ossf/scorecard-webapp

Docs: clarify wording around security risk

开放

#639 创建于 2024年5月27日

 (0 条评论) (0 个反应) (0 位负责人)Go (30 个派生)auto 404
documentationgood first issuehelp wanted

仓库指标

星标
 (29 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

The following feedback to the scorecard website was reported at https://github.com/ossf/alpha-omega/issues/359

The The checks section of the homepage starts with:

The checks collect together security best practises and industry standards

The riskiness of each vulnerability is based on how easy it is to exploit. For example if something can be exploited via a pull request, we consider that a high risk.

The example (described in the last sentence quoted) is very hard to understand. I cannot figure out what "something can be exploited via a pull request" means.

It would help to give an example of what "something" can be and to clarify what you mean by "a pull request".

By the way: Sentences should be terminated with a full stop ("."), including the one opening the section.

贡献者指南