221.json (8197B)
1 { 2 "number": 221, 3 "title": "Bump ossf/scorecard-action from 1.0.4 to 1.1.1", 4 "state": "closed", 5 "diff_file": "221.diff", 6 "author": "dependabot[bot]", 7 "created_at": "2022-06-06T08:13:26Z", 8 "closed_at": "2023-01-03T16:43:21Z", 9 "merged_at": null, 10 "base_ref": "main", 11 "head_ref": "dependabot/github_actions/ossf/scorecard-action-1.1.1", 12 "labels": [ 13 "dependencies", 14 "github_actions" 15 ], 16 "assignees": [ 17 "MTRNord" 18 ], 19 "requested_reviewers": [ 20 "MTRNord" 21 ], 22 "body": "Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 1.0.4 to 1.1.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a href=\"https://github.com/ossf/scorecard-action/releases\">ossf/scorecard-action's releases</a>.</em></p>\n<blockquote>\n<h2>v1.1.1</h2>\n<h2>What's Changed</h2>\n<p>Fix for <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/323\">ossf/scorecard-action#323</a></p>\n<p><strong>Full Changelog</strong>: <a href=\"https://github.com/ossf/scorecard-action/compare/v1.1.0...v1.1.1\">https://github.com/ossf/scorecard-action/compare/v1.1.0...v1.1.1</a></p>\n<h2>v1.1.0</h2>\n<h2>Main changes</h2>\n<p>This release lets you run Scorecards without creating a PAT token. If you don't provide a PAT token, Scorecards will use the default <code>GITHUB_TOKEN</code> available in the workflow. Due to limitations of the permissions model and GitHub APIs, be aware of the following limitations:</p>\n<ol>\n<li>Without a PAT, the Branch-Protection is not supported, so it will be disabled. You will not receive alerts for this check.</li>\n<li>Scorecards only supports PAT on private repositories. If you want to install Scorecards on a private repository, you still need to use a PAT.</li>\n</ol>\n<p>For more information, visit the <a href=\"https://github.com/ossf/scorecard-action/tree/v1.1.0#readme\">README.md</a></p>\n<h2>New Contributors</h2>\n<ul>\n<li><a href=\"https://github.com/rohankh532\"><code>@\u200brohankh532</code></a> made their first contribution in <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/pull/112\">ossf/scorecard-action#112</a></li>\n<li><a href=\"https://github.com/justaugustus\"><code>@\u200bjustaugustus</code></a> made their first contribution in <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/pull/126\">ossf/scorecard-action#126</a></li>\n<li><a href=\"https://github.com/jamietanna\"><code>@\u200bjamietanna</code></a> made their first contribution in <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/pull/145\">ossf/scorecard-action#145</a></li>\n<li><a href=\"https://github.com/jonasbb\"><code>@\u200bjonasbb</code></a> made their first contribution in <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/pull/129\">ossf/scorecard-action#129</a></li>\n<li><a href=\"https://github.com/azeemshaikh38\"><code>@\u200bazeemshaikh38</code></a> made their first contribution in <a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/pull/247\">ossf/scorecard-action#247</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a href=\"https://github.com/ossf/scorecard-action/compare/v1.0.4...v1.1.0\">https://github.com/ossf/scorecard-action/compare/v1.0.4...v1.1.0</a></p>\n</blockquote>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/3e15ea8318eee9b333819ec77a36aca8d39df13e\"><code>3e15ea8</code></a> \u2728 Bump container hash to use scorecard v4.3.1 (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/324\">#324</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/6c071aca8599d63e8125a51b6b698c0f9e75bc54\"><code>6c071ac</code></a> :seedling: Bump actions/setup-go from 3.1.0 to 3.2.0</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/51fbe793f85fb5cc5ba2014839c838aff0228177\"><code>51fbe79</code></a> :seedling: Bump debian from <code>fbaacd5</code> to <code>06a93cb</code></li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/d8a25b210c487a143a67fac8ae05612b6ee81ff9\"><code>d8a25b2</code></a> :seedling: Bump github.com/caarlos0/env/v6 from 6.9.2 to 6.9.3</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/cd3637b65cef198b9be1162b557eeaab7a0a8887\"><code>cd3637b</code></a> Update README.md (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/319\">#319</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/77f5e34142bc416a475a7c6abd090302af532f7c\"><code>77f5e34</code></a> :seedling: .github: Add dependency review action (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/165\">#165</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/ef34fe9e22cb41cacfa034924045103524c632f1\"><code>ef34fe9</code></a> \ud83d\udcd6 docs/e2e: Add information about golang-staging branch tests (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/170\">#170</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/1aa187dfb0742950fb8f08f4068dd6af6bd3367a\"><code>1aa187d</code></a> :seedling: Bump github/codeql-action from 2.1.10 to 2.1.11 (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/311\">#311</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/049eb0c0d4a12868f4be4b39f1f896ca0cd3aa13\"><code>049eb0c</code></a> :seedling: Bump github.com/ossf/scorecard/v4 from 4.2.0 to 4.3.0 (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/313\">#313</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/5c8bc69dc88b65c66584e07611df79d3579b0377\"><code>5c8bc69</code></a> multi-repo-action: Cleanups (1/n) (<a href=\"https://github-redirect.dependabot.com/ossf/scorecard-action/issues/301\">#301</a>)</li>\n<li>Additional commits viewable in <a href=\"https://github.com/ossf/scorecard-action/compare/c1aec4ac820532bab364f02a81873c555a0ba3a1...3e15ea8318eee9b333819ec77a36aca8d39df13e\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n\n[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n</details>", 23 "comments": [ 24 { 25 "author": "dependabot[bot]", 26 "created_at": "2023-01-03T16:43:20Z", 27 "body": "Superseded by #248." 28 } 29 ], 30 "review_comments": [] 31 }