Bring all monitored repositories to 100% in CLOMonitor

Open
#104 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
50/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
github-actions

Research direction

Start with the linked CLOMonitor report and the named repositories, comparing each repository's release status and compliance checks. Inspect .github/workflows/build-verify.yml in microcks-docker-desktop-extension and the .clomonitor.yml files for the two source-only GitHub Actions. Done means every monitored repository reports 100% after the next CLOMonitor refresh.

Written by the indexing model from the issue text.

Description

The CLOMonitor audit conducted on 2026-09-18 reports an overall Microcks score of 98.49% (A). Fourteen of the twenty monitored repositories are already at 100%.

The remaining work is:

  • hub.microcks.io: publish a recent release.
  • microcks-backstage-provider: publish a recent release.
  • microcks-jenkins-plugin: publish a recent release.
  • import-github-action: publish a recent release and address the SBOM and signed-release checks.
  • test-github-action: publish a recent release and address the SBOM and signed-release checks.
  • microcks-docker-desktop-extension:
    • Publish a recent release.
    • Provide or document an SBOM.
    • Sign the release artifacts or provide provenance.
    • Define restrictive GITHUB_TOKEN permissions in .github/workflows/build-verify.yml.

For the two source-only GitHub Actions, maintainers should decide whether to produce signed release artifacts and SBOMs or declare documented exemptions in each repository's .clomonitor.yml when those checks are not applicable.

References:

Completion criteria: every monitored repository reports 100% after the next CLOMonitor refresh.

Dominant language
No language data
Stars
8
Forks
41
Avg merge
1d 1h
Merged PRs (30d)
7

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microcks/.github

All issues in microcks/.github

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.