You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Right now, everything seems to be done by checking into master; there's no releases or tagging.I want to use ossf/scorecard but I'll get dinged for not pinning specific hashes. I can pin a specific git commit, but things like dependabot don't see a release so that's no help.
Looks like neither CIFuzz nor CFLite can be pinned properly so I'll go ahead and close #6836. CFLite can't be unpinned either though: google/clusterfuzzlite#95 so once it's resolved I'll unpin it and ignore scorecard.
Right now, everything seems to be done by checking into master; there's no releases or tagging.I want to use
ossf/scorecard
but I'll get dinged for not pinning specific hashes. I can pin a specific git commit, but things likedependabot
don't see a release so that's no help.Please see ossf/scorecard#1500 for some background.
The text was updated successfully, but these errors were encountered: