Sourced from ossf/scorecard-action's releases.
v2.1.0
What's Changed
Scorecard version
This release uses scorecard v4.10.0.
Improvements
- Docker build workflow by
@naveensrinivasan
in ossf/scorecard-action#981- Use root user in distroless to support GitHub Actions by
@spencerschrock
in ossf/scorecard-action#994- Disable pull_request_target by
@laurentsimon
in ossf/scorecard-action#1031Documentation
- Add PAT section explaining risks by
@olivekl
in ossf/scorecard-action#1024- Make the badge text easier to copy by
@rajbos
in ossf/scorecard-action#1026New Contributors
@joycebrum
made their first contribution in ossf/scorecard-action#984@rajbos
made their first contribution in ossf/scorecard-action#1026Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.0.6...v2.1.0
937ffa9
Minor release v2.1.0 (#1040)a42a080
Create scorecards.yml (#1041)cf93e24
:seedling: Bump github.com/ossf/scorecard/v4 from 4.8.0 to 4.10.0 (#1039)b2f0d4e
:seedling: Bump golang from 04f76f9
to 54184d6
(#1038)bff7712
:seedling: Bump actions/checkout from 3.1.0 to 3.2.0 (#1035)cd50e39
:seedling: Bump github/codeql-action from 2.1.35 to 2.1.36 (#1036)420fff2
update (#1031)8d8c1ec
:seedling: Bump golang.org/x/net from 0.2.0 to 0.4.0 (#1033)c694c35
feat: update logging (#1032)f27f8fe
:seedling: Bump golang from 84ac6d8
to 04f76f9
(#1029)