Skip to content

Configure OpenSSF Scorecard's Pinned-Dependencies check to block CI #1579

Open

Description

OpenSSF Scorecard is configured on this repository, but it only runs periodically and generates reports like this one (inserting screen shots since these alerts are not publicly viewable):

Screenshot 2024-08-08 at 8 33 31 AM Screenshot 2024-08-08 at 8 34 01 AM

It would be better if we could block PRs if they fail this check.

Mentoring instructions

Interested in contributing? See our contributing guide.

  • Figure out how to run the Pinned-Dependency check in CI
  • Ensure all dependencies reported by this check are pinned
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    experience-mediumThis issue is of medium difficulty, and requires some experiencehelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions