plugins
plugins copied to clipboard
[gh_actions]: Bump ossf/scorecard-action from 1.1.1 to 1.1.2
Bumps ossf/scorecard-action from 1.1.1 to 1.1.2.
Release notes
Sourced from ossf/scorecard-action's releases.
v1.1.2
What's Changed
- Fix for ossf/scorecard-action#329
Full Changelog: https://github.com/ossf/scorecard-action/compare/v1.1.1...v1.1.2
Commits
ce330fd✨ use GITHUB_TOKEN when repo_token is empty on PRs (#335)2e062bcGet repo info from REST API if event file is unavailable (#576)85bc05a:seedling: Bump github.com/sigstore/cosign from 1.8.0 to 1.9.0 (#331)f8cb15a:seedling: Bump github/codeql-action from 2.1.11 to 2.1.12 (#339)fe5d183:seedling: Bump actions/cache from 3.0.2 to 3.0.4 (#393)ed46015:seedling: Bump debian from06a93cbtof695745(#536)5cc5d09:seedling: Bump github.com/spf13/cobra from 1.4.0 to 1.5.0 (#523)f470ef7Get the Golang code in sync with Bash (#489)1ca6c49:seedling: Bump debian from06a93cbto06a93cb(#432)66a8cbc:seedling: Bump github.com/ossf/scorecard/v4 from 4.3.1 to 4.4.0 (#454)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
@godofredoc Ping on this.
(Should I just be approving these, or is there an audit process for them?)
@godofredoc Ping on this.
(Should I just be approving these, or is there an audit process for them?)
As long as the tests are passing they are good to land.
As long as the tests are passing they are good to land.
Isn't this configured to only run on main? I don't think anything we run in presubmit is affected by this PR, in which case there's no test coverage.