We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependencies are not pinned in the CodeQL workflow.
Having unpinned dependencies can reduce the project's quality score computed by 3rd parties (e.g. OpenSSF Scorecard).
Pin dependencies in CodeQL workflow.
While at it, also bump version of Go from 1.19 to 1.20.
The text was updated successfully, but these errors were encountered:
fxamacker
Successfully merging a pull request may close this issue.
Issue To Be Solved
Dependencies are not pinned in the CodeQL workflow.
Having unpinned dependencies can reduce the project's quality score computed by 3rd parties (e.g. OpenSSF Scorecard).
Suggested Solution
Pin dependencies in CodeQL workflow.
While at it, also bump version of Go from 1.19 to 1.20.
The text was updated successfully, but these errors were encountered: