-
-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
Signed-off-by: rjdbcm <[email protected]>
- Loading branch information
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -36,6 +36,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
@@ -65,6 +66,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
@@ -94,6 +96,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -38,6 +38,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
@@ -68,6 +69,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
@@ -98,6 +100,7 @@ jobs: | |
fulcio.sigstore.dev:443 | ||
rekor.sigstore.dev:443 | ||
tuf-repo-cdn.sigstore.dev:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
with: | ||
|
@@ -179,6 +182,7 @@ jobs: | |
quay.io:443 | ||
cdn03.quay.io:443 | ||
downloads.python.org:443 | ||
oauth2.sigstore.dev:443 | ||
- uses: OZI-Project/[email protected] | ||
Check warning Code scanning / Scorecard Pinned-Dependencies Medium
score is 7: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io Click Remediation section below for further remediation help |
||
id: release | ||
|