Tie our dependencies to a commit hash instead of a movable version tag
Author: maehneCreated Sep 7, 2026Updated Sep 7, 2026
Labelshelp wantedgood first issue
The thanks to the help of @zdimension re-enabled SonarQube by PR #2967 raised some quality gate issues related to the versioning of our dependencies:
C Security Rating on New Code (required ≥ A)
We should address them as suggested in the reports by tying the dependencies to the commit hash instead of a movable tag. Dependabot should still be able to handle the automatic updating of the dependencies.
Source: logisim-evolution/logisim-evolution