Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin Github actions dependencies #421

Conversation

stephenpaulger
Copy link
Contributor

I've made this change to try to improve mark's OpenSSF ScoreCard. ScoreCard has a check for pinned dependencies, including those used in the CI workflow. Currently mark has 0/10 for pinned dependencies and a contributor to that is not having used pinned actions. A good ScoreCard score can be helpful to users in enterprise environments where there is a need to show that thought has been given to the security of tools being used.

mark is already using dependabot and it looks to be configured to update github actions, it understands this format and will continue to send PRs to update dependencies in the CI.

@stephenpaulger
Copy link
Contributor Author

This is out of date now, if you'd like to consider doing this you can let me know and I can redo it.

@stephenpaulger
Copy link
Contributor Author

Closing this for now.

@stephenpaulger stephenpaulger deleted the pin-workflow-dependencies branch April 10, 2024 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant