Surface OpenSSF Scorecard scores for newly added dependencies in pull requests using GitHub's Dependency Review Action, as a supply-chain vetting gate

domain: github.com/actions/dependency-review-action · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Add actions/dependency-review-action as a step in a workflow triggered on pull_request, on a repository with the dependency graph enabled.
  2. Confirm the action's Scorecard integration is active (available since dependency-review-action v4.2.3) so it displays each changed dependency's published OpenSSF Scorecard score in the PR summary.
  3. Set severity and license fail conditions (fail-on-severity, allow/deny license lists) in the action config to combine vulnerability gating with Scorecard visibility in the same check.
  4. Require human review or a branch protection rule for PRs that introduce a dependency with a low Scorecard score, since the action surfaces the score as information rather than enforcing a hard numeric threshold on it by default.
  5. Pair this PR-time visibility with a separate scheduled ossf/scorecard-action run against your own repository to track your own project's Scorecard trend over time.

Known gotchas

Related routes

Compute an OpenSSF Scorecard score for a GitHub repository and surface results in CI
securityscorecards.dev · 5 steps · unrated
Configure the OpenSSF Scorecard GitHub Action to run on every pull request and publish results to GitHub Code Scanning
securityscorecards.dev · 5 steps · unrated
Run OpenSSF Scorecard against a GitHub repository and interpret the weighted score output
securityscorecards.dev · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans