You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
adopt its suggestions to improve your project's security posture.
A preliminary run of the OpenSSF Scorecard has identified the following improvements that can be made to the project, followed by their risk level and a summary of the remediation steps:
This derives from a request by Google's security team, which is reproduced here:
Current status:![OpenSSF Scorecard](https://camo.githubusercontent.com/706ff74deed4f6ef6cb0c9c3fc91a3818bc16b5e2d29703ca8d2569b355a0681/68747470733a2f2f6170692e736563757269747973636f726563617264732e6465762f70726f6a656374732f6769746875622e636f6d2f676f6f676c652f7a65726f636f70792f6261646765)
Steps:
Integrate scorecard(Create .github/workflows/scorecard.yml #167)Grant scorecard more permissions to improve the fidelity of its analysis([CI] Grant Scorecard more permissions #258)Use dependabot to keep dependencies up-to-date(Use Dependabot GitHub Action #240)Pin to specific dependency version hashes in CIandscan PRs for vulnerable dependencies([CI] Apply StepSecurity recommendations #259)Restrict token permisions([CI] Only grant CI action "read" permission #261)The text was updated successfully, but these errors were encountered: