Skip to content

Security request: onboard to scorecard.dev to highlight existing vulnerabilities in the dependency chain. #498

@RoyalOughtness

Description

@RoyalOughtness

https://scorecard.dev can help identify vulnerable packages in a project's dependencies, and other risky practices.

For example for sigstore, sigstore requires json-syntax (which is barely maintained), json-syntax requires locspan-derive (which is unmaintained), and locspan-derive requires proc-macro-error, which is dead and superceded by proc-macro-error2: rust-lang/docs.rs#2595

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions