matrix-art.meta

Issues/PRs archive for MTRNord/matrix-art
git clone git://archive.git.mtrnord.blog/MTRNord/matrix-art.meta.git
Log | Files | Refs

221.md (7828B)


      1 # PR #221 Bump ossf/scorecard-action from 1.0.4 to 1.1.1
      2 
      3 - **Status:** closed
      4 - **Author:** @dependabot[bot]
      5 - **Created:** 2022-06-06T08:13:26Z
      6 - **Branch:** dependabot/github_actions/ossf/scorecard-action-1.1.1 → main
      7 - **Closed:** 2023-01-03T16:43:21Z
      8 - **Labels:** dependencies, github_actions
      9 - **Assignees:** @MTRNord
     10 - **Reviewers:** @MTRNord
     11 - **Diff:** [221.diff](./221.diff)
     12 
     13 ---
     14 
     15 Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 1.0.4 to 1.1.1.
     16 <details>
     17 <summary>Release notes</summary>
     18 <p><em>Sourced from <a href="https://github.com/ossf/scorecard-action/releases">ossf/scorecard-action's releases</a>.</em></p>
     19 <blockquote>
     20 <h2>v1.1.1</h2>
     21 <h2>What's Changed</h2>
     22 <p>Fix for <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/323">ossf/scorecard-action#323</a></p>
     23 <p><strong>Full Changelog</strong>: <a href="https://github.com/ossf/scorecard-action/compare/v1.1.0...v1.1.1">https://github.com/ossf/scorecard-action/compare/v1.1.0...v1.1.1</a></p>
     24 <h2>v1.1.0</h2>
     25 <h2>Main changes</h2>
     26 <p>This release lets you run Scorecards without creating a PAT token. If you don't provide a PAT token, Scorecards will use the default <code>GITHUB_TOKEN</code> available in the workflow. Due to limitations of the permissions model and GitHub APIs, be aware of the following limitations:</p>
     27 <ol>
     28 <li>Without a PAT, the Branch-Protection is not supported, so it will be disabled. You will not receive alerts for this check.</li>
     29 <li>Scorecards only supports PAT on private repositories. If you want to install Scorecards on a private repository, you still need to use a PAT.</li>
     30 </ol>
     31 <p>For more information, visit the <a href="https://github.com/ossf/scorecard-action/tree/v1.1.0#readme">README.md</a></p>
     32 <h2>New Contributors</h2>
     33 <ul>
     34 <li><a href="https://github.com/rohankh532"><code>@​rohankh532</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/112">ossf/scorecard-action#112</a></li>
     35 <li><a href="https://github.com/justaugustus"><code>@​justaugustus</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/126">ossf/scorecard-action#126</a></li>
     36 <li><a href="https://github.com/jamietanna"><code>@​jamietanna</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/145">ossf/scorecard-action#145</a></li>
     37 <li><a href="https://github.com/jonasbb"><code>@​jonasbb</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/129">ossf/scorecard-action#129</a></li>
     38 <li><a href="https://github.com/azeemshaikh38"><code>@​azeemshaikh38</code></a> made their first contribution in <a href="https://github-redirect.dependabot.com/ossf/scorecard-action/pull/247">ossf/scorecard-action#247</a></li>
     39 </ul>
     40 <p><strong>Full Changelog</strong>: <a href="https://github.com/ossf/scorecard-action/compare/v1.0.4...v1.1.0">https://github.com/ossf/scorecard-action/compare/v1.0.4...v1.1.0</a></p>
     41 </blockquote>
     42 </details>
     43 <details>
     44 <summary>Commits</summary>
     45 <ul>
     46 <li><a href="https://github.com/ossf/scorecard-action/commit/3e15ea8318eee9b333819ec77a36aca8d39df13e"><code>3e15ea8</code></a> ✨ Bump container hash to use scorecard v4.3.1 (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/324">#324</a>)</li>
     47 <li><a href="https://github.com/ossf/scorecard-action/commit/6c071aca8599d63e8125a51b6b698c0f9e75bc54"><code>6c071ac</code></a> :seedling: Bump actions/setup-go from 3.1.0 to 3.2.0</li>
     48 <li><a href="https://github.com/ossf/scorecard-action/commit/51fbe793f85fb5cc5ba2014839c838aff0228177"><code>51fbe79</code></a> :seedling: Bump debian from <code>fbaacd5</code> to <code>06a93cb</code></li>
     49 <li><a href="https://github.com/ossf/scorecard-action/commit/d8a25b210c487a143a67fac8ae05612b6ee81ff9"><code>d8a25b2</code></a> :seedling: Bump github.com/caarlos0/env/v6 from 6.9.2 to 6.9.3</li>
     50 <li><a href="https://github.com/ossf/scorecard-action/commit/cd3637b65cef198b9be1162b557eeaab7a0a8887"><code>cd3637b</code></a> Update README.md (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/319">#319</a>)</li>
     51 <li><a href="https://github.com/ossf/scorecard-action/commit/77f5e34142bc416a475a7c6abd090302af532f7c"><code>77f5e34</code></a> :seedling: .github: Add dependency review action (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/165">#165</a>)</li>
     52 <li><a href="https://github.com/ossf/scorecard-action/commit/ef34fe9e22cb41cacfa034924045103524c632f1"><code>ef34fe9</code></a> 📖 docs/e2e: Add information about golang-staging branch tests (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/170">#170</a>)</li>
     53 <li><a href="https://github.com/ossf/scorecard-action/commit/1aa187dfb0742950fb8f08f4068dd6af6bd3367a"><code>1aa187d</code></a> :seedling: Bump github/codeql-action from 2.1.10 to 2.1.11 (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/311">#311</a>)</li>
     54 <li><a href="https://github.com/ossf/scorecard-action/commit/049eb0c0d4a12868f4be4b39f1f896ca0cd3aa13"><code>049eb0c</code></a> :seedling: Bump github.com/ossf/scorecard/v4 from 4.2.0 to 4.3.0 (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/313">#313</a>)</li>
     55 <li><a href="https://github.com/ossf/scorecard-action/commit/5c8bc69dc88b65c66584e07611df79d3579b0377"><code>5c8bc69</code></a> multi-repo-action: Cleanups (1/n) (<a href="https://github-redirect.dependabot.com/ossf/scorecard-action/issues/301">#301</a>)</li>
     56 <li>Additional commits viewable in <a href="https://github.com/ossf/scorecard-action/compare/c1aec4ac820532bab364f02a81873c555a0ba3a1...3e15ea8318eee9b333819ec77a36aca8d39df13e">compare view</a></li>
     57 </ul>
     58 </details>
     59 <br />
     60 
     61 
     62 [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ossf/scorecard-action&package-manager=github_actions&previous-version=1.0.4&new-version=1.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
     63 
     64 Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
     65 
     66 [//]: # (dependabot-automerge-start)
     67 [//]: # (dependabot-automerge-end)
     68 
     69 ---
     70 
     71 <details>
     72 <summary>Dependabot commands and options</summary>
     73 <br />
     74 
     75 You can trigger Dependabot actions by commenting on this PR:
     76 - `@dependabot rebase` will rebase this PR
     77 - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
     78 - `@dependabot merge` will merge this PR after your CI passes on it
     79 - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
     80 - `@dependabot cancel merge` will cancel a previously requested merge and block automerging
     81 - `@dependabot reopen` will reopen this PR if it is closed
     82 - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
     83 - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
     84 - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
     85 - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
     86 
     87 
     88 </details>
     89 
     90 
     91 ## Comments
     92 
     93 ### @dependabot[bot] — 2023-01-03T16:43:20Z
     94 
     95 Superseded by #248.
     96