Skip to content

🐛 Split ko matcher so either setup-ko spelling is detected - #5195

Open
rylena wants to merge 1 commit into
ossf:mainfrom
rylena:fix/packaging-ko-matcher
Open

🐛 Split ko matcher so either setup-ko spelling is detected#5195
rylena wants to merge 1 commit into
ossf:mainfrom
rylena:fix/packaging-ko-matcher

fix(packaging): split ko matcher so either setup-ko spelling is detected

3cfb914
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Aug 24, 2026 in 44s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results

✅ Safe to merge

No flagged issues detected. All values appear to be within acceptable risk parameters.

What we checked

No pinned dependency version changes

The dependency analysis found no pinned version dependency changes in this Pull Request.

  • ✅ No vulnerabilities introduced
  • ✅ No supply chain concerns

Unpinned GitHub Actions in Scorecard test fixtures

Test data files under checks/testdata/.github/workflows/ intentionally contain mutable action tags to validate Scorecard's own unpinned-dependency detection logic, not real executed workflows.

  • ❌ Unpinned action tags present in test fixture files

    actions/checkout@v2, imjasonh/setup-ko@v0.6, and ko-build/setup-ko@v0.6 are used unpinned in checks/testdata/.github/workflows/ files, referenced by checks/fileparser/github_workflow_test.go as intentional legacy/renamed-action test scenarios.

    Fix: No action needed; pinning these would break the unit tests that validate Scorecard's pinned-dependencies check.

  • ✅ No workflow issues in production CI/CD

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 3cfb914, performed at: 2026-08-24T05:09:21Z