-
Notifications
You must be signed in to change notification settings - Fork 71
Comparing changes
Open a pull request
base repository: ossf/scorecard-action
base: v2.3.0
head repository: ossf/scorecard-action
compare: v2.3.1
- 11 commits
- 9 files changed
- 2 contributors
Commits on Oct 9, 2023
-
🌱 Bump golang from 1.21.1 to 1.21.2 (#1272)
Bumps golang from 1.21.1 to 1.21.2. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 54b14e1 - Browse repository at this point
Copy the full SHA 54b14e1View commit details
Commits on Oct 10, 2023
-
🌱 Bump step-security/harden-runner from 2.5.1 to 2.6.0 (#1273)
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.5.1 to 2.6.0. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@8ca2b8b...1b05615) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7c1648b - Browse repository at this point
Copy the full SHA 7c1648bView commit details -
🌱 Bump github/codeql-action from 2.21.9 to 2.22.1 (#1274)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.21.9 to 2.22.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ddccb87...fdcae64) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 87157ac - Browse repository at this point
Copy the full SHA 87157acView commit details -
🌱 Bump distroless/base from
a35b652
tob31a6e0
(#1275)Bumps distroless/base from `a35b652` to `b31a6e0`. --- updated-dependencies: - dependency-name: distroless/base dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for cb50491 - Browse repository at this point
Copy the full SHA cb50491View commit details -
🌱 Group Dependabot updates for GitHub Actions and Dockerfiles (#1276)
* group github action updates Signed-off-by: Spencer Schrock <sschrock@google.com> * group docker image updates Signed-off-by: Spencer Schrock <sschrock@google.com> * change docker to weekly Signed-off-by: Spencer Schrock <sschrock@google.com> --------- Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for 28d0c92 - Browse repository at this point
Copy the full SHA 28d0c92View commit details -
🌱 Bump github.com/google/go-cmp from 0.5.9 to 0.6.0 (#1277)
Bumps [github.com/google/go-cmp](https://github.com/google/go-cmp) from 0.5.9 to 0.6.0. - [Release notes](https://github.com/google/go-cmp/releases) - [Commits](google/go-cmp@v0.5.9...v0.6.0) --- updated-dependencies: - dependency-name: github.com/google/go-cmp dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 652ddd0 - Browse repository at this point
Copy the full SHA 652ddd0View commit details -
🌱 Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1278)
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.16.0 to 0.17.0. - [Commits](golang/net@v0.16.0...v0.17.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2fa1e2f - Browse repository at this point
Copy the full SHA 2fa1e2fView commit details
Commits on Oct 17, 2023
-
🌱 Bump the github-actions group with 1 update (#1280)
Bumps the github-actions group with 1 update: [github/codeql-action](https://github.com/github/codeql-action). - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@fdcae64...0116bc2) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for dbfd042 - Browse repository at this point
Copy the full SHA dbfd042View commit details -
🌱 Bump the docker-images group with 1 update (#1281)
Bumps the docker-images group with 1 update: golang. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-images ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0ea411f - Browse repository at this point
Copy the full SHA 0ea411fView commit details
Commits on Oct 23, 2023
-
🌱 Bump github.com/ossf/scorecard/v4 from v4.13.0 to v4.13.1 (#1282)
Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for 72df3bf - Browse repository at this point
Copy the full SHA 72df3bfView commit details -
🌱 Bump docker tag to for v2.3.1 release (#1284)
Signed-off-by: Spencer Schrock <sschrock@google.com>
Configuration menu - View commit details
-
Copy full SHA for 0864cf1 - Browse repository at this point
Copy the full SHA 0864cf1View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v2.3.0...v2.3.1