It seems like an awful waste for me to run these on each of my dependencies in real time. I expected some list that is just maintained and pinged for values. Also, this scorecard doesn’t look for CVEs or problems in particular versions. It seems like it’s much more important that there’s a valid vulnerability in version 1.04 that I’m using than the current version has code reviews for everything. The reason I care is…
I think you miss the point then. The things it's looking for are indicators security practices are even in place. If you wanted vuln scanning, many solutions for that today exist. This is almost like a reputation score. The higher it is, the more likely vulnerabilities will be addressed in the future (or outright prevented). I like the idea, I think it will just be tough to work out the right heuristics.
Also the name is “scorecard” that again connotes that a high score is good. I don’t get a 10/10 on my assignment because I did my homework, said hello to the teacher each morning, and was polite to my classmates.
Those are all positive things and if I wanted to measure students they may be a part of the grade. But if I only graded on these factors that’s not terribly useful.
Process measures are good when it’s not possible to measure outcome, but I think in this situation more outcome measures could be factored in.