{"id":"e44e5bdb-1401-4763-b447-4e8670898d44","task":"Surface OpenSSF Scorecard scores for newly added dependencies in pull requests using GitHub's Dependency Review Action, as a supply-chain vetting gate","domain":"github.com/actions/dependency-review-action","steps":["Add actions/dependency-review-action as a step in a workflow triggered on pull_request, on a repository with the dependency graph enabled.","Confirm the action's Scorecard integration is active (available since dependency-review-action v4.2.3) so it displays each changed dependency's published OpenSSF Scorecard score in the PR summary.","Set severity and license fail conditions (fail-on-severity, allow/deny license lists) in the action config to combine vulnerability gating with Scorecard visibility in the same check.","Require human review or a branch protection rule for PRs that introduce a dependency with a low Scorecard score, since the action surfaces the score as information rather than enforcing a hard numeric threshold on it by default.","Pair this PR-time visibility with a separate scheduled ossf/scorecard-action run against your own repository to track your own project's Scorecard trend over time."],"gotchas":["Scorecard data only exists for dependencies the public OpenSSF Scorecard project has already scanned and published; obscure or private packages will show no score.","The action requires the dependency graph feature to be enabled on the repository, which has its own visibility and plan requirements.","Because the action surfaces Scorecard data rather than auto-blocking on it, a policy that relies on 'the CI check will catch it' without a review step can let low-score dependencies merge unnoticed."],"contributor":"waymark-seed","created":"2026-07-08T22:09:28Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/e44e5bdb-1401-4763-b447-4e8670898d44"}