ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.63k stars 504 forks source link

:seedling: Bump github.com/goreleaser/goreleaser/v2 from 2.0.1 to 2.1.0 in /tools #4240

Closed dependabot[bot] closed 4 months ago

dependabot[bot] commented 4 months ago

Bumps github.com/goreleaser/goreleaser/v2 from 2.0.1 to 2.1.0.

Release notes

Sourced from github.com/goreleaser/goreleaser/v2's releases.

v2.1.0

Changelog

New Features

  • 65a3e06e9227a0818799c9065887567f1bed37ac: feat(archive): support .tzst suffix (#4870) (@​sorairolake)
  • 3e663003b177b1f6b5c9c4535e90bcf5db3c87e4: feat(blob): allow to upload only extra_files (#4925) (@​caarlos0)
  • 34ba5b6a79b263cf5585a62b1393353060a8ceda: feat(build): use GOCACHEPROG if set (#4941) (@​caarlos0)
  • ac40ce8a805e64db605dc5a2d8b99e63886373b2: feat(chocolatey): allow template in copyright, provide ctx.ReleaseNotes (#4858) (@​bradenhilton)
  • cc114fc8b906e28d10d2db1100da3783d1f2b508: feat(nfpm): add support for ipk package format (#4863) (@​schmidtw)
  • cefec7c58bd8ece27bf13c7ac897a9e0b0ce0635: feat(nfpm): support arm in termux (#4901) (@​rsteube)
  • 2d54bf0211497e4ea66d2e0aafaea8feee86be1f: feat(notary): allow to sign without notarizing (#4919) (@​caarlos0)
  • f3fce3df5bd88ccea3d902d071918b7f4b6de8b2: feat: --skip=archive (#4916) (@​caarlos0)
  • f5c4fce822dace73bd578a12f7bf14ea307a42bd: feat: build --auto-snapshot (#4917) (@​caarlos0)
  • 675629e79821b7c0e15d1bc77d3ec9130a6f6c45: feat: support extra_files in http upload and artifactories (#4940) (@​caarlos0)

Bug fixes

  • afd92ffe0fc1070081dcd7e0e49cf87f0749853f: fix(github): set discussion category on publish only (@​caarlos0)
  • 50a6a96257843532bfa3ca4c8b116a5d6fc4fb39: fix(gitlab): better handle CI_JOB_TOKEN and unavailable APIs (#4918) (@​caarlos0)
  • 2e9eefb5b90761044e5f029ab38c747f7a81df4b: fix(snapcraft): set confinement to strict by default (@​caarlos0)
  • 9b6af9efba812278bd652314ff6a3c85214ac9cc: fix: actually respect changelog.abbrev (#4942) (@​caarlos0)
  • 212dbb39d4dd5f3db9b432b1f7d41065af70f39b: fix: improve snapcraft configuration handling (@​caarlos0)
  • 9d513696c2c5bccdb07d987c52a6667962f8964b: fix: make latest on drafts (#4966) (@​caarlos0)
  • 0d1e3c023f4f840642d8d817efb56c0aff11b6d5: fix: moving some logs to debug (@​caarlos0)
  • 9fcfaf95cf5b4c990e2f47ec9a980cfa3d950048: fix: revert unwanted change (@​caarlos0)
  • f0b4db184e4f9b2919442be5b34a738f83db3dbe: fix: snapcraft temporary directory + concurrency (#4963) (@​caarlos0)
  • c36a79789fb0083cfff0018f20575c6ef6c6b380: fix: typo (@​caarlos0)

Dependency updates

  • 13ab48447a1a1c4952ac36bf70241edbb80381cc: chore(deps): bump golang to 1.22.5-alpine (#4993) (@​caarlos0)
  • 763f4a55bb374ab334a66cb00e0db9887e20d114: chore(deps): bump actions/checkout from 4.1.6 to 4.1.7 (#4933) (@​dependabot[bot])
  • b83ac8fda52fc3ec0e0365be3cdde230f65e8d98: chore(deps): bump actions/setup-go from 5.0.1 to 5.0.2 (#4984) (@​dependabot[bot])
  • 5386c84551cac44f90a346d30e483a93ed620d73: chore(deps): bump anchore/sbom-action from 0.16.0 to 0.16.1 (#4979) (@​dependabot[bot])
  • d25edd591b716d870f47c1301d98b2e333f9d207: chore(deps): bump anchore/scan-action from 3 to 4 (#4985) (@​dependabot[bot])
  • 9ca52e44b12fb2e412063f67f851dd1339a5a58e: chore(deps): bump codecov/codecov-action from 4.4.1 to 4.5.0 (#4932) (@​dependabot[bot])
  • 02c4f93c7bf31cd85a0dbd37c9590ab6d969dbc2: chore(deps): bump docker/setup-buildx-action from 3.3.0 to 3.4.0 (#4973) (@​dependabot[bot])
  • 9786269e109eabbfb6e7220f3133ebe2bf884179: chore(deps): bump docker/setup-qemu-action from 3.0.0 to 3.1.0 (#4972) (@​dependabot[bot])
  • 4d9cd0c453d16cab62ce71061c12d740200876d8: chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.5.1 to 1.6.0 (#4928) (@​dependabot[bot])
  • f080c2620849c76fabbfd382a678923c9b4c01c3: chore(deps): bump github.com/anchore/quill from 0.4.1 to 0.4.2 (#4988) (@​dependabot[bot])
  • 6be7b143f6446658382c50ef0ed4e1c3a717f9e5: chore(deps): bump github.com/aws/aws-sdk-go from 1.53.0 to 1.54.0 (#4929) (@​dependabot[bot])
  • 1892aa38d682c570a04320706a255da9aee2d2a5: chore(deps): bump github.com/caarlos0/env/v11 from 11.0.1 to 11.1.0 (#4951) (@​dependabot[bot])
  • 6548d4b74f6d5a0b0d7cbbdbc5e128684e3018b6: chore(deps): bump github.com/charmbracelet/lipgloss from 0.11.0 to 0.11.1 (#4982) (@​dependabot[bot])
  • 56529e1b7c70b155f4edd0cd260bf5bf9cdad084: chore(deps): bump github.com/charmbracelet/x/exp/ordered from 0.0.0-20231010190216-1cb11efc897d to 0.1.0 (#4948) (@​dependabot[bot])
  • 81f4b6558e51e177b7219a32744ccc792433fab8: chore(deps): bump github.com/distribution/distribution/v3 from 3.0.0-alpha.1 to 3.0.0-beta.1 (#4983) (@​dependabot[bot])
  • 01f58f98678a05d1b955f24a04a4a9a02c4f04c9: chore(deps): bump github.com/google/go-containerregistry from 0.19.1 to 0.19.2 (#4946) (@​dependabot[bot])
  • c79137ceb28505889bf87b875a80f78d174eaeed: chore(deps): bump github.com/google/go-containerregistry from 0.19.2 to 0.20.0 (#4978) (@​dependabot[bot])
  • 72fcfc6ea529562da1ce7654f4dac2b67bbef010: chore(deps): bump github.com/goreleaser/nfpm/v2 from 2.37.1 to 2.38.0 (#4976) (@​dependabot[bot])
  • 08b19ba326c5f6f8abcf71a0a56d38e4d268c6a1: chore(deps): bump github.com/hashicorp/go-retryablehttp from 0.7.5 to 0.7.7 (#4955) (@​dependabot[bot])
  • dc4f450233772431435f403bd922efc9060b60b8: chore(deps): bump github.com/klauspost/compress from 1.17.8 to 1.17.9 (#4930) (@​dependabot[bot])
  • 5b7d4734dd802a53e9866dfda900b6ce27799923: chore(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1 (#4945) (@​dependabot[bot])
  • 9ee9a8f6cc9e2eac99009f0d92251a0aec026236: chore(deps): bump github.com/xanzy/go-gitlab from 0.105.0 to 0.106.0 (#4958) (@​dependabot[bot])
  • 639902d0c85d331006da7ec9fa1c1f7e9b4e6a7a: chore(deps): bump github/codeql-action from 3.25.10 to 3.25.11 (#4967) (@​dependabot[bot])
  • 42d6005f40ae43a5933b13b1422aefed2f86ac4d: chore(deps): bump github/codeql-action from 3.25.8 to 3.25.10 (#4935) (@​dependabot[bot])
  • 908dabaf0aa47f1c88418bf756d565081ac72dd3: chore(deps): bump golang from 1.22.4-alpine to 1.23rc1-alpine (#4970) (@​dependabot[bot])

... (truncated)

Commits
  • 2a1bcac docs: update schemas
  • c36a797 fix: typo
  • 212dbb3 fix: improve snapcraft configuration handling
  • 13ab484 chore(deps): bump golang to 1.22.5-alpine (#4993)
  • ff33256 docs: blob.md neq -> ne (#4991)
  • 2e9eefb fix(snapcraft): set confinement to strict by default
  • 2226cb5 chore: go mod tidy
  • f080c26 chore(deps): bump github.com/anchore/quill from 0.4.1 to 0.4.2 (#4988)
  • e421f6d docs: improve docs on goamd64
  • 33e0fc4 test(nfpm): improve ipk test
  • Additional commits viewable in compare view


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @spencerschrock.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)