statuses
statuses copied to clipboard
chore: pin dependencies and specify permissions in the pipeline
Main Changes
This change includes the pinning for the GitHub Actions dependencies and the permissions definition for the pipeline.
Impact in the OSSF Scorecard
Context
Changes related
- OSSF Scorecard Documentation | Tokens permissions
- OSSF Scorecard Documentation | Pinned dependencies
Team discussion related
- Ref: https://github.com/expressjs/security-wg/issues/2
- Report: https://kooltheba.github.io/openssf-scorecard-api-visualizer/#/projects/github.com/jshttp/statuses/commit/454ceb6e0bfea4f889be244de2538df8afb4dc2a