commons-configuration
commons-configuration copied to clipboard
Bump ossf/scorecard-action from 1.1.2 to 2.0.4
Bumps ossf/scorecard-action from 1.1.2 to 2.0.4.
Release notes
Sourced from ossf/scorecard-action's releases.
v2.0.4
Fixes #856
What's Changed
- :seedling: Bump github.com/caarlos0/env/v6 from 6.10.0 to 6.10.1 by
@dependabot
in ossf/scorecard-action#934- feat: do not run signing on pull requests by
@laurentsimon
in ossf/scorecard-action#935- :seedling: Bump debian from 11.4-slim to 11.5-slim by
@dependabot
in ossf/scorecard-action#936- :seedling: Bump github.com/sigstore/cosign from 1.11.1 to 1.12.0 by
@dependabot
in ossf/scorecard-action#938- :seedling: Bump github/codeql-action from 2.1.22 to 2.1.24 by
@dependabot
in ossf/scorecard-action#941- 🐛 Restore behavior of ignoring scorecard runtime errors by
@spencerschrock
in ossf/scorecard-action#948- :seedling: Bump actions/dependency-review-action from 2.1.0 to 2.4.0 by
@dependabot
in ossf/scorecard-action#950- :seedling: Bump github.com/sigstore/cosign from 1.12.0 to 1.12.1 by
@dependabot
in ossf/scorecard-action#947- :seedling: Bump github/codeql-action from 2.1.24 to 2.1.25 by
@dependabot
in ossf/scorecard-action#949- :seedling: Bump codecov/codecov-action from 3.1.0 to 3.1.1 by
@dependabot
in ossf/scorecard-action#942- Create v2.0.4 patch by
@spencerschrock
in ossf/scorecard-action#952New Contributors
@spencerschrock
made their first contribution in ossf/scorecard-action#948Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.0.3...v2.0.4
v2.0.3
Patch for fix in #898
v2.0.2
Fixes ossf/scorecard-action#895
v2.0.1
Fix for #856
v2.0.0
What's Changed
- 🌱 Prepare for a pre-release of the Golang action by
@azeemshaikh38
in ossf/scorecard-action#750- :seedling: Bump github/codeql-action from 2.1.12 to 2.1.16 by
@dependabot
in ossf/scorecard-action#751- :seedling: Bump debian from 11.3-slim to 11.4-slim by
@dependabot
in ossf/scorecard-action#749- :seedling: Bump step-security/harden-runner from 1.4.3 to 1.4.4 by
@dependabot
in ossf/scorecard-action#646- :seedling: Bump actions/setup-go from 3.2.0 to 3.2.1 by
@dependabot
in ossf/scorecard-action#748- 🐛 Fix dependency conflicts in go.mod by
@azeemshaikh38
in ossf/scorecard-action#771- 🌱 Prepare for v2 beta1 release by
@azeemshaikh38
in ossf/scorecard-action#766- multi-repo-action: Note that tool is a work-in-progress by
@naveensrinivasan
in ossf/scorecard-action#776- 🐛 Fix intermittent failures in CI-Tests by
@azeemshaikh38
in ossf/scorecard-action#778- :seedling: Bump sigs.k8s.io/release-utils from 0.7.2 to 0.7.3 by
@dependabot
in ossf/scorecard-action#775- :seedling: Bump actions/cache from 3.0.4 to 3.0.5 by
@dependabot
in ossf/scorecard-action#769- 📖 Update README about the restrictions for scorecard-action:v2 by
@azeemshaikh38
in ossf/scorecard-action#779- :seedling: Bump github/codeql-action from 2.1.16 to 2.1.17 by
@dependabot
in ossf/scorecard-action#783- 📖 Update instructions for Scorecard badge to README by
@azeemshaikh38
in ossf/scorecard-action#785- :seedling: Bump debian from
f576b80
toa811e62
by@dependabot
in ossf/scorecard-action#787- :seedling: Bump github.com/ossf/scorecard/v4 from 4.4.0 to 4.5.0 by
@dependabot
in ossf/scorecard-action#786- :seedling: Bump github/codeql-action from 2.1.17 to 2.1.18 by
@dependabot
in ossf/scorecard-action#788- :seedling: Bump actions/cache from 3.0.5 to 3.0.6 by
@dependabot
in ossf/scorecard-action#789
... (truncated)
Commits
e363bfc
Bump docker to next release. (#952)65d491b
:seedling: Bump codecov/codecov-action from 3.1.0 to 3.1.1f60b7d6
:seedling: Bump github/codeql-action from 2.1.24 to 2.1.25be7ddf6
:seedling: Bump github.com/sigstore/cosign from 1.12.0 to 1.12.19a2bfd4
:seedling: Bump actions/dependency-review-action from 2.1.0 to 2.4.0 (#950)a346ade
🐛 Restore behavior of ignoring scorecard runtime errors (#948)2db2a1c
:seedling: Bump github/codeql-action from 2.1.22 to 2.1.24 (#941)c858631
:seedling: Bump github.com/sigstore/cosign from 1.11.1 to 1.12.0 (#938)8ee777f
:seedling: Bump debian from 11.4-slim to 11.5-slim (#936)6213479
feat: do not run signing on pull requests (#935)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Codecov Report
Merging #222 (72ec4c1) into master (7bf6f17) will not change coverage. The diff coverage is
n/a
.
@@ Coverage Diff @@
## master #222 +/- ##
=========================================
Coverage 89.00% 89.00%
Complexity 3528 3528
=========================================
Files 183 183
Lines 9642 9642
Branches 1196 1196
=========================================
Hits 8582 8582
Misses 777 777
Partials 283 283
:mega: We’re building smart automated test selection to slash your CI/CD build times. Learn more
This change needs approval on the Apache Infra side to actually run to completion.
Closing: Needs Apache Infra
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore
condition with the desired update_types
to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.