Skip to content

Conversation

@OskarStark
Copy link

Or is there a specific reason for the commit hashes?

@spencerschrock
Copy link
Member

Or is there a specific reason for the commit hashes?

It's intentional, for security and stability reasons. Here are some resources where we/others try to explain our rationale.

https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies
https://github.com/sethvargo/ratchet#problem-statement

That being said, the versions/SHAs in are README are out of date and could use an update. If you'd like to update them I'd be happy to review the contribution, otherwise feel free to close this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants