start discussion with ossf/scorecard team to build an initial prototype
Goals:
- new functionality added to scorecard app in a topic branch
- demonstrate reading from rulesets and repositories APIs to validate at least one best practice
- demonstrate summarization of those findings into a check that can fail the merge of non-compliant code.
We should file a FR here: https://github.com/ossf/scorecard/issues
And join a community meeting to discuss. Apparently the next one is Oct 17th.
@zachariahcox do you have time to pursue this?
Possibly a starting point: https://github.com/ossf/scorecard/issues/3352
FYI I attended the Scorecards meeting today to discuss. Folks are open to it. Notes here https://docs.google.com/document/d/1b6d3CVJLsl7YnTE7ZaZQHdkdYIvuOQ8rzAmvVdypOWM/edit?tab=t.0#heading=h.5r8j0smn6u10
Still TBD is who would do this work. (and actually getting a concrete proposal in place to be agreed on more formally)
They weren't interested in this. In the meantime we created our own prototype.