Skip to content

Conversation

@gcanlin
Copy link

@gcanlin gcanlin commented Jul 1, 2025

Related to #197, I add the scorecard and dependabot workflows. Scorecard helps automatically assess and improve project security and quality with every code change.

* [StepSecurity] Apply security best practices

Signed-off-by: StepSecurity Bot <[email protected]>

* Update dependabot.yml

---------

Signed-off-by: StepSecurity Bot <[email protected]>
Co-authored-by: Canlin Guo <[email protected]>
@gcanlin
Copy link
Author

gcanlin commented Jul 1, 2025

If you set up this configuration, it will send a report to help you improve the security of your project as the following picture shows. Besides, it can also help promote your project by reducing users’ security concerns.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants