brave / omaha

Omaha for brave-browser
Apache License 2.0
20 stars 19 forks source link

Update ossf/scorecard-action action to v2.3.3 #85

Closed renovate[bot] closed 5 months ago

renovate[bot] commented 5 months ago

Mend Renovate

This PR contains the following updates:

Package Type Update Change
ossf/scorecard-action action patch v2.3.1 -> v2.3.3

Release Notes

ossf/scorecard-action (ossf/scorecard-action) ### [`v2.3.3`](https://togithub.com/ossf/scorecard-action/releases/tag/v2.3.3) [Compare Source](https://togithub.com/ossf/scorecard-action/compare/v2.3.2...v2.3.3) > \[!NOTE]\ > There is no v2.3.2 release as a step was skipped in the release process. This was fixed and re-released under the v2.3.3 tag #### What's Changed - :seedling: Bump github.com/ossf/scorecard/v4 (v4.13.1) to github.com/ossf/scorecard/v5 (v5.0.0-rc1) by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1366](https://togithub.com/ossf/scorecard-action/pull/1366) - :seedling: Bump github.com/ossf/scorecard/v5 from v5.0.0-rc1 to v5.0.0-rc2 by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1374](https://togithub.com/ossf/scorecard-action/pull/1374) - :seedling: Bump github.com/ossf/scorecard/v5 from v5.0.0-rc2 to v5.0.0-rc2.0.20240509182734-7ce860946928 by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1377](https://togithub.com/ossf/scorecard-action/pull/1377) For a full changelist of what these include, see the [v5.0.0-rc1](https://togithub.com/ossf/scorecard/releases/tag/v5.0.0-rc1) and [v5.0.0-rc2](https://togithub.com/ossf/scorecard/releases/tag/v5.0.0-rc2) release notes. ##### Documentation - :book: Move token discussion out of main README. by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1279](https://togithub.com/ossf/scorecard-action/pull/1279) - :book: link to `ossf/scorecard` workflow instead of maintaining an example by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1352](https://togithub.com/ossf/scorecard-action/pull/1352) - :book: update api links to new scorecard.dev site by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1376](https://togithub.com/ossf/scorecard-action/pull/1376) **Full Changelog**: https://github.com/ossf/scorecard-action/compare/v2.3.1...v2.3.3 ### [`v2.3.2`](https://togithub.com/ossf/scorecard-action/compare/v2.3.1...v2.3.2) [Compare Source](https://togithub.com/ossf/scorecard-action/compare/v2.3.1...v2.3.2)

Configuration

📅 Schedule: Branch creation - " 0-4 * 3" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

github-actions[bot] commented 5 months ago

[puLL-Merge] - ossf/scorecard-action@v2.3.1..v2.3.3

Description

This PR updates various dependencies used in the scorecard-action project, including the scorecard library itself (from v4 to v5), and several GitHub Actions. It also updates the Go version from 1.20 to 1.21.8, and the base Docker image for the action from golang:1.21.3 to golang:1.22.2.

Changes ### Changes - `.github/workflows/`: - Updated various GitHub Actions to newer versions across multiple workflow files. - `Dockerfile`: - Updated base Go image from 1.21.3 to 1.22.2. - Updated base distroless image to a newer version. - `Makefile`: - Updated LDFLAGS to reference scorecard v5. - `README.md`: - Updated documentation on using fine-grained Personal Access Tokens. - Updated URL for REST API. - Other minor documentation updates. - `action.yaml`: - Updated Docker image tag to v2.3.3. - `docs/authentication/`: - Added documentation files for fine-grained auth token and classic token. - `entrypoint/entrypoint.go`, `github/github.go`, `go.mod`, `go.sum`, `options/options.go`, `options/options_test.go`: - Updated import paths from `scorecard/v4` to `scorecard/v5`. - Updated other dependencies. - `golangci.yml`: - Changed `deadline` to `timeout`.