Skip to content

Add security-gates workflow and update README

ad73f1b
Select commit
Loading
Failed to load commit list.
Open

feat: Add security-gates and update README #11

Add security-gates workflow and update README
ad73f1b
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Scorecard failed Jan 30, 2025 in 3s

3 new alerts including 2 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 high
  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 58 in .github/workflows/scorecard.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 8: GitHub-owned GitHubAction not pinned by hash
Click Remediation section below to solve this issue

Check failure on line 1 in .github/workflows/security-gates.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check failure on line 21 in .github/workflows/security-gates.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: jobLevel 'security-events' permission set to 'write'
Remediation tip: Verify which permissions are needed and consider whether you can reduce them.
Click Remediation section below for further remediation help