Skip to content

Bring all monitored repositories to 100% in CLOMonitor #104

Description

@yada

The CLOMonitor audit conducted on 2026-09-18 reports an overall Microcks score of 98.49% (A). Fourteen of the twenty monitored repositories are already at 100%.

The remaining work is:

  • hub.microcks.io: publish a recent release.
  • microcks-backstage-provider: publish a recent release.
  • microcks-jenkins-plugin: publish a recent release.
  • import-github-action: publish a recent release and address the SBOM and signed-release checks.
  • test-github-action: publish a recent release and address the SBOM and signed-release checks.
  • microcks-docker-desktop-extension:
    • Publish a recent release.
    • Provide or document an SBOM.
    • Sign the release artifacts or provide provenance.
    • Define restrictive GITHUB_TOKEN permissions in .github/workflows/build-verify.yml.

For the two source-only GitHub Actions, maintainers should decide whether to produce signed release artifacts and SBOMs or declare documented exemptions in each repository's .clomonitor.yml when those checks are not applicable.

References:

Completion criteria: every monitored repository reports 100% after the next CLOMonitor refresh.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions