3e8363eb80
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.0.3 to 2.0.6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ossf/scorecard-action/releases">ossf/scorecard-action's releases</a>.</em></p> <blockquote> <h2>v2.0.6</h2> <h2>What's Changed</h2> <ul> <li>Fix - Broken dockerfile by <a href="https://github.com/naveensrinivasan"><code>@naveensrinivasan</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/979">ossf/scorecard-action#979</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ossf/scorecard-action/compare/v2.0.5...v2.0.6">https://github.com/ossf/scorecard-action/compare/v2.0.5...v2.0.6</a></p> <h2>v2.0.5</h2> <h2>What's Changed</h2> <ul> <li>Remove trailing space from example by <a href="https://github.com/jamacku"><code>@jamacku</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/955">ossf/scorecard-action#955</a></li> <li>🌱 Bump actions/cache from 3.0.8 to 3.0.10 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/956">ossf/scorecard-action#956</a></li> <li>🌱 Bump github/codeql-action from 2.1.25 to 2.1.26 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/957">ossf/scorecard-action#957</a></li> <li>🌱 Bump step-security/harden-runner from 1.4.5 to 1.5.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/958">ossf/scorecard-action#958</a></li> <li>🌱 Bump debian from <code>5cf1d98</code> to <code>b46fc4e</code> by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/959">ossf/scorecard-action#959</a></li> <li>🌱 Bump github.com/sigstore/cosign from 1.12.1 to 1.13.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/962">ossf/scorecard-action#962</a></li> <li>🌱 Upgrade to go 1.19 by <a href="https://github.com/naveensrinivasan"><code>@naveensrinivasan</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/961">ossf/scorecard-action#961</a></li> <li>🌱 Bump github.com/spf13/cobra from 1.5.0 to 1.6.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/967">ossf/scorecard-action#967</a></li> <li>🌱 Bump golang from <code>c2a98a5</code> to <code>b850621</code> by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/966">ossf/scorecard-action#966</a></li> <li>🌱 Bump golang from <code>b850621</code> to <code>25de7b6</code> by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/968">ossf/scorecard-action#968</a></li> <li>New release for Scorecard v4.8.0 by <a href="https://github.com/naveensrinivasan"><code>@naveensrinivasan</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/969">ossf/scorecard-action#969</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/jamacku"><code>@jamacku</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/955">ossf/scorecard-action#955</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ossf/scorecard-action/compare/v2.0.4...v2.0.5">https://github.com/ossf/scorecard-action/compare/v2.0.4...v2.0.5</a></p> <h2>v2.0.4</h2> <p>Fixes <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/856">#856</a></p> <h2>What's Changed</h2> <ul> <li>🌱 Bump github.com/caarlos0/env/v6 from 6.10.0 to 6.10.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/934">ossf/scorecard-action#934</a></li> <li>feat: do not run signing on pull requests by <a href="https://github.com/laurentsimon"><code>@laurentsimon</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/935">ossf/scorecard-action#935</a></li> <li>🌱 Bump debian from 11.4-slim to 11.5-slim by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/936">ossf/scorecard-action#936</a></li> <li>🌱 Bump github.com/sigstore/cosign from 1.11.1 to 1.12.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/938">ossf/scorecard-action#938</a></li> <li>🌱 Bump github/codeql-action from 2.1.22 to 2.1.24 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/941">ossf/scorecard-action#941</a></li> <li>🐛 Restore behavior of ignoring scorecard runtime errors by <a href="https://github.com/spencerschrock"><code>@spencerschrock</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/948">ossf/scorecard-action#948</a></li> <li>🌱 Bump actions/dependency-review-action from 2.1.0 to 2.4.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/950">ossf/scorecard-action#950</a></li> <li>🌱 Bump github.com/sigstore/cosign from 1.12.0 to 1.12.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/947">ossf/scorecard-action#947</a></li> <li>🌱 Bump github/codeql-action from 2.1.24 to 2.1.25 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/949">ossf/scorecard-action#949</a></li> <li>🌱 Bump codecov/codecov-action from 3.1.0 to 3.1.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/942">ossf/scorecard-action#942</a></li> <li>Create v2.0.4 patch by <a href="https://github.com/spencerschrock"><code>@spencerschrock</code></a> in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/952">ossf/scorecard-action#952</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/spencerschrock"><code>@spencerschrock</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/948">ossf/scorecard-action#948</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ossf/scorecard-action/compare/v2.0.3...v2.0.4">https://github.com/ossf/scorecard-action/compare/v2.0.3...v2.0.4</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
---|---|---|
.. | ||
ci.yml | ||
pre-release.yml | ||
publish.yml | ||
scorecards-analysis.yml | ||
tot-ci.yml |