You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Jointly closed by explicit maintainer agreement (2026-05-17). #72 SAST fixed via modshells#41 (CodeQL matrix → actions; auto-clears on next Scorecard run). #63 (Pinned-Deps/SLSA) and #44 (Maintained) are no longer open code-scanning alerts. Validated live by hyperpolymath/hypatia ScorecardReconciler (2026-05-17): found=1 (only #72, action=fix), recurrence_defects=[], decision recorded to the offline registry. Refs hyperpolymath/hypatia#260.
Refs hyperpolymath/hypatia#260 (root-cause + anti-recurrence). Do not auto-close.
javascript-typescript; repo is Ada/Scheme/Shell so CodeQL recorded 0 results → "0/7 commits checked". Fix: matrix →language: actions(always scannable, runs every commit). (this PR)generator-generic-ossf-slsa3-publish.yml:68usesslsa-framework/slsa-github-generator/...@v2.1.0. SHA-pinning the SLSA generator is harmful (it self-verifiesgithub.ref; SHA-ref → invalid provenance). Accepted false-positive → dismissed with rationale.