ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.39k stars 482 forks source link

Feature: Allow unpinned in non-privileged workflows #2018

Open laurentsimon opened 2 years ago

laurentsimon commented 2 years ago

Workflows that have no secret and all their permissions set to read/none don't benefit from being pinned, and add burden for users to keep them up to date. We may want to relax the Token-Permission check, making this a "bonus" point rather than flagging it as an problem

github-actions[bot] commented 5 months ago

This issue has been marked stale because it has been open for 60 days with no activity.