msquic
msquic copied to clipboard
Bump ossf/scorecard-action from 1.0.3 to 1.1.2
Bumps ossf/scorecard-action from 1.0.3 to 1.1.2.
Release notes
Sourced from ossf/scorecard-action's releases.
v1.1.2
What's Changed
- Fix for ossf/scorecard-action#329
Full Changelog: https://github.com/ossf/scorecard-action/compare/v1.1.1...v1.1.2
v1.1.1
What's Changed
Fix for ossf/scorecard-action#323
Full Changelog: https://github.com/ossf/scorecard-action/compare/v1.1.0...v1.1.1
v1.1.0
Main changes
This release lets you run Scorecards without creating a PAT token. If you don't provide a PAT token, Scorecards will use the default
GITHUB_TOKENavailable in the workflow. Due to limitations of the permissions model and GitHub APIs, be aware of the following limitations:
- Without a PAT, the Branch-Protection is not supported, so it will be disabled. You will not receive alerts for this check.
- Scorecards only supports PAT on private repositories. If you want to install Scorecards on a private repository, you still need to use a PAT.
For more information, visit the README.md
New Contributors
@rohankh532made their first contribution in ossf/scorecard-action#112@justaugustusmade their first contribution in ossf/scorecard-action#126@jamietannamade their first contribution in ossf/scorecard-action#145@jonasbbmade their first contribution in ossf/scorecard-action#129@azeemshaikh38made their first contribution in ossf/scorecard-action#247Full Changelog: https://github.com/ossf/scorecard-action/compare/v1.0.4...v1.1.0
v1.0.4
Summary
This release fixes
nullrepository and branch issues: see ossf/scorecard-action#106, ossf/scorecard-action#84 and ossf/scorecard-action#73What's Changed
- Update codeql-analysis.yml by
@jauderhoin ossf/scorecard-action#76- use GITHUB_REPOSITORY in shell script by
@laurentsimonin ossf/scorecard-action#83- Bump github/codeql-action from 1.0.30 to 1.0.31 by
@dependabotin ossf/scorecard-action#81- ✨ Add warning for empty repo token by
@laurentsimonin ossf/scorecard-action#71- 🐛 Fix default parameter requirement by
@laurentsimonin ossf/scorecard-action#89- :sparkles: Initial porting the shellscript to go by
@naveensrinivasanin ossf/scorecard-action#87- :seedling: Golang CI for clean code. by
@naveensrinivasanin ossf/scorecard-action#90- Bump github/codeql-action from 1.0.31 to 1.0.32 by
@dependabotin ossf/scorecard-action#93- :seedling: Porting shell script to Go by
@naveensrinivasanin ossf/scorecard-action#94- 🌱 More tests by
@naveensrinivasanin ossf/scorecard-action#95- 🐛 Fix null is fork in script by
@laurentsimonin ossf/scorecard-action#98- :seedling: Porting of shell script to go by
@naveensrinivasanin ossf/scorecard-action#99- Bump github/codeql-action from 1.0.32 to 1.1.0 by
@dependabotin ossf/scorecard-action#102- Bump actions/setup-go from 2.1.5 to 2.2.0 by
@dependabotin ossf/scorecard-action#101- :seedling: Final bits of porting the shell to go by
@naveensrinivasanin ossf/scorecard-action#103
... (truncated)
Commits
ce330fd✨ use GITHUB_TOKEN when repo_token is empty on PRs (#335)2e062bcGet repo info from REST API if event file is unavailable (#576)85bc05a:seedling: Bump github.com/sigstore/cosign from 1.8.0 to 1.9.0 (#331)f8cb15a:seedling: Bump github/codeql-action from 2.1.11 to 2.1.12 (#339)fe5d183:seedling: Bump actions/cache from 3.0.2 to 3.0.4 (#393)ed46015:seedling: Bump debian from06a93cbtof695745(#536)5cc5d09:seedling: Bump github.com/spf13/cobra from 1.4.0 to 1.5.0 (#523)f470ef7Get the Golang code in sync with Bash (#489)1ca6c49:seedling: Bump debian from06a93cbto06a93cb(#432)66a8cbc:seedling: Bump github.com/ossf/scorecard/v4 from 4.3.1 to 4.4.0 (#454)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
@dependabot rebase
Superseded by #3059.