ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.46k stars 489 forks source link

Add more options for Pinned-Dependencies #3618

Open gabibguti opened 11 months ago

gabibguti commented 11 months ago

Is your feature request related to a problem? Please describe. I would like to start a discussion to add more options for Pinned-Dependencies. Currently we check dependencies of:

I would like to mention the possibility of including Cargo dependencies and leave the issue open if more dependencies of other ecossystems are needed.

Describe the solution you'd like Including Cargo dependencies to provide better support for Rust projects.

Describe alternatives you've considered None.

Additional context Related to: https://github.com/ossf/scorecard-action/issues/1017#issuecomment-1783094528

github-actions[bot] commented 9 months ago

This issue is stale because it has been open for 60 days with no activity.