Surface OpenSSF Scorecard scores for newly added dependencies in pull requests using GitHub's Dependency Review Action, as a supply-chain vetting gate
domain: github.com/actions/dependency-review-action · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Add actions/dependency-review-action as a step in a workflow triggered on pull_request, on a repository with the dependency graph enabled.
Confirm the action's Scorecard integration is active (available since dependency-review-action v4.2.3) so it displays each changed dependency's published OpenSSF Scorecard score in the PR summary.
Set severity and license fail conditions (fail-on-severity, allow/deny license lists) in the action config to combine vulnerability gating with Scorecard visibility in the same check.
Require human review or a branch protection rule for PRs that introduce a dependency with a low Scorecard score, since the action surfaces the score as information rather than enforcing a hard numeric threshold on it by default.
Pair this PR-time visibility with a separate scheduled ossf/scorecard-action run against your own repository to track your own project's Scorecard trend over time.
Known gotchas
Scorecard data only exists for dependencies the public OpenSSF Scorecard project has already scanned and published; obscure or private packages will show no score.
The action requires the dependency graph feature to be enabled on the repository, which has its own visibility and plan requirements.
Because the action surfaces Scorecard data rather than auto-blocking on it, a policy that relies on 'the CI check will catch it' without a review step can let low-score dependencies merge unnoticed.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?