-
Notifications
You must be signed in to change notification settings - Fork 72
Comparing changes
Open a pull request
base repository: ossf/scorecard-action
base: v2.3.3
head repository: ossf/scorecard-action
compare: v2.4.0
Commits on May 13, 2024
-
🌱 Bump golang from 1.22.2 to 1.22.3 in the docker-images group (#1380)
Bumps the docker-images group with 1 update: golang. Updates `golang` from 1.22.2 to 1.22.3 --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-images ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 6451974 - Browse repository at this point
Copy the full SHA 6451974View commit details
Commits on May 14, 2024
-
🌱 Bump the github-actions group with 2 updates (#1379)
Bumps the github-actions group with 2 updates: [github/codeql-action](https://github.com/github/codeql-action) and [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action). Updates `github/codeql-action` from 3.25.3 to 3.25.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@d39d31e...b7cec75) Updates `golangci/golangci-lint-action` from 5.3.0 to 6.0.1 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@38e1018...a4f60bb) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: golangci/golangci-lint-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c64f0a7 - Browse repository at this point
Copy the full SHA c64f0a7View commit details
Commits on May 29, 2024
-
🌱 Bump the github-actions group across 1 directory with 3 updates (#1385
) Bumps the github-actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [github/codeql-action](https://github.com/github/codeql-action) and [step-security/harden-runner](https://github.com/step-security/harden-runner). Updates `actions/checkout` from 4.1.5 to 4.1.6 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@44c2b7a...a5ac7e5) Updates `github/codeql-action` from 3.25.5 to 3.25.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b7cec75...9fdb3e4) Updates `step-security/harden-runner` from 2.7.1 to 2.8.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a4aa98b...f086349) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7699f53 - Browse repository at this point
Copy the full SHA 7699f53View commit details
Commits on Jun 5, 2024
-
🌱 Bump github/codeql-action (#1388)
Bumps the github-actions group with 1 update in the / directory: [github/codeql-action](https://github.com/github/codeql-action). Updates `github/codeql-action` from 3.25.6 to 3.25.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@9fdb3e4...2e230e8) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b8000e8 - Browse repository at this point
Copy the full SHA b8000e8View commit details -
🌱 Bump golang.org/x/net from 0.25.0 to 0.26.0 (#1389)
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.25.0 to 0.26.0. - [Commits](golang/net@v0.25.0...v0.26.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 641740c - Browse repository at this point
Copy the full SHA 641740cView commit details
Commits on Jun 11, 2024
-
🌱 Bump golang from 1.22.3 to 1.22.4 in the docker-images group (#1390)
Bumps the docker-images group with 1 update: golang. Updates `golang` from 1.22.3 to 1.22.4 --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-images ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d0985f8 - Browse repository at this point
Copy the full SHA d0985f8View commit details -
🌱 Bump the github-actions group with 2 updates (#1391)
Bumps the github-actions group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [actions/dependency-review-action](https://github.com/actions/dependency-review-action). Updates `step-security/harden-runner` from 2.8.0 to 2.8.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@f086349...17d0e2b) Updates `actions/dependency-review-action` from 4.3.2 to 4.3.3 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@0c155c5...72eb03d) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0a8153a - Browse repository at this point
Copy the full SHA 0a8153aView commit details
Commits on Jun 26, 2024
-
🌱 Bump github.com/hashicorp/go-retryablehttp (#1396)
Bumps [github.com/hashicorp/go-retryablehttp](https://github.com/hashicorp/go-retryablehttp) from 0.7.5 to 0.7.7. - [Changelog](https://github.com/hashicorp/go-retryablehttp/blob/main/CHANGELOG.md) - [Commits](hashicorp/go-retryablehttp@v0.7.5...v0.7.7) --- updated-dependencies: - dependency-name: github.com/hashicorp/go-retryablehttp dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for e240506 - Browse repository at this point
Copy the full SHA e240506View commit details -
🌱 Bump github.com/spf13/cobra from 1.8.0 to 1.8.1 (#1392)
Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra) from 1.8.0 to 1.8.1. - [Release notes](https://github.com/spf13/cobra/releases) - [Commits](spf13/cobra@v1.8.0...v1.8.1) --- updated-dependencies: - dependency-name: github.com/spf13/cobra dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 09f6ba3 - Browse repository at this point
Copy the full SHA 09f6ba3View commit details
Commits on Jul 1, 2024
-
🌱 Bump the github-actions group across 1 directory with 2 updates (#1397
) Bumps the github-actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [github/codeql-action](https://github.com/github/codeql-action). Updates `actions/checkout` from 4.1.6 to 4.1.7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@a5ac7e5...692973e) Updates `github/codeql-action` from 3.25.8 to 3.25.11 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@2e230e8...b611370) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 8c9e2c1 - Browse repository at this point
Copy the full SHA 8c9e2c1View commit details
Commits on Jul 10, 2024
-
docs: dogfooding badge (#1399)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for a4737bf - Browse repository at this point
Copy the full SHA a4737bfView commit details -
Configuration menu - View commit details
-
Copy full SHA for 82bcb91 - Browse repository at this point
Copy the full SHA 82bcb91View commit details -
Configuration menu - View commit details
-
Copy full SHA for 54cc1fe - Browse repository at this point
Copy the full SHA 54cc1feView commit details -
Configuration menu - View commit details
-
Copy full SHA for 873d5fd - Browse repository at this point
Copy the full SHA 873d5fdView commit details
Commits on Jul 15, 2024
-
Configuration menu - View commit details
-
Copy full SHA for a8eaa1b - Browse repository at this point
Copy the full SHA a8eaa1bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 9fc518d - Browse repository at this point
Copy the full SHA 9fc518dView commit details
Commits on Jul 19, 2024
-
bump scorecard to v5.0.0 release (#1410)
Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for a46b90b - Browse repository at this point
Copy the full SHA a46b90bView commit details
Commits on Jul 22, 2024
-
Configuration menu - View commit details
-
Copy full SHA for de5fcb9 - Browse repository at this point
Copy the full SHA de5fcb9View commit details -
Configuration menu - View commit details
-
Copy full SHA for cf8594c - Browse repository at this point
Copy the full SHA cf8594cView commit details
Commits on Jul 23, 2024
-
lower license score alert threshold to 9 (#1411)
When the threshold was introduced, the license check was a boolean check: 0 points for no license, and 10 points with a license. This later changed as covered in ossf/scorecard#1369 As the last point relies on SPDX detection, it's often flaky. Lowering the threshold allows us to still warn if a license isn't detected but not expect perfection. Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for c09630c - Browse repository at this point
Copy the full SHA c09630cView commit details
Commits on Jul 26, 2024
-
bump docker tag to v2.4.0 for release (#1414)
The main change is the Scorecard bump to v5.0.0, which includes maintainer annotations which will affect the SARIF produced by this action. For full details see the release notes: https://github.com/ossf/scorecard/releases/tag/v5.0.0 Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for 62b2cac - Browse repository at this point
Copy the full SHA 62b2cacView commit details
There are no files selected for viewing
Large diffs are not rendered by default.
Large diffs are not rendered by default.