Skip to content

Configure OpenSSF Scorecard's Pinned-Dependencies check to block CI #1579

Open
@joshlf

Description

@joshlf

OpenSSF Scorecard is configured on this repository, but it only runs periodically and generates reports like this one (inserting screen shots since these alerts are not publicly viewable):

Screenshot 2024-08-08 at 8 33 31 AM Screenshot 2024-08-08 at 8 34 01 AM

It would be better if we could block PRs if they fail this check.

Mentoring instructions

Interested in contributing? See our contributing guide.

  • Figure out how to run the Pinned-Dependency check in CI
  • Ensure all dependencies reported by this check are pinned

Metadata

Metadata

Assignees

Labels

experience-mediumThis issue is of medium difficulty, and requires some experiencehelp wantedExtra attention is needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions