Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Enforce pinned pip dependencies #827

Conversation

rettichschnidi
Copy link
Contributor

@rettichschnidi rettichschnidi commented Nov 15, 2024

This should give us a 10/10 OpenSSF rating for pinned dependencies.

It has been done all by hand, trough trial and error. Feels like there should be some better tooling for this out there...

@rettichschnidi rettichschnidi force-pushed the gardena/rs/upstream/pin-dependencies-3 branch from f5b929f to 17d1b00 Compare November 17, 2024 11:29
This should give us a 10/10 OpenSSF rating for pinned dependencies.
@rettichschnidi rettichschnidi force-pushed the gardena/rs/upstream/pin-dependencies-3 branch from 17d1b00 to 43e3f88 Compare November 17, 2024 12:20
@rettichschnidi rettichschnidi marked this pull request as ready for review November 17, 2024 13:23
Copy link
Contributor

@LukasWoodtli LukasWoodtli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool!

@rettichschnidi rettichschnidi merged commit d28bd14 into eclipse-wakaama:main Nov 18, 2024
34 checks passed
@rettichschnidi
Copy link
Contributor Author

Cool!

Let's see if we think the same a few months down the road. :)

@rettichschnidi rettichschnidi deleted the gardena/rs/upstream/pin-dependencies-3 branch November 18, 2024 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants