Configure OpenSSF Scorecard's Pinned-Dependencies
check to block CI
#1579
Labels
experience-medium
This issue is of medium difficulty, and requires some experience
help wanted
Extra attention is needed
OpenSSF Scorecard is configured on this repository, but it only runs periodically and generates reports like this one (inserting screen shots since these alerts are not publicly viewable):
It would be better if we could block PRs if they fail this check.
Mentoring instructions
Interested in contributing? See our contributing guide.
The text was updated successfully, but these errors were encountered: