Documentation
¶
Overview ¶
Package ossf wraps the OpenSSF Scorecard public API (api.securityscorecards.dev). The API returns repo-level project quality assessments with an aggregate score (0–10) and a list of per-check results. The endpoint is unauthenticated and accepts only GET requests; we make small, bounded calls behind a short timeout.
Per-check scores: -1 means the check did not apply (e.g., Fuzzing on a docs-only repo); 0–10 are real scores. Callers should preserve the distinction when surfacing results to users.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrNotFound = errors.New("ossf scorecard: not found")
ErrNotFound is returned when the OSSF API has no scorecard for the requested repo. This is a normal outcome (small or new repos), not a transport error — callers should treat it as "no data" rather than failure.
Functions ¶
This section is empty.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client is the OSSF Scorecard HTTP client.
func NewClient ¶
NewClient returns a Client with the given timeout. A zero or negative timeout falls back to a sane default; callers should not run unbounded — the OSSF API has been known to return large responses for large monorepos.
type Scorecard ¶
type Scorecard struct {
Score float64
Date time.Time
Commit string
ScorecardVer string
Checks []Check
}
Scorecard is the parsed response. Only fields we surface are kept; the upstream payload includes additional metadata (raw check details, remediation hints) that we currently do not display.