Skip to content

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Apr 3, 2023

Bumps ossf/scorecard-action from 2.1.2 to 2.1.3.

Release notes

Sourced from ossf/scorecard-action's releases.

v2.1.3

What's Changed

Bug Fixes

  • Invalid SARIF files from a bug in scorecard
  • Vulnerabilities check crashes if a vulnerable dependency is found via OSVScanner
  • Scorecard action not reporting binary artifacts in the repo

Full Scorecard Changelog: ossf/scorecard@v4.10.2...v4.10.5

Full Changelog: ossf/scorecard-action@v2.1.2...v2.1.3

Commits
  • 80e868c 🌱 Bump docker tag for release. (#1117)
  • aed6134 🌱 Bump golang.org/x/net from 0.7.0 to 0.8.0 (#1099)
  • 33dfbd3 🌱 Bump github.com/ossf/scorecard/v4 from 4.10.2 to 4.10.5 (#1111)
  • 193ae37 🌱 Bump actions/dependency-review-action from 3.0.3 to 3.0.4 (#1110)
  • ca9bf95 🌱 Bump actions/cache from 3.2.6 to 3.3.1 (#1103)
  • fa15212 🌱 Bump github/codeql-action from 2.2.4 to 2.2.7 (#1105)
  • 136025e 🌱 Bump step-security/harden-runner from 2.1.0 to 2.2.1 (#1104)
  • c59c116 🌱 Bump actions/cache from 3.2.5 to 3.2.6 (#1097)
  • 7cc3711 🌱 Bump github.com/emicklei/go-restful (#1086)
  • 570a953 🌱 Bump actions/cache from 3.2.4 to 3.2.5 (#1088)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.1.2 to 2.1.3.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@e38b190...80e868c)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 3, 2023
@codecov
Copy link

codecov bot commented Apr 3, 2023

Codecov Report

Merging #16 (2da70ab) into master (9d9bd9d) will decrease coverage by 0.23%.
The diff coverage is n/a.

@@            Coverage Diff             @@
##           master      #16      +/-   ##
==========================================
- Coverage   76.16%   75.94%   -0.23%     
==========================================
  Files         104      104              
  Lines       22466    22277     -189     
==========================================
- Hits        17112    16919     -193     
- Misses       5354     5358       +4     

see 53 files with indirect coverage changes

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

rouilj added a commit that referenced this pull request Apr 3, 2023
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Apr 3, 2023

Looks like ossf/scorecard-action is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Apr 3, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/ossf/scorecard-action-2.1.3 branch April 3, 2023 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants