OpenSSF Scorecard
Medium-risk checks – OpenSSF Scorecard

OpenSSF Scorecard Packaging: Packaging check

Scorecard checks whether the project publishes a package, looking for GitHub packaging workflows and language-specific actions that upload to a package hub such as npm or PyPI. Packages let users install and receive security updates through a package manager. Other packaging routes may go undetected.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Medium-risk checks – OpenSSF Scorecard

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.