Sourced from ossf/scorecard-action's releases.
v2.3.0
What's Changed
- :seedling: Bump github.com/ossf/scorecard/v4 from v4.11.0 to v4.13.0 by
@âspencerschrockin ossf/scorecard-action#1270- :sparkles: Send rekor tlog index to webapp when publishing results by
@âspencerschrockin ossf/scorecard-action#1169- :bug: Prevent url clipping for GHES instances by
@ârajbosin ossf/scorecard-action#1225Documentation
- :book: Update access rights needed to see the results in code scanning by
@ârajbosin ossf/scorecard-action#1229- :book: Add package comments. by
@âspencerschrockin ossf/scorecard-action#1221- :book: Add SECURITY.md file by
@âdavid-a-wheelerin ossf/scorecard-action#1250- :book: Fix typo in token input docs by
@âaabouzaidin ossf/scorecard-action#1258New Contributors
@âdavid-a-wheelermade their first contribution in ossf/scorecard-action#1250@âaabouzaidmade their first contribution in ossf/scorecard-action#1258Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.2.0...v2.3.0
v2.2.0
What's Changed
- :seedling: Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0 by
@âspencerschrockin ossf/scorecard-action#1192Scorecard Result Viewer
Thanks to contributions from
@âcynthia-sgand@âtegiozat CLOMonitor, there is a new Scorecard Result visualization page athttps://securityscorecards.dev/viewer/?uri=<project-url>.As an example, you can see our own score visualized here Checkout our README to learn how to link your README badge to the new visualization page.
Publishing Results
This release contains two fixes which will improve the user experience when
publish_resultsistrue
- Runs that fail our workflow restrictions will fail with a 400 response indicating the problem, instead of a vague 500 status. (ossf/scorecard-action#1156, resolved ossf/scorecard-action#1150)
- Scorecard action will retry when signing results and submitting them to our web API. This should help with flakiness from connection failures. (ossf/scorecard-action#1191)
Docs
- ð Update README to accept fine-grained tokens by
@âpnachtin ossf/scorecard-action#1175- ð Update installation instructions to match current GitHub UI by
@âjoycebrumin ossf/scorecard-action#1153- ð Document the GitHub action workflow restrictions when publishing results. by
@âspencerschrockinNew Contributors
@âbobcallawaymade their first contribution in ossf/scorecard-action#1140@âpnachtmade their first contribution in ossf/scorecard-action#1175Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.1.3...v2.2.0
483ef80 :seedling: Bump docker tag for v2.3.0 release. (#1271)5d35913 :seedling: Bump github.com/ossf/scorecard/v4 from v4.11.0 to v4.13.0 (#1270)49787a6 :seedling: Bump distroless/base from 46c5b9b to a35b652 (#1269)4283c75 :seedling: Bump github/codeql-action from 2.21.8 to 2.21.9 (#1268)709ecd0 :seedling: Bump golang from 6974950 to c416cee (#1266)25bb02c :seedling: Bump actions/checkout from 4.0.0 to 4.1.0 (#1267)b687393 :seedling: Bump github/codeql-action from 2.21.5 to 2.21.8 (#1265)6a1c21f :seedling: Bump golang from cffaba7 to 6974950 (#1264)2dee8c1 :seedling: Bump github.com/sigstore/cosign/v2 from 2.1.1 to 2.2.0 (#1254)e79dcb6 :seedling: Upgrade to go 1.20 (#1262)