openssf scorecard suggested improvements

This commit is contained in:
Mick Grove 2026-03-19 20:45:58 -07:00
commit d637a7b6fb
4 changed files with 5 additions and 6 deletions

View file

@ -26,6 +26,8 @@ jobs:
id-token: write id-token: write
steps: steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_sha || github.sha }}
- name: Determine version/tag - name: Determine version/tag
id: version id: version

View file

@ -48,6 +48,8 @@ jobs:
# otherwise just use the SHA tied to the release / manual dispatch. # otherwise just use the SHA tied to the release / manual dispatch.
# ----------------------------------------------------------------------- # -----------------------------------------------------------------------
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_sha || github.sha }}
# ----------------------------------------------------------------------- # -----------------------------------------------------------------------
# Decide which tag were going to publish # Decide which tag were going to publish

View file

@ -10,7 +10,7 @@ jobs:
# Compute SHA256 hashes of all release assets # Compute SHA256 hashes of all release assets
hash: hash:
name: Compute artifact hashes name: Compute artifact hashes
runs-on: ubuntu-latest runs-on: ubuntu-24.04
permissions: permissions:
contents: read contents: read
outputs: outputs:

View file

@ -2,11 +2,6 @@
## Reporting a Vulnerability ## Reporting a Vulnerability
If you discover a security vulnerability in Kingfisher, please report it
responsibly. **Do not open a public GitHub issue.**
## Reporting a Vulnerability
If you discover a security vulnerability in Kingfisher, please follow MongoDB's responsible disclosure process: If you discover a security vulnerability in Kingfisher, please follow MongoDB's responsible disclosure process:
- **Do not publicly disclose the vulnerability.** - **Do not publicly disclose the vulnerability.**