Sourced from ossf/scorecard-action's releases.
v2.4.0
What's Changed
This update bumps the Scorecard version to the v5 release. For a complete list of changes, please refer to the v5.0.0 release notes. Of special note to Scorecard Action is the Maintainer Annotation feature, which can be used to suppress some Code Scanning false positives. Alerts will not be generated for any Scorecard Check with an annotation.
- :seedling: Bump github.com/ossf/scorecard/v5 from v5.0.0-rc2 to v5.0.0 by
@âspencerschrockin ossf/scorecard-action#1410- :bug: lower license sarif alert threshold to 9 by
@âspencerschrockin ossf/scorecard-action#1411Documentation
- docs: dogfooding badge by
@âjkowalleckin ossf/scorecard-action#1399New Contributors
@âjkowalleckmade their first contribution in ossf/scorecard-action#1399Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.3.3...v2.4.0
62b2cac bump docker tag to v2.4.0 for release (#1414)c09630c lower license score alert threshold to 9 (#1411)cf8594c :seedling: Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.3.0 (#1413)de5fcb9 :seedling: Bump the github-actions group with 2 updates (#1412)a46b90b bump scorecard to v5.0.0 release (#1410)9fc518d :seedling: Bump golang in the docker-images group (#1407)a8eaa1b :seedling: Bump the github-actions group with 2 updates (#1408)873d5fd :seedling: Bump the github-actions group across 1 directory with 2 updates (#...54cc1fe :seedling: Bump the docker-images group with 2 updates (#1401)82bcb91 :seedling: Bump golang.org/x/net from 0.26.0 to 0.27.0 (#1400)