This repository has been archived by the owner on Nov 18, 2024. It is now read-only.
Lock Dependency Versions #84
Labels
campaign-eng-infra
Evolving infrastructure supporting Engineering efforts
All dependencies should be explicitly set; no version ranges. Locked versions reduce several security risks:
It comes with the tradeoff of inhibiting dependency updates for a vulnerability fix. To mitigate this we need to use automated tools that detect such VULNs and also notify about outdated dependencies.
Reference: https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies
The text was updated successfully, but these errors were encountered: