matrix-art.meta

Issues/PRs archive for MTRNord/matrix-art
git clone git://archive.git.mtrnord.blog/MTRNord/matrix-art.meta.git
Log | Files | Refs

412.json (9716B)


      1 {
      2   "number": 412,
      3   "title": "Bump ossf/scorecard-action from 1.0.4 to 2.1.3",
      4   "state": "closed",
      5   "diff_file": "412.diff",
      6   "author": "dependabot[bot]",
      7   "created_at": "2023-04-03T09:03:04Z",
      8   "closed_at": "2023-06-26T09:00:42Z",
      9   "merged_at": null,
     10   "base_ref": "main",
     11   "head_ref": "dependabot/github_actions/ossf/scorecard-action-2.1.3",
     12   "labels": [
     13     "dependencies",
     14     "github_actions"
     15   ],
     16   "assignees": [
     17     "MTRNord"
     18   ],
     19   "requested_reviewers": [
     20     "MTRNord"
     21   ],
     22   "body": "Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 1.0.4 to 2.1.3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a href=\"https://github.com/ossf/scorecard-action/releases\">ossf/scorecard-action's releases</a>.</em></p>\n<blockquote>\n<h2>v2.1.3</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>\ud83c\udf31 Bump github.com/ossf/scorecard/v4 from 4.10.2 to 4.10.5 by <a href=\"https://github.com/spencerschrock\"><code>@\u200bspencerschrock</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/1111\">ossf/scorecard-action#1111</a></li>\n</ul>\n<h3>Bug Fixes</h3>\n<ul>\n<li>Invalid SARIF files from a bug in scorecard\n<ul>\n<li><a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1076\">#1076</a>, <a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1094\">#1094</a></li>\n</ul>\n</li>\n<li>Vulnerabilities check crashes if a vulnerable dependency is found via OSVScanner\n<ul>\n<li><a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1092\">#1092</a></li>\n</ul>\n</li>\n<li>Scorecard action not reporting binary artifacts in the repo\n<ul>\n<li><a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1116\">#1116</a></li>\n</ul>\n</li>\n</ul>\n<p><strong>Full Scorecard Changelog</strong>: <a href=\"https://github.com/ossf/scorecard/compare/v4.10.2...v4.10.5\">https://github.com/ossf/scorecard/compare/v4.10.2...v4.10.5</a></p>\n<p><strong>Full Changelog</strong>: <a href=\"https://github.com/ossf/scorecard-action/compare/v2.1.2...v2.1.3\">https://github.com/ossf/scorecard-action/compare/v2.1.2...v2.1.3</a></p>\n<h2>v2.1.2</h2>\n<h2>What's Changed</h2>\n<h3>Fixes</h3>\n<ul>\n<li>\ud83c\udf31 Bump scorecard dependency to v4.10.2 to remove a CODEOWNERS printf statement. by <a href=\"https://github.com/spencerschrock\"><code>@\u200bspencerschrock</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/1054\">ossf/scorecard-action#1054</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a href=\"https://github.com/ossf/scorecard-action/compare/v2.1.1...v2.1.2\">https://github.com/ossf/scorecard-action/compare/v2.1.1...v2.1.2</a></p>\n<h2>v2.1.1</h2>\n<h2>Scorecard version</h2>\n<p>This release use <a href=\"https://github.com/ossf/scorecard/releases/tag/v4.10.1\">Scorecard's v4.10.1</a></p>\n<p><strong>Full Changelog</strong>: <a href=\"https://github.com/ossf/scorecard-action/compare/v2.1.0...v2.1.1\">https://github.com/ossf/scorecard-action/compare/v2.1.0...v2.1.1</a></p>\n<h2>v2.1.0</h2>\n<h2>What's Changed</h2>\n<h3>Scorecard version</h3>\n<p>This release uses <a href=\"https://github.com/ossf/scorecard/releases/tag/v4.10.0\">scorecard v4.10.0</a>.</p>\n<h3>Improvements</h3>\n<ul>\n<li>Docker build workflow by <a href=\"https://github.com/naveensrinivasan\"><code>@\u200bnaveensrinivasan</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/981\">ossf/scorecard-action#981</a></li>\n<li>Use root user in distroless to support GitHub Actions by <a href=\"https://github.com/spencerschrock\"><code>@\u200bspencerschrock</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/994\">ossf/scorecard-action#994</a></li>\n<li>Disable pull_request_target by <a href=\"https://github.com/laurentsimon\"><code>@\u200blaurentsimon</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/1031\">ossf/scorecard-action#1031</a></li>\n</ul>\n<h3>Documentation</h3>\n<ul>\n<li>Add PAT section explaining risks by <a href=\"https://github.com/olivekl\"><code>@\u200bolivekl</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/1024\">ossf/scorecard-action#1024</a></li>\n<li>Make the badge text easier to copy by <a href=\"https://github.com/rajbos\"><code>@\u200brajbos</code></a> in <a href=\"https://redirect.github.com/ossf/scorecard-action/pull/1026\">ossf/scorecard-action#1026</a></li>\n</ul>\n<!-- raw HTML omitted -->\n</blockquote>\n<p>... (truncated)</p>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/80e868c13c90f172d68d1f4501dee99e2479f7af\"><code>80e868c</code></a> :seedling: Bump docker tag for release. (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1117\">#1117</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/aed6134b530f65762d8da8171e42d5ff9108d1a1\"><code>aed6134</code></a> :seedling: Bump golang.org/x/net from 0.7.0 to 0.8.0 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1099\">#1099</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/33dfbd30942d716772ffc2fa55d8ea035df8fa73\"><code>33dfbd3</code></a> \ud83c\udf31 Bump github.com/ossf/scorecard/v4 from 4.10.2 to 4.10.5 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1111\">#1111</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/193ae3767915e21afcbf44eff2fe6b41edb4d245\"><code>193ae37</code></a> :seedling: Bump actions/dependency-review-action from 3.0.3 to 3.0.4 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1110\">#1110</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/ca9bf9578ec9f68bd1cd99bfbde41ba4f0516a50\"><code>ca9bf95</code></a> :seedling: Bump actions/cache from 3.2.6 to 3.3.1 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1103\">#1103</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/fa1521272c15724b2dce74f8b1ce9bd6df33b7ae\"><code>fa15212</code></a> :seedling: Bump github/codeql-action from 2.2.4 to 2.2.7 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1105\">#1105</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/136025e1eacdf84d71a9c3227f53d7c737852cd8\"><code>136025e</code></a> :seedling: Bump step-security/harden-runner from 2.1.0 to 2.2.1 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1104\">#1104</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/c59c116cbead5af2de7d75f4d82cf5a2ef5b0304\"><code>c59c116</code></a> :seedling: Bump actions/cache from 3.2.5 to 3.2.6 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1097\">#1097</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/7cc371152c77bfecfa34fdfb62b1630ff3682cf1\"><code>7cc3711</code></a> :seedling: Bump github.com/emicklei/go-restful (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1086\">#1086</a>)</li>\n<li><a href=\"https://github.com/ossf/scorecard-action/commit/570a953ea0770f30a8aa0a778cfc4bc955bbf9c4\"><code>570a953</code></a> :seedling: Bump actions/cache from 3.2.4 to 3.2.5 (<a href=\"https://redirect.github.com/ossf/scorecard-action/issues/1088\">#1088</a>)</li>\n<li>Additional commits viewable in <a href=\"https://github.com/ossf/scorecard-action/compare/c1aec4ac820532bab364f02a81873c555a0ba3a1...80e868c13c90f172d68d1f4501dee99e2479f7af\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ossf/scorecard-action&package-manager=github_actions&previous-version=1.0.4&new-version=2.1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n</details>\n\n<!-- Replace -->\n----\n\u231b Deploy Preview - Build in Progress\n<!-- Replace -->\n",
     23   "comments": [
     24     {
     25       "author": "dependabot[bot]",
     26       "created_at": "2023-06-26T09:00:41Z",
     27       "body": "Superseded by #492."
     28     }
     29   ],
     30   "review_comments": []
     31 }