🐛 Split ko matcher so either setup-ko spelling is detected - #5195
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results
✅ Safe to merge
No flagged issues detected. All values appear to be within acceptable risk parameters.
What we checked
No pinned dependency version changes
The dependency analysis found no pinned version dependency changes in this Pull Request.
- ✅ No vulnerabilities introduced
- ✅ No supply chain concerns
Unpinned GitHub Actions in Scorecard test fixtures
Test data files under checks/testdata/.github/workflows/ intentionally contain mutable action tags to validate Scorecard's own unpinned-dependency detection logic, not real executed workflows.
-
❌ Unpinned action tags present in test fixture files
actions/checkout@v2, imjasonh/setup-ko@v0.6, and ko-build/setup-ko@v0.6 are used unpinned in checks/testdata/.github/workflows/ files, referenced by checks/fileparser/github_workflow_test.go as intentional legacy/renamed-action test scenarios.
⇨ Fix: No action needed; pinning these would break the unit tests that validate Scorecard's pinned-dependencies check.
-
✅ No workflow issues in production CI/CD
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 3cfb914, performed at: 2026-08-24T05:09:21Z