-topic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants