GitHub: dependency submission: fix main branch name #9
dependency-review-action.yml
on: pull_request
dependency-submission
1m 51s
Annotations
1 error, 10 warnings, and 1 notice
dependency-submission
Dependency review detected vulnerable packages.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-android-extensions has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-assignment has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-assignment-compiler-plugin-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-build-tools-api has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-compiler-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-compiler-runner has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-daemon-client has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-daemon-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-gradle-plugin has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-gradle-plugin-annotations has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
dependency-submission
Submitted dependency-graph-reports/dependency_review_for_pull_requests-dependency-submission.json: The snapshot was accepted, but it is not for the default branch. It will not update dependency results for the repository.
|