Skip to content

📖 Clarify shell script pinned dependencies - #5154

Open
rylena wants to merge 1 commit into
ossf:mainfrom
rylena:docs-pinned-deps-shell-hash
Open

📖 Clarify shell script pinned dependencies#5154
rylena wants to merge 1 commit into
ossf:mainfrom
rylena:docs-pinned-deps-shell-hash

Conversation

@rylena

@rylena rylena commented Aug 2, 2026

Copy link
Copy Markdown

Summary

  • clarify how shell scripts can remediate Pinned-Dependencies findings for download-and-run build/release artifacts
  • update the generated check documentation from checks.yaml

Fixes #3401

Verification

  • go run ./docs/checks/internal/generate docs/checks.md
  • go test ./docs/checks/...
  • go run ./docs/checks/internal/validate
  • git diff --check

Signed-off-by: Rylen Anil <rylen.anil@gmail.com>
@dosubot dosubot Bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Aug 2, 2026
@dosubot

dosubot Bot commented Aug 2, 2026

Copy link
Copy Markdown

📄 Knowledge review

Dosu skipped reviewing this PR because your organization has used its 200 included credits for the month. Your usage will reset on 2026-09-01. To have Dosu review this PR before then, ask your organization admin to upgrade to a pro account.


Leave Feedback Ask Dosu about scorecard Add Dosu to your team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

How to mitigate C or bash pinned dependencies?

1 participant