Skip to content

Conversation

@osyniakov
Copy link
Contributor

Description

Pinned pipenv and its dependencies by hash to make scorecard check pass while waiting for a reply regarding best practices ossf/scorecard#4834

How was this PR tested?

n/a

@osyniakov
Copy link
Contributor Author

@guilload could you please check this one?

@guilload
Copy link
Member

guilload commented Nov 4, 2025

Is there a public place to see the scorecard? Is there way to get notified if we break something and we are no longer compliant?
Would you quickly document what you did to secure the repo / software in some SECURITY.md file at the root of the repo for instance?

@guilload guilload merged commit bbc5542 into quickwit-oss:main Nov 4, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants