Sourced from ossf/scorecard-action's releases.
v2.4.3
What's Changed
This update bumps the Scorecard version to the v5.3.0 release. For a complete list of changes, please refer to the Scorecard v5.3.0 release notes.
Documentation
- docs: clarify
GITHUB_TOKENpermissions needed for private repos by@pankajtaneja5in ossf/scorecard-action#1574- :book: Fix recommended command to test the image in development by
@deivid-rodriguezin ossf/scorecard-action#1583Other
- add missing top-level token permissions to workflows by
@timothykleein ossf/scorecard-action#1566- setup codeowners for requesting reviews by
@spencerschrockin ossf/scorecard-action#1576- :seedling: Improve printing options by
@deivid-rodriguezin ossf/scorecard-action#1584New Contributors
@timothykleemade their first contribution in ossf/scorecard-action#1566@pankajtaneja5made their first contribution in ossf/scorecard-action#1574@deivid-rodriguezmade their first contribution in ossf/scorecard-action#1584Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.4.2...v2.4.3
4eaacf0
bump docker to ghcr v2.4.3 (#1587)42e3a01
:seedling: Bump the github-actions group with 3 updates (#1585)88c07ac
:seedling: Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)6c690f2
Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)92083b5
:book: Fix recommended command to test the image in development (#1583)7975ea6
:seedling: Bump the docker-images group across 1 directory with 2
updates (#1...0d1a743
:seedling: Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)46e6e0c
:seedling: Bump the github-actions group with 2 updates (#1580)c3f1350
:seedling: Improve printing options (#1584)43e475b
:seedling: Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)