StepSecurity has identified repository-level hardening opportunities in TLMSLLC/token-contract based on your organization's Policy-Driven PR configuration.
Dependabot configuration should cover the configured package ecosystems
- Status: Failed
- Severity: Medium
- Description: This check fails if the repository has no .github/dependabot.yml or it does not cover the package ecosystems configured by the organization.
- Resolution: Add or update .github/dependabot.yml to include version updates for the configured package ecosystems.
- Details: dependabot configuration does not cover configured package ecosystems: *
Suggested changes
Create or update .github/dependabot.yml:
version: 2
updates:
- package-ecosystem: "*"
directory: "/"
schedule:
interval: "daily"
Pre-commit configuration should include the configured hooks
- Status: Failed
- Severity: Low
- Description: This check fails if the repository has no .pre-commit-config.yaml or it is missing hooks the organization has configured. Pre-commit hooks enforce code quality and detect security issues before commit.
- Resolution: Add or update .pre-commit-config.yaml to include the configured hooks.
- Details: pre-commit configuration is missing configured hooks: php-lint-all
Enabling Pull Requests mode for these controls lets StepSecurity remediate them automatically via a pull request.
StepSecurity has identified repository-level hardening opportunities in
TLMSLLC/token-contractbased on your organization's Policy-Driven PR configuration.Dependabot configuration should cover the configured package ecosystems
Suggested changes
Create or update
.github/dependabot.yml:Pre-commit configuration should include the configured hooks
Enabling Pull Requests mode for these controls lets StepSecurity remediate them automatically via a pull request.