Skip to content

Commit

Permalink
Merge #365
Browse files Browse the repository at this point in the history
365: chore(deps): update ossf/scorecard-action action to v2.1.0 r=renovate[bot] a=renovate[bot]

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ossf/scorecard-action](https://togithub.com/ossf/scorecard-action) | action | minor | `v2.0.6` -> `v2.1.0` |

---

### Release Notes

<details>
<summary>ossf/scorecard-action</summary>

### [`v2.1.0`](https://togithub.com/ossf/scorecard-action/releases/tag/v2.1.0)

[Compare Source](https://togithub.com/ossf/scorecard-action/compare/v2.0.6...v2.1.0)

#### What's Changed

##### Scorecard version

This release uses [scorecard v4.10.0](https://togithub.com/ossf/scorecard/releases/tag/v4.10.0).

##### Improvements

-   Docker build workflow by [`@&#8203;naveensrinivasan](https://togithub.com/naveensrinivasan)` in [ossf/scorecard-action#981
-   Use root user in distroless to support GitHub Actions by [`@&#8203;spencerschrock](https://togithub.com/spencerschrock)` in [ossf/scorecard-action#994
-   Disable pull_request_target by [`@&#8203;laurentsimon](https://togithub.com/laurentsimon)` in [ossf/scorecard-action#1031

##### Documentation

-   Add PAT section explaining risks by [`@&#8203;olivekl](https://togithub.com/olivekl)` in [ossf/scorecard-action#1024
-   Make the badge text easier to copy by [`@&#8203;rajbos](https://togithub.com/rajbos)` in [ossf/scorecard-action#1026

#### New Contributors

-   [`@&#8203;joycebrum](https://togithub.com/joycebrum)` made their first contribution in [ossf/scorecard-action#984
-   [`@&#8203;rajbos](https://togithub.com/rajbos)` made their first contribution in [ossf/scorecard-action#1026

**Full Changelog**: ossf/scorecard-action@v2.0.6...v2.1.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/OpenPoolProject/stratum).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC41NC4yIiwidXBkYXRlZEluVmVyIjoiMzQuNTQuMiJ9-->


Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
  • Loading branch information
bors[bot] and renovate[bot] committed Dec 15, 2022
2 parents 9dbbaaa + 8282ee5 commit 1c428de
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion .github/workflows/scorecards.yml
Expand Up @@ -30,7 +30,7 @@ jobs:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d # v2.0.6
uses: ossf/scorecard-action@937ffa90d79c7d720498178154ad4c7ba1e4ad8c # v2.1.0
with:
results_file: results.sarif
results_format: sarif
Expand Down

0 comments on commit 1c428de

Please sign in to comment.