Would we want to ever “trade and grade”? If that makes sense? I did a really shitty scan of our stuff the other day and I would be happy to begin collaborating on a small effort to just standardize the checks and keep an eye out for the broader community.
Here’s my work BTW — these have sense been fixed as far as I know.
https://github.com/hachyderm/security/blob/main/reports/2022-12-02/README.md