Skip to content

Bump ossf/scorecard-action from 2.1.2 to 2.2.0#1763

Merged
0ssigeno merged 1 commit intodevelopfrom
dependabot/github_actions/develop/ossf/scorecard-action-2.2.0
Jun 27, 2023
Merged

Bump ossf/scorecard-action from 2.1.2 to 2.2.0#1763
0ssigeno merged 1 commit intodevelopfrom
dependabot/github_actions/develop/ossf/scorecard-action-2.2.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 27, 2023

Bumps ossf/scorecard-action from 2.1.2 to 2.2.0.

Release notes

Sourced from ossf/scorecard-action's releases.

v2.2.0

What's Changed

Scorecard Result Viewer

Thanks to contributions from @​cynthia-sg and @​tegioz at CLOMonitor, there is a new Scorecard Result visualization page at https://securityscorecards.dev/viewer/?uri=<project-url>.

As an example, you can see our own score visualized here Checkout our README to learn how to link your README badge to the new visualization page.

Publishing Results

This release contains two fixes which will improve the user experience when publish_results is true

Docs

New Contributors

Full Changelog: ossf/scorecard-action@v2.1.3...v2.2.0

v2.1.3

What's Changed

Bug Fixes

  • Invalid SARIF files from a bug in scorecard
  • Vulnerabilities check crashes if a vulnerable dependency is found via OSVScanner
  • Scorecard action not reporting binary artifacts in the repo

Full Scorecard Changelog: ossf/scorecard@v4.10.2...v4.10.5

Full Changelog: ossf/scorecard-action@v2.1.2...v2.1.3

Commits
  • 08b4669 🌱 Bump docker tag to for v2.2.0 release. (#1194)
  • 3c7470f 📖 Update README badge link to use new uri param. (#1185)
  • a164dbc 🌱 Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0 (#1192)
  • 597960e 📖 Update README to accept fine-grained tokens (#1175)
  • 8808ed2 🌱 Retry external network calls when publishing results (#1191)
  • 0eed6cb 🌱 Bump golang.org/x/net from 0.10.0 to 0.11.0
  • 6c6335c 🌱 Bump github/codeql-action from 2.3.6 to 2.20.0
  • 7f1baf3 📖 Switch recommended badge link to the new viewer. (#1176)
  • df98bbc 🌱 Bump actions/checkout from 3.5.2 to 3.5.3
  • 75886d4 🌱 Bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 (#1172)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Jun 27, 2023
@0ssigeno 0ssigeno merged commit d095b0b into develop Jun 27, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/develop/ossf/scorecard-action-2.2.0 branch June 27, 2023 08:39
carellamartina pushed a commit that referenced this pull request Jul 3, 2023
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.1.2 to 2.2.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@e38b190...08b4669)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
drosetti added a commit that referenced this pull request Jul 26, 2023
* added CopyToClipboardButton

* adjusted copy_text  field and visualizer tests

* added function to handle visualizers errors (#1741)

* added function to handle visualizers errors

* doc update

* More status mgmt (#1740)

* More status mgmt

Signed-off-by: 0ssigeno <[email protected]>

* Black

Signed-off-by: 0ssigeno <[email protected]>

* Minor fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fix migrations

Signed-off-by: 0ssigeno <[email protected]>

* Fix migrations

Signed-off-by: 0ssigeno <[email protected]>

* Prettier

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

---------

Signed-off-by: 0ssigeno <[email protected]>

* updated frontend dependencies

* Visualizer connected to playbook (#1755)

* Start

Signed-off-by: 0ssigeno <[email protected]>

* More stuff

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fix

Signed-off-by: 0ssigeno <[email protected]>

* Fix

Signed-off-by: 0ssigeno <[email protected]>

* Blake

Signed-off-by: 0ssigeno <[email protected]>

* Visualizer config points only to a single playbook, not many

Signed-off-by: 0ssigeno <[email protected]>

* Fix migration

Signed-off-by: 0ssigeno <[email protected]>

* Fix tests

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fix post review

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Blake

Signed-off-by: 0ssigeno <[email protected]>

* little adjustments

* Blake

Signed-off-by: 0ssigeno <[email protected]>

* Unused migration

Signed-off-by: 0ssigeno <[email protected]>

* Fix page order

Signed-off-by: 0ssigeno <[email protected]>

* Fix migration

Signed-off-by: 0ssigeno <[email protected]>

* Fix

Signed-off-by: 0ssigeno <[email protected]>

---------

Signed-off-by: 0ssigeno <[email protected]>
Co-authored-by: Matteo Lodi <[email protected]>

* adjusted order in docs

* added link to HackinBo presentation

* Bump ossf/scorecard-action from 2.1.2 to 2.2.0 (#1763)

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.1.2 to 2.2.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@e38b190...08b4669)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump pre-commit from 3.2.1 to 3.3.3 in /requirements (#1764)

Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 3.2.1 to 3.3.3.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v3.2.1...v3.3.3)

---
updated-dependencies:
- dependency-name: pre-commit
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Fix captcha (#1761)

* Fix captcha

Signed-off-by: 0ssigeno <[email protected]>

* Fix backend

Signed-off-by: 0ssigeno <[email protected]>

* fix frontend

* Fix environments

Signed-off-by: 0ssigeno <[email protected]>

* Fix

Signed-off-by: 0ssigeno <[email protected]>

* black

* Fix deepsource

Signed-off-by: 0ssigeno <[email protected]>

---------

Signed-off-by: 0ssigeno <[email protected]>
Co-authored-by: Daniele Rosetti <[email protected]>

* Fix waiting

Signed-off-by: 0ssigeno <[email protected]>

* Pivot framework (#1739)

* Pivot

Signed-off-by: 0ssigeno <[email protected]>

* More stuff

Signed-off-by: 0ssigeno <[email protected]>

* More stuff

Signed-off-by: 0ssigeno <[email protected]>

* Typo

Signed-off-by: 0ssigeno <[email protected]>

* Pivot

Signed-off-by: 0ssigeno <[email protected]>

* Minor fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Update tests/pivot_manager/test_views.py

Co-authored-by: code-review-doctor[bot] <72320148+code-review-doctor[bot]@users.noreply.github.com>

* Update tests/pivot_manager/test_views.py

Co-authored-by: code-review-doctor[bot] <72320148+code-review-doctor[bot]@users.noreply.github.com>

* Update api_app/pivots_manager/models.py

Co-authored-by: code-review-doctor[bot] <72320148+code-review-doctor[bot]@users.noreply.github.com>

* Fix post review

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* More fixes and tests

Signed-off-by: 0ssigeno <[email protected]>

* More fixes

Signed-off-by: 0ssigeno <[email protected]>

* Minor fixes

Signed-off-by: 0ssigeno <[email protected]>

* deepsource

Signed-off-by: 0ssigeno <[email protected]>

* typo

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Blake

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Fixes

Signed-off-by: 0ssigeno <[email protected]>

* Manage files

Signed-off-by: 0ssigeno <[email protected]>

* Fix test

Signed-off-by: 0ssigeno <[email protected]>

---------

Signed-off-by: 0ssigeno <[email protected]>
Co-authored-by: code-review-doctor[bot] <72320148+code-review-doctor[bot]@users.noreply.github.com>
Co-authored-by: Matteo Lodi <[email protected]>

* set USE_RECAPTCHA as False by default

* collapsed job metadata in job result (#1754)

* collapsed jobInfoCard in jobResult

* adjusted UncontrolledTooltip message

* added collapse test

* Fix

Signed-off-by: 0ssigeno <[email protected]>

* Frontend improvements (#1772)

* fixed status

* changed size for children elements

* removed test

* test modify

* added small

* improved small value

* fixed frontend tests

* prettier

* Fix migrations

Signed-off-by: 0ssigeno <[email protected]>

* added CopyToClipboardButton

* adjusted copy_text  field and visualizer tests

* added VisualizerTooltip component + adjusted tests

* removed redundant default arguments

* adjusted tooltip position + tests

* fix

* adjested buttons

* fixed tests

---------

Signed-off-by: 0ssigeno <[email protected]>
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Daniele Rosetti <[email protected]>
Co-authored-by: Simone Berni <[email protected]>
Co-authored-by: Daniele Rosetti <[email protected]>
Co-authored-by: Matteo Lodi <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: 0ssigeno <[email protected]>
Co-authored-by: code-review-doctor[bot] <72320148+code-review-doctor[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant