SCORECARD_REMEDIATION_PLAN.md
Last updated: 2026-04-18
Current public Scorecard snapshot for github.com/fabricjs/fabric.js:
6.1 / 102026-04-18T07:39:30Zf80aa89a0614f1936952d53557ed46abd94f8d6fChecks below 10:
Dangerous-Workflow: 0Token-Permissions: 0Fuzzing: 0CII-Best-Practices: 0Code-Review: 5Pinned-Dependencies: 7Binary-Artifacts: 8CI-Tests: 8SAST: 9Packaging: -1Signed-Releases: -1Branch-Protection: -1head_sha / head_branch checkouts.head_sha / head_branch checkouts in privileged follow-up workflows when a safer ref or merge ref is available.lib/google_closure_compiler.jar if it is no longer used.lib/yuicompressor-2.4.6.jar if it is no longer used.npm ci over npm install in publish workflows.publish.js where possible and keep the publish command explicit in workflow YAML.npm publish --provenance for stronger release provenance.master, 5.x, and 6.x.SCORECARD_TOKEN so the Scorecard action can read branch protection state.This branch starts with the CI hardening items: