Skip to content

Docs?: Why do a few of the dependencies for the OpenSSF scorecard get invalid repository, and why are they not shown in the mvn related PR´s? (but in NPM).. #34761

Discussion options

You must be logged in to vote

To get a score:

  • Renovate must be able to determine the source repo of the package. This is not always available from registries
  • The OpenSSF must have scored that same repo

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@janderssonse
Comment options

@janderssonse
Comment options

@rarkins
Comment options

Answer selected by janderssonse
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants