-
Notifications
You must be signed in to change notification settings - Fork 0
[test][maven-lockfile] add dirty-waters #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Software Supply Chain Report of randomicecube/maven-lockfile - 42c33ffThis report is a gradual report: that is, only the highest severity smell type with issues found within this project is reported. All available checks were performed. How to read the results 📖Dirty-waters has analyzed your project dependencies and found different categories for each of them:
Total packages in the supply chain: 421🔧 Packages with inaccessible commit SHA/tag ( ❗ Packages with no source code URL ( ⛔ Packages with repo URL that is 404 ( 🔓 Packages with invalid code signature ( 🔒 Packages without code signature ( Fine grained information🐬 For further information about software supply chain smells in your project, take a look at the following tables. All packages have accessible tags. Source code links that could not be found(11)
Call to Action:👻What do I do now?For packages without source code & accessible SHA/release tags:
For deprecated packages:
For packages without code signature:
For packages with invalid code signature:
For packages without provenance:
For packages that are aliased:
NotesOther info:
Report created by dirty-waters. Report created on 2025-05-11 22:27:57
|
…res; just checking signatures
No description provided.