🌱 Add Posnic POS to weekly Scorecard projects - #5212
sridharkalaibala wants to merge 1 commit into
Conversation
Signed-off-by: Sridhar Bala <sridharkalaibala@gmail.com>
bilaldeveloper4312
left a comment
There was a problem hiding this comment.
Independent verification of the proposed project entry:\n\n- Posnic/POS resolves to a public, active organization repository; it is not archived or disabled, and GitHub reports AGPL-3.0.\n- Its default branch is develop.\n- .github/workflows/scorecard.yml is active on that branch and configures ossf/scorecard-action with publish_results: true.\n- Recent Scorecard workflow runs on develop are completing successfully (including https://github.com/Posnic/POS/actions/runs/33863367451).\n- The added CSV row is in the correct literal sort position between PoslavskySV/rings and Poss111/discord-hook-action; I found no existing Posnic entry in the current list.\n- The PR verifier, DCO, and Kusari checks are green.\n\nThis matches the repository's documented add-project workflow. Approved as an independent review; this is not maintainer acceptance authority.
|
@sridharkalaibala — Following our infrastructure move, we're restructuring a few things e.g., where new projects are added. Can you please refile this using the instructions in |
Summary
Adds
github.com/Posnic/POStocron/internal/data/projects.csvso OpenSSF Scorecard can include the public Posnic POS repository in weekly scans.Posnic POS is a public AGPL-3.0-only Electron/Node.js point-of-sale and billing application repository. The project already runs the OpenSSF Scorecard GitHub Action on its default development branch with
publish_results: true.Validation
ossf/scorecard.https://github.com/Posnic/POSis public, not archived, and licensed AGPL-3.0.cron/internal/data/projects.csvremains sorted by the literal repo column and contains exactly one case-insensitive Posnic entry with a local Node.js check.git diff --checkLocal tooling note: this Windows host does not have Go or GNU make installed, so I could not run
make add-projectsormake validate-projectslocally. The added row is placed where the repository'sSortAndAppendToordering puts canonicalgithub.com/Posnic/POS.Disclosure
I am submitting this on behalf of the Posnic project.