chore: upgrade scorecard workflow pinned action versions
Upgrade scorecard workflow pinned action versions to latest versions.
Issue https://github.com/expressjs/security-wg/issues/2
Can we move these into another repo instead? https://github.com/expressjs/security-wg/issues/31
Why are we upgrading? What’s changed? This doesn’t fix that scorecard workflows turn themselves off when the repo isn’t popular right?
I agree with @blakeembrey. I dont see a reason to close this until we get together a plan that doesn't involve so much distribute work. Centralizing it seems like a great way, and I think this is part of the next round of already planned work right?
So far seems like centralization is not simple in this case https://github.com/expressjs/security-wg/issues/31#issuecomment-2813048690, so I will like to unblock this PR :smile: