From 7aa721115cfede22f1b266a56a6fa6af18934255 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 29 Apr 2024 21:44:10 +0000 Subject: [PATCH] :seedling: Bump the docker-images group with 2 updates Bumps the docker-images group with 2 updates: golang and distroless/base. Updates `golang` from `450e382` to `d5302d4` Updates `distroless/base` from `611d30d` to `d8d01e2` --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-images - dependency-name: distroless/base dependency-type: direct:production dependency-group: docker-images ... Signed-off-by: dependabot[bot] --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 551cb706..91a869bc 100644 --- a/Dockerfile +++ b/Dockerfile @@ -22,7 +22,7 @@ # -e GITHUB_REPOSITORY="ossf/scorecard" \ # laurentsimon/scorecard-action:latest -FROM golang:1.22.2@sha256:450e3822c7a135e1463cd83e51c8e2eb03b86a02113c89424e6f0f8344bb4168 AS builder +FROM golang:1.22.2@sha256:d5302d40dc5fbbf38ec472d1848a9d2391a13f93293a6a5b0b87c99dc0eaa6ae AS builder WORKDIR /src ENV CGO_ENABLED=0 COPY go.* ./ @@ -35,7 +35,7 @@ ARG TARGETARCH RUN CGO_ENABLED=0 make build # Need root for GitHub Actions support -FROM gcr.io/distroless/base@sha256:611d30d7f6d9992c37b1e1a212eefdf1f7c671deb56db3707e24eb01da8c4c2a +FROM gcr.io/distroless/base@sha256:d8d01e2d5868f622544543ca0311679bbc2f3fbf7f7bafd11af78a284c479ea3 COPY --from=build /src/scorecard-action / COPY policies/template.yml /policy.yml ENTRYPOINT [ "/scorecard-action" ]