Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(ci): OSSF Changes #1769

Merged
merged 15 commits into from
Feb 17, 2025
Merged

fix(ci): OSSF Changes #1769

merged 15 commits into from
Feb 17, 2025

Conversation

sthulb
Copy link
Contributor

@sthulb sthulb commented Feb 14, 2025

Issue #, if available:

Description of changes:

In order to comply with OSSF, I've created this PR to:

  • Pin dependencies in the docs Dockerfile
  • Remove executables (gradle-wrapper)
  • Pinned the OSV workflow to a hash

These should remove 5 advisories from the project

Checklist

Breaking change checklist

RFC issue #:

  • Migration process documented
  • Implement warnings (if it can live side by side)

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@pull-request-size pull-request-size bot added size/M and removed size/S labels Feb 14, 2025
@phipag phipag self-requested a review February 14, 2025 13:54
@pull-request-size pull-request-size bot added size/L and removed size/M labels Feb 14, 2025
@sthulb sthulb merged commit ed89b3c into main Feb 17, 2025
13 of 17 checks passed
@sthulb sthulb deleted the ossf branch February 17, 2025 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants