ossf

package
v0.26.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 12, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package ossf wraps the OpenSSF Scorecard public API (api.securityscorecards.dev). The API returns repo-level project quality assessments with an aggregate score (0–10) and a list of per-check results. The endpoint is unauthenticated and accepts only GET requests; we make small, bounded calls behind a short timeout.

Per-check scores: -1 means the check did not apply (e.g., Fuzzing on a docs-only repo); 0–10 are real scores. Callers should preserve the distinction when surfacing results to users.

Index

Constants

This section is empty.

Variables

View Source
var ErrNotFound = errors.New("ossf scorecard: not found")

ErrNotFound is returned when the OSSF API has no scorecard for the requested repo. This is a normal outcome (small or new repos), not a transport error — callers should treat it as "no data" rather than failure.

Functions

This section is empty.

Types

type Check

type Check struct {
	Name   string
	Score  int
	Reason string
	DocURL string
}

Check is a single check result.

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client is the OSSF Scorecard HTTP client.

func NewClient

func NewClient(timeout time.Duration) *Client

NewClient returns a Client with the given timeout. A zero or negative timeout falls back to a sane default; callers should not run unbounded — the OSSF API has been known to return large responses for large monorepos.

func (*Client) Fetch

func (c *Client) Fetch(ctx context.Context, owner, repo string) (*Scorecard, error)

Fetch retrieves the scorecard for the given GitHub-hosted repo. owner and repo must both be non-empty. Returns ErrNotFound for a 404; any other non-2xx is wrapped as an error with the status code.

type Scorecard

type Scorecard struct {
	Score        float64
	Date         time.Time
	Commit       string
	ScorecardVer string
	Checks       []Check
}

Scorecard is the parsed response. Only fields we surface are kept; the upstream payload includes additional metadata (raw check details, remediation hints) that we currently do not display.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL