Bump ossf/scorecard-action from 2.1.0 to 2.1.2 by dependabot[bot] 路 Pull Request #223 路 step-security/harden-runner (original) (raw)
Bumps ossf/scorecard-action from 2.1.0 to 2.1.2.
Release notes
Sourced from ossf/scorecard-action's releases.
v2.1.2
What's Changed
Fixes
- 馃尡 Bump scorecard dependency to v4.10.2 to remove a CODEOWNERS printf statement. by @鈥媠pencerschrock in ossf/scorecard-action#1054
Full Changelog: ossf/scorecard-action@v2.1.1...v2.1.2
v2.1.1
Scorecard version
This release use Scorecard's v4.10.1
Full Changelog: ossf/scorecard-action@v2.1.0...v2.1.1
Commits
- e38b190 Bump docker tag for release. (#1055)
- 7da02bf Bump scorecard to v4.10.2 to remove a CODEOWNERS printf statement. (#1054)
- 013c0f8 馃尡 Bump actions/dependency-review-action from 3.0.1 to 3.0.2
- f93c094 馃尡 Bump github/codeql-action from 2.1.36 to 2.1.37
- ce8978e 馃尡 Bump actions/upload-artifact from 3.1.0 to 3.1.1
- 5ce49db 馃尡 Bump actions/setup-go from 3.4.0 to 3.5.0
- 15c10fc Update tag to v2.1.1 (#1047)
- f96da1a 馃尡 Update scorecard for the panic (#1045)
- 813a825 Complete the list of required actions (#1044)
- be62ea8 Update RELEASE.md (#1042)
- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)