integrating something like scorecard to help understand potential issues with opensource package dependencies.