OpenSSF Scorecard
Webhooks + Contributors + Score

OpenSSF Scorecard OSSFSC-7: Webhook Authentication, Contributors Diversity, Aggregate Score

Operate webhook authentication + contributors diversity + aggregate scoring per OpenSSF Scorecard checks Webhooks + Contributors + aggregate score. Webhooks Authenticated must (a) verify webhook authentication tokens at endpoints + (b) avoid unauthenticated webhook endpoints + (c) rotate webhook secrets + (d) monitor webhook abuse. Contributors From Multiple Organisations assesses (a) presence of contributors from multiple organisations indicating broader project sustainability + (b) is a sustainability signal not security control directly. Aggregate Scorecard Score and Threshold must (a) compute aggregate Scorecard score from individual check results + (b) maintain score threshold appropriate to project criticality + (c) integrate score with consumption decisions + dependency review + procurement + (d) track score over time + with improvement objectives. Use Scorecard as continuous indicator + with action on declining trends + with executive visibility for high-criticality projects.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.