{"date":"2026-08-17","repo":{"name":"github.com/medusajs/medusa","commit":"b33f14a334769e9265b2c7ff1b120db183bc1e07"},"scorecard":{"version":"v5.5.1-0.20260815060127-d1fab88f5463","commit":"d1fab88f54636ff366076edfc5c239f97b3c8e66"},"score":5.6,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}},{"name":"Code-Review","score":5,"reason":"Found 14/25 approved changesets -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/cloud-docs-automation.yml:13","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/cloud-webhooks-docs-automation.yml:18","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/docs-automation.yml:25","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/docs-staging-sync.yml:16","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/draft-release.yml:23","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/dx-triage-doc-fixes.yml:22","Info: jobLevel 'contents' permission set to 'read': .github/workflows/review-pr-action.yml:75","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/review-pr-action.yml:76","Info: jobLevel 'issues' permission set to 'read': .github/workflows/review-pr-action.yml:77","Info: jobLevel 'contents' permission set to 'read': .github/workflows/review-pr-action.yml:334","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/review-prs.yml:29","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/triage-dependabot-alerts.yml:58","Info: jobLevel 'contents' permission set to 'read': .github/workflows/triage-issue-action.yml:66","Info: jobLevel 'issues' permission set to 'read': .github/workflows/triage-issue-action.yml:67","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/triage-issue-action.yml:71","Info: jobLevel 'contents' permission set to 'read': .github/workflows/triage-issue-action.yml:288","Info: jobLevel 'issues' permission set to 'read': .github/workflows/triage-issues.yml:29","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/tsdoc-generation.yml:30","Warn: no topLevel permission defined: .github/workflows/action.yml:1","Warn: no topLevel permission defined: .github/workflows/admin-i18n-validation.yml:1","Warn: no topLevel permission defined: .github/workflows/algolia-api-indexer.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/close-linked-prs.yml:20","Warn: no topLevel permission defined: .github/workflows/cloud-docs-automation.yml:1","Warn: no topLevel permission defined: .github/workflows/cloud-webhooks-docs-automation.yml:1","Warn: no topLevel permission defined: .github/workflows/create-linear-issue-on-discussion.yml:1","Warn: no topLevel permission defined: .github/workflows/create-linear-issue-on-pr.yml:1","Warn: no topLevel permission defined: .github/workflows/discord-issue-labels.yml:1","Warn: no topLevel permission defined: .github/workflows/docs-automation.yml:1","Warn: no topLevel permission defined: .github/workflows/docs-staging-sync.yml:1","Warn: no topLevel permission defined: .github/workflows/docs-test.yml:1","Warn: no topLevel permission defined: .github/workflows/docs-update-version.yml:1","Warn: no topLevel permission defined: .github/workflows/draft-release.yml:1","Warn: no topLevel permission defined: .github/workflows/dx-triage-doc-fixes.yml:1","Warn: no topLevel permission defined: .github/workflows/generate-public-references.yml:1","Warn: no topLevel permission defined: .github/workflows/notify-docs-consumers.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/nudge-preview-bump.yml:23","Warn: no topLevel permission defined: .github/workflows/oas-test.yml:1","Warn: no topLevel permission defined: .github/workflows/release-notifications.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release.yml:17","Warn: topLevel 'actions' permission set to 'write': .github/workflows/release.yml:20","Info: topLevel 'contents' permission set to 'read': .github/workflows/remove-automerge-on-commit.yml:19","Warn: no topLevel permission defined: .github/workflows/review-pr-action.yml:1","Warn: no topLevel permission defined: .github/workflows/review-prs.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/security-advisories-to-linear.yml:16","Warn: no topLevel permission defined: .github/workflows/stale-bot.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-api-reference-specs-to-r2.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-resources-references-to-r2.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-ui-specs-to-r2.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/team-labeler.yml:6","Warn: no topLevel permission defined: .github/workflows/test-cli-with-database.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/triage-dependabot-alerts.yml:18","Warn: no topLevel permission defined: .github/workflows/triage-issue-action.yml:1","Warn: no topLevel permission defined: .github/workflows/triage-issues.yml:1","Warn: no topLevel permission defined: .github/workflows/trigger-staging-deployment.yml:1","Warn: no topLevel permission defined: .github/workflows/tsdoc-generation.yml:1","Warn: no topLevel permission defined: .github/workflows/validate-http-types.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 29 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:232: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:247: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:310: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:316: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:325: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:388: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:394: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:403: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/algolia-api-indexer.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/algolia-api-indexer.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/algolia-api-indexer.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/algolia-api-indexer.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-linked-prs.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/close-linked-prs.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cloud-docs-automation.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-docs-automation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cloud-docs-automation.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-docs-automation.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cloud-docs-automation.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-docs-automation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cloud-webhooks-docs-automation.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-webhooks-docs-automation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cloud-webhooks-docs-automation.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-webhooks-docs-automation.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cloud-webhooks-docs-automation.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/cloud-webhooks-docs-automation.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-discussion.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-discussion.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-pr.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-pr.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/discord-issue-labels.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/discord-issue-labels.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/discord-issue-labels.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/discord-issue-labels.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-automation.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-automation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-automation.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-automation.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-automation.yml:203: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-automation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-staging-sync.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-staging-sync.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:234: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:239: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:275: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:407: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:412: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:292: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:297: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:333: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:350: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:355: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:390: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:429: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:434: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/draft-release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/draft-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/draft-release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/draft-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/draft-release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/draft-release.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/draft-release.yml:287: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/draft-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dx-triage-doc-fixes.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/dx-triage-doc-fixes.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dx-triage-doc-fixes.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/dx-triage-doc-fixes.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:268: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:273: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:278: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/notify-docs-consumers.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/notify-docs-consumers.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/notify-docs-consumers.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/notify-docs-consumers.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nudge-preview-bump.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/nudge-preview-bump.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/oas-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/remove-automerge-on-commit.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/remove-automerge-on-commit.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/remove-automerge-on-commit.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/remove-automerge-on-commit.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:322: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:339: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:345: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:351: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/review-pr-action.yml:635: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-pr-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/review-prs.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/review-prs.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/security-advisories-to-linear.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/security-advisories-to-linear.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/security-advisories-to-linear.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/security-advisories-to-linear.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/security-advisories-to-linear.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/security-advisories-to-linear.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/stale-bot.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-api-reference-specs-to-r2.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-api-reference-specs-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-api-reference-specs-to-r2.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-api-reference-specs-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-resources-references-to-r2.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-resources-references-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-resources-references-to-r2.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-resources-references-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-ui-specs-to-r2.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-ui-specs-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-ui-specs-to-r2.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/sync-ui-specs-to-r2.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cli-with-database.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/test-cli-with-database.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cli-with-database.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/test-cli-with-database.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-cli-with-database.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/test-cli-with-database.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/triage-dependabot-alerts.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-dependabot-alerts.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-issue-action.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-issue-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-issue-action.yml:274: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-issue-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-issue-action.yml:292: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-issue-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-issue-action.yml:298: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-issue-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/triage-issue-action.yml:304: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/triage-issue-action.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:225: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tsdoc-generation.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/tsdoc-generation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tsdoc-generation.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/tsdoc-generation.yml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/tsdoc-generation.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/tsdoc-generation.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-http-types.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/validate-http-types.yml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-http-types.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/validate-http-types.yml/develop?enable=pin","Warn: downloadThenRun not pinned by hash: integration-tests/scripts/cli/get-products.sh:5","Warn: npmCommand not pinned by hash: .github/workflows/release.yml:39","Warn: npmCommand not pinned by hash: .github/workflows/test-cli-with-database.yml:66","Warn: npmCommand not pinned by hash: .github/workflows/trigger-release.yml:87","Warn: npmCommand not pinned by hash: .github/workflows/trigger-release.yml:213","Info:   0 out of 104 GitHub-owned GitHubAction dependencies pinned","Info:  13 out of  58 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   0 out of   4 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}}]}
