mirror of
https://github.com/getnora-io/nora.git
synced 2026-04-12 19:40:31 +00:00
- Pin all GitHub Actions by SHA hash (Pinned-Dependencies) - Add top-level permissions: read-all (Token-Permissions) - Add explicit job-level permissions (least privilege) - Add OpenSSF Scorecard workflow with weekly schedule - Publish scorecard results to scorecard.dev and GitHub Security tab
6.6 KiB
6.6 KiB