OpenSSF Scorecard evaluates my projects

1 · Jordan Sissel · Sept. 23, 2022, 4 a.m.
Like so many things in business, it feels inevitable that we reduce everything to some numerical value through a kind of lossy information compression. Revenue, margins, etc. Risk gets quantized. Vulnerabilities get quantized. Once it’s a quantity, there becomes an urge to monitor it, optimize it, and game it. At the speed of business these days(1), who has time to evaluate a vulnerability’s impact on your operations when we can simply say “If it’s got a score of 8 or higher, we take immediate a...