security: pin all pre-commit hooks to SHA
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 58/100
Research direction
Start by locating the repository's pre-commit configuration and compare its hook revisions with the referenced Apache examples. Check each hook entry for an immutable commit SHA, then verify that all configured hooks are pinned and review the linked trusted-releases issue for any project-specific requirements.
Written by the indexing model from the issue text.
Description
- Dominant language
- HTML
- Stars
- 10
- Forks
- 8
- Avg merge
- 12h 24m
- Merged PRs (30d)
- 8
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Similar issues
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Nmap
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
blocklist removal
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
MetaMask/eth-phishing-detect#296544 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Azure/azure-functions-docker#1257 ·