Skip to content

🌱 Add Posnic POS to weekly Scorecard projects - #5212

Closed
sridharkalaibala wants to merge 1 commit into
ossf:mainfrom
sridharkalaibala:add-posnic-scorecard
Closed

sridharkalaibala wants to merge 1 commit into
ossf:mainfrom
sridharkalaibala:add-posnic-scorecard

Conversation

@sridharkalaibala

Copy link
Copy Markdown

Summary

Adds github.com/Posnic/POS to cron/internal/data/projects.csv so OpenSSF Scorecard can include the public Posnic POS repository in weekly scans.

Posnic POS is a public AGPL-3.0-only Electron/Node.js point-of-sale and billing application repository. The project already runs the OpenSSF Scorecard GitHub Action on its default development branch with publish_results: true.

Validation

  • Confirmed no existing open PR for Posnic in ossf/scorecard.
  • Confirmed https://github.com/Posnic/POS is public, not archived, and licensed AGPL-3.0.
  • Verified cron/internal/data/projects.csv remains sorted by the literal repo column and contains exactly one case-insensitive Posnic entry with a local Node.js check.
  • git diff --check

Local tooling note: this Windows host does not have Go or GNU make installed, so I could not run make add-projects or make validate-projects locally. The added row is placed where the repository's SortAndAppendTo ordering puts canonical github.com/Posnic/POS.

Disclosure

I am submitting this on behalf of the Posnic project.

Signed-off-by: Sridhar Bala <sridharkalaibala@gmail.com>
@sridharkalaibala
sridharkalaibala requested a review from a team as a code owner September 2, 2026 12:28
@sridharkalaibala
sridharkalaibala requested review from AdamKorcz and spencerschrock and removed request for a team September 2, 2026 12:28

@bilaldeveloper4312 bilaldeveloper4312 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent verification of the proposed project entry:\n\n- Posnic/POS resolves to a public, active organization repository; it is not archived or disabled, and GitHub reports AGPL-3.0.\n- Its default branch is develop.\n- .github/workflows/scorecard.yml is active on that branch and configures ossf/scorecard-action with publish_results: true.\n- Recent Scorecard workflow runs on develop are completing successfully (including https://github.com/Posnic/POS/actions/runs/33863367451).\n- The added CSV row is in the correct literal sort position between PoslavskySV/rings and Poss111/discord-hook-action; I found no existing Posnic entry in the current list.\n- The PR verifier, DCO, and Kusari checks are green.\n\nThis matches the repository's documented add-project workflow. Approved as an independent review; this is not maintainer acceptance authority.

@justaugustus

justaugustus commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

@sridharkalaibala — Following our infrastructure move, we're restructuring a few things e.g., where new projects are added.

Can you please refile this using the instructions in ossf/scorecard-infra: https://github.com/ossf/scorecard-infra/blob/main/CONTRIBUTING.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants