Skip to content

Conversation

@kelson42
Copy link
Contributor

@kelson42 kelson42 commented Apr 11, 2025

Update with latest version of the OSSF CI check

@kelson42 kelson42 force-pushed the fix-ossf-scorecard branch from 57a9876 to 0006349 Compare April 11, 2025 07:28
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@1b1aada464948af03b950897e5eb522f92603cc2 # v3.24.9
uses: github/codeql-action/upload-sarif@v3

Check warning

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 5: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help
@kelson42 kelson42 marked this pull request as ready for review April 11, 2025 07:31
@kelson42 kelson42 changed the title Use latest version of action/upload-artifact Update OSSF CI action Apr 11, 2025
@kelson42
Copy link
Contributor Author

We are impacted by kiwix/kiwix-build#770 for the two CI tasks failing. Merging anyway.

@kelson42 kelson42 merged commit 1422f97 into main Apr 11, 2025
27 of 29 checks passed
@kelson42 kelson42 deleted the fix-ossf-scorecard branch April 11, 2025 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants