actions / starter-workflows

Accelerating new GitHub Actions workflows
https://github.com/features/actions
Other
8.59k stars 5.08k forks source link

update Scorecard Action hashes and version comments #2348

Closed spencerschrock closed 3 months ago

spencerschrock commented 3 months ago

ossf/scorecard-action v2.1.2 is old and is broken after a Sigstore change. https://blog.sigstore.dev/tuf-root-update/

(Also fixes #2138)

Pre-requisites


Please note that at this time we are only accepting new starter workflows for Code Scanning. Updates to existing starter workflows are fine.


Tasks

For all workflows, the workflow:

For CI workflows, the workflow:

For Code Scanning workflows, the workflow:

Some general notes: