mirror of
https://github.com/ossf/scorecard.git
synced 2024-11-04 03:52:31 +03:00
6868fe6f93
One reason to pin dependencies is that it's one way to counter dependency confusion attacks; mention that. Pinning dependencies is definitely not the *only* way, and it's not even clear it's the best way, but it's a legitimate reason to pin dependencies in applications. Signed-off-by: David A. Wheeler <dwheeler@dwheeler.com> |
||
---|---|---|
.. | ||
checks | ||
checks.md |