Sourced from ossf/scorecard-action's releases.
v2.2.0
What's Changed
- :seedling: Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0 by
@spencerschrock
in ossf/scorecard-action#1192Scorecard Result Viewer
Thanks to contributions from
@cynthia-sg
and@tegioz
at CLOMonitor, there is a new Scorecard Result visualization page athttps://securityscorecards.dev/viewer/?uri=<project-url>
.As an example, you can see our own score visualized here Checkout our README to learn how to link your README badge to the new visualization page.
Publishing Results
This release contains two fixes which will improve the user experience when
publish_results
istrue
- Runs that fail our workflow restrictions will fail with a 400 response indicating the problem, instead of a vague 500 status. (ossf/scorecard-action#1156, resolved ossf/scorecard-action#1150)
- Scorecard action will retry when signing results and submitting them to our web API. This should help with flakiness from connection failures. (ossf/scorecard-action#1191)
Docs
- 📖 Update README to accept fine-grained tokens by
@pnacht
in ossf/scorecard-action#1175- 📖 Update installation instructions to match current GitHub UI by
@joycebrum
in ossf/scorecard-action#1153- 📖 Document the GitHub action workflow restrictions when publishing results. by
@spencerschrock
inNew Contributors
@bobcallaway
made their first contribution in ossf/scorecard-action#1140@pnacht
made their first contribution in ossf/scorecard-action#1175Full Changelog: https://github.com/ossf/scorecard-action/compare/v2.1.3...v2.2.0
08b4669
:seedling: Bump docker tag to for v2.2.0 release. (#1194)3c7470f
:book: Update README badge link to use new uri param. (#1185)a164dbc
:seedling: Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0 (#1192)597960e
:book: Update README to accept fine-grained tokens (#1175)8808ed2
:seedling: Retry external network calls when publishing results (#1191)0eed6cb
:seedling: Bump golang.org/x/net from 0.10.0 to 0.11.06c6335c
:seedling: Bump github/codeql-action from 2.3.6 to 2.20.07f1baf3
:book: Switch recommended badge link to the new viewer. (#1176)df98bbc
:seedling: Bump actions/checkout from 3.5.2 to 3.5.375886d4
:seedling: Bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 (#1172)