Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade scorecard version #1

Merged
merged 395 commits into from
Feb 28, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
395 commits
Select commit Hold shift + click to select a range
60615ce
:seedling: Remove go.mod replaces (#3440)
spencerschrock Sep 13, 2023
d03ca5c
:seedling: Bump actions/cache from 3.3.1 to 3.3.2 (#3463)
dependabot[bot] Sep 13, 2023
1bd5b42
:seedling: Bump actions/upload-artifact from 3.1.2 to 3.1.3 (#3459)
dependabot[bot] Sep 13, 2023
8a54672
:seedling: Bump actions/dependency-review-action from 3.0.8 to 3.1.0 …
dependabot[bot] Sep 13, 2023
0fcf4d9
:seedling: Bump tj-actions/changed-files from 39.0.0 to 39.0.2 (#3470)
dependabot[bot] Sep 13, 2023
a51f0af
:seedling: Bump github.com/bradleyfalzon/ghinstallation/v2 (#3467)
dependabot[bot] Sep 13, 2023
9c9c84b
:seedling: Bump cloud.google.com/go/bigquery from 1.54.0 to 1.55.0 (#…
dependabot[bot] Sep 13, 2023
e515c2a
✨ Support Branch-Protection via GitHub Repository Rules (#3354)
thepwagner Sep 14, 2023
4a0e3ff
🌱 workflows/stale: Update workflow to increase operations-per-run to …
afmarcum Sep 16, 2023
f7f75d0
Update URI() for GitLab repos. Add fuzzing test (#3477)
raghavkaul Sep 18, 2023
00f4d51
:bug: Print Info in Empty Repo Scans (#3426)
leec94 Sep 18, 2023
84b53a9
:seedling: Bump goreleaser/goreleaser-action from 4.6.0 to 5.0.0 (#3478)
dependabot[bot] Sep 18, 2023
59da3b3
:seedling: Bump github.com/go-git/go-git/v5 from 5.8.1 to 5.9.0 (#3479)
dependabot[bot] Sep 18, 2023
fdac84a
:seedling: Bump github.com/google/osv-scanner from 1.3.6 to 1.4.0 (#3…
dependabot[bot] Sep 19, 2023
ac13ac7
:seedling: Bump tj-actions/changed-files from 39.0.2 to 39.1.0 (#3488)
dependabot[bot] Sep 19, 2023
5c93fe6
:book: Add webviewer link (#3490)
olivekl Sep 19, 2023
893a472
🌱 workflows/stale: Remove issue auto-close (#3493)
afmarcum Sep 19, 2023
93edfbc
:seedling: Reduce confusion around codecov check status. (#3492)
spencerschrock Sep 19, 2023
fe7906f
:book: Add gitlab links to viewer example (#3494)
olivekl Sep 19, 2023
0ce62a8
:bug: Fix npe for GitLab repos without license API data (#3500)
raghavkaul Sep 20, 2023
5a5a656
:seedling: Bump tj-actions/changed-files from 39.1.0 to 39.1.2 (#3504)
dependabot[bot] Sep 21, 2023
fa31d56
:seedling: Bump actions/checkout from 4.0.0 to 4.1.0 (#3511)
dependabot[bot] Sep 25, 2023
7626a05
:sparkles: scdiff: add basic stats command to count scores by buckets…
spencerschrock Sep 25, 2023
fd12f6a
:seedling: Switch test import to remove gotest.tools dependency. (#3501)
spencerschrock Sep 25, 2023
bbd673c
:bug: Set repo commit SHA in results after fetching successfully. (#3…
spencerschrock Sep 25, 2023
6aa3bcc
:seedling: Don't close stale issues explicitly (#3513)
spencerschrock Sep 25, 2023
8752511
:sparkles: Move "EnforcesAdmins" to tier 5 Branch-Protection (#3502)
spencerschrock Sep 25, 2023
052d89b
:bug: Pinned-Dependencies: only score detected ecosystems (#3436)
gabibguti Sep 25, 2023
52463bd
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools (#3497)
dependabot[bot] Sep 25, 2023
7a94273
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.12.0 to 2.12.1 (#3496)
dependabot[bot] Sep 25, 2023
7034306
:seedling: Bump github.com/xanzy/go-gitlab from 0.91.1 to 0.92.1 (#3517)
dependabot[bot] Sep 26, 2023
c738750
📖 Update docs for Signed-Releases check (#3469)
raghavkaul Oct 2, 2023
c061367
:seedling: Bump github.com/rhysd/actionlint from 1.6.15 to 1.6.26 (#3…
spencerschrock Oct 2, 2023
86aed2c
:seedling: Bump github.com/onsi/gomega from 1.27.10 to 1.28.0 (#3523)
dependabot[bot] Oct 3, 2023
e81ec7e
✨ Add --output argument to write results to file (#3482)
gabibguti Oct 3, 2023
7161ec1
:seedling: Bump step-security/harden-runner from 2.5.1 to 2.6.0 (#3532)
dependabot[bot] Oct 3, 2023
2c25c46
:seedling: Bump tj-actions/changed-files from 39.1.2 to 39.2.1 (#3531)
dependabot[bot] Oct 3, 2023
7ad9de3
:seedling: Fix race condition in output file test. (#3533)
spencerschrock Oct 4, 2023
3785f9c
:book: Fix documentation typos (#3505)
omahs Oct 4, 2023
a9e2505
:sparkles: broaden job matcher for semantic release (#3506)
secustor Oct 4, 2023
7a1c8fe
:seedling: Bump nick-invision/retry from 2.8.3 to 2.9.0 (#3519)
dependabot[bot] Oct 4, 2023
3c27597
:seedling: Bump github.com/xanzy/go-gitlab from 0.92.1 to 0.92.3 (#3528)
dependabot[bot] Oct 4, 2023
71078d8
:seedling: Bump github.com/otiai10/copy from 1.12.0 to 1.14.0 (#3527)
dependabot[bot] Oct 4, 2023
5e05661
:seedling: Bump github.com/google/osv-scanner from 1.4.0 to 1.4.1 (#3…
dependabot[bot] Oct 5, 2023
64c491b
:seedling: Bump github.com/xanzy/go-gitlab from 0.92.3 to 0.93.0 (#3537)
dependabot[bot] Oct 5, 2023
e1d3abc
:sparkles: scdiff: Limit generating results to specific checks (#3535)
spencerschrock Oct 5, 2023
1c8f6a8
:seedling: Add probe test utility (#3541)
AdamKorcz Oct 6, 2023
971f3e8
:seedling: Sort fields of raw results alphabetically (#3540)
AdamKorcz Oct 6, 2023
5187087
:seedling: Bump ossf/scorecard-action from 2.2.0 to 2.3.0 (#3544)
dependabot[bot] Oct 9, 2023
9619d4e
:seedling: Bump golang.org/x/oauth2 from 0.12.0 to 0.13.0 (#3545)
dependabot[bot] Oct 9, 2023
c2cf090
:seedling: Bump github.com/xanzy/go-gitlab from 0.93.0 to 0.93.1 (#3546)
dependabot[bot] Oct 9, 2023
03060f2
:seedling: Bump distroless/base from `27647a6` to `29da700` and golan…
spencerschrock Oct 9, 2023
74c57cd
:seedling: Bump cloud.google.com/go/bigquery from 1.55.0 to 1.56.0 (#…
dependabot[bot] Oct 9, 2023
034e6b2
:seedling: Add OutcomeNotApplicable (#3539)
AdamKorcz Oct 9, 2023
bd640f7
:sparkles: Add additional fuzzing probes (#3473)
DavidKorczynski Oct 9, 2023
29aa5d2
:book: fix "default" typo (#3543)
testwill Oct 10, 2023
f2ce613
:seedling: checks/raw: fix struct alignment linter issue (#3550)
spencerschrock Oct 10, 2023
6c43301
:seedling: Add map to Finding (#3558)
AdamKorcz Oct 11, 2023
bada658
:seedling: Bump golang.org/x/net from 0.16.0 to 0.17.0 (#3563)
dependabot[bot] Oct 12, 2023
bb5fede
:seedling: Bump golang.org/x/net from 0.14.0 to 0.17.0 in /tools (#3562)
dependabot[bot] Oct 12, 2023
7cbc4b1
:seedling: Adding all Intel public GitHub repos (#3556)
Oct 12, 2023
3b63938
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.12.1 to 2.13.0 (#3551)
dependabot[bot] Oct 12, 2023
67431ba
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools (#3552)
dependabot[bot] Oct 12, 2023
e5955d0
:seedling: Bump github.com/google/go-cmp from 0.5.9 to 0.6.0 (#3557)
dependabot[bot] Oct 12, 2023
16ace55
:seedling: Bump kubernetes-sigs/kubebuilder-release-tools (#3553)
dependabot[bot] Oct 12, 2023
05a1ead
:bug: Fix wrong quotes (#3565)
AdamKorcz Oct 12, 2023
8eaf0d7
:seedling: Add new outcome to UnmarshalYAML (#3566)
AdamKorcz Oct 12, 2023
b9bbb82
:bug: scdiff: fix generate cmd when no --checks arg provided. (#3570)
spencerschrock Oct 16, 2023
63fff3c
:sparkles: scdiff: improve `compare` usability (#3573)
spencerschrock Oct 16, 2023
f26ee46
:sparkles: Add fast-check test runners integrations (#3568)
sheerlox Oct 19, 2023
836c040
:seedling: Bump github.com/bradleyfalzon/ghinstallation/v2 (#3575)
dependabot[bot] Oct 19, 2023
159c6c8
:seedling: Bump tj-actions/changed-files from 39.2.1 to 39.2.3 (#3577)
dependabot[bot] Oct 19, 2023
1c05571
:seedling: Bump github.com/google/ko from 0.14.1 to 0.15.0 in /tools …
dependabot[bot] Oct 19, 2023
4b8066a
:seedling: Bump actions/checkout from 4.1.0 to 4.1.1 (#3580)
dependabot[bot] Oct 19, 2023
49c0eed
:bug: SAST detect new GitHub app slug for CodeQL (#3591)
martincostello Oct 20, 2023
d0cefa5
:seedling: enable the golangci-lint `bugs` preset (#3583)
spencerschrock Oct 23, 2023
2d93196
:seedling: use forbidigo linter to prevent print statements (#3585)
spencerschrock Oct 23, 2023
ca5c404
:bug: scanning gitlab private repositories (#3596)
gabibguti Oct 23, 2023
8959d3f
:seedling: Bump github.com/xanzy/go-gitlab from 0.93.1 to 0.93.2 (#3593)
dependabot[bot] Oct 23, 2023
6fb5f8a
:seedling: Bump github.com/onsi/gomega from 1.28.0 to 1.28.1 (#3597)
dependabot[bot] Oct 23, 2023
2391edf
:seedling: add style linters: mirror, tenv, usestdlibvars (#3586)
spencerschrock Oct 23, 2023
1c649cb
:seedling: enable gomoddirectives linter. (#3584)
spencerschrock Oct 23, 2023
5eca374
:seedling: enable style linter `errname` (#3587)
spencerschrock Oct 23, 2023
25c414d
:seedling: remove unused osv helper tool. (#3572)
spencerschrock Oct 23, 2023
52f950b
:seedling: Bump github.com/golangci/golangci-lint in /tools (#3592)
dependabot[bot] Oct 24, 2023
622f104
:seedling: GitLab: track coverage for gitlab e2e tests (#3601)
raghavkaul Oct 24, 2023
0e3a523
:seedling: Add license probe (#3465)
AdamKorcz Oct 24, 2023
1aca1d9
🌱 convert packaging check to probe (#3486)
AdamKorcz Oct 24, 2023
ae75bbb
:seedling: Add probe support for contributors metrics (#3460)
AdamKorcz Oct 24, 2023
5f171ba
:seedling: Fix linter issues caught by new linters in golangci-lint v…
spencerschrock Oct 24, 2023
f2bbd0a
remove sonatype lift (#3605)
spencerschrock Oct 25, 2023
de022da
:seedling: convert vulnerabilities check to probe (#3487)
AdamKorcz Oct 25, 2023
fa0e1c1
:sparkles: Add WithValues function to findings (#3619)
laurentsimon Oct 27, 2023
b15b47a
CODEOWNERS: Support distribution of code reviews via team assignments…
justaugustus Oct 27, 2023
5f3a0e2
:seedling: Enable golangci-lint `test` presets (#3594)
spencerschrock Oct 27, 2023
a3495dd
:seedling: Bump google.golang.org/grpc from 1.57.0 to 1.57.1 (#3611)
dependabot[bot] Oct 27, 2023
a372034
:seedling: Bump google.golang.org/grpc from 1.58.2 to 1.58.3 in /tool…
dependabot[bot] Oct 27, 2023
50d2466
:seedling: Bump ossf/scorecard-action from 2.3.0 to 2.3.1 (#3599)
dependabot[bot] Oct 27, 2023
f72b774
:seedling: Bump github.com/google/osv-scanner from 1.4.1 to 1.4.2 (#3…
dependabot[bot] Oct 27, 2023
ab7d364
:seedling: Bump github.com/moby/buildkit from 0.12.2 to 0.12.3 (#3589)
dependabot[bot] Oct 28, 2023
478f347
:seedling: Bump github.com/golangci/golangci-lint in /tools (#3613)
dependabot[bot] Oct 28, 2023
c52a170
🌱 Update stale workflow to exempt Structured Results milestone (#3634)
afmarcum Nov 1, 2023
45c5c65
:seedling: Bump github.com/docker/docker (#3627)
dependabot[bot] Nov 1, 2023
faffac6
:seedling: Bump github.com/docker/docker in /tools (#3628)
dependabot[bot] Nov 1, 2023
dac01db
:seedling: Bump github.com/go-logr/logr from 1.2.4 to 1.3.0 (#3622)
dependabot[bot] Nov 1, 2023
1b2c4cf
:seedling: Bump github.com/go-git/go-git/v5 from 5.9.0 to 5.10.0 (#3623)
dependabot[bot] Nov 1, 2023
3cce5ad
:seedling: Bump github.com/onsi/gomega from 1.28.1 to 1.29.0 (#3624)
dependabot[bot] Nov 1, 2023
b0c782a
:seedling: Bump cloud.google.com/go/bigquery from 1.56.0 to 1.57.1 (#…
dependabot[bot] Nov 2, 2023
70c8e05
:bug: remove probe remediations from detail string (#3642)
spencerschrock Nov 3, 2023
d0610fe
:seedling: Bump github.com/spf13/cobra from 1.7.0 to 1.8.0 (#3644)
dependabot[bot] Nov 6, 2023
f422f69
:seedling: Convert Dangerous Workflow check to probes (#3521)
AdamKorcz Nov 6, 2023
47e04c1
:seedling: Convert SAST check to probes (#3571)
AdamKorcz Nov 7, 2023
fbffff1
:seedling: Bump github.com/google/osv-scanner from 1.4.2 to 1.4.3 (#3…
dependabot[bot] Nov 7, 2023
77fa8c8
:seedling: Bump golang.org/x/text from 0.13.0 to 0.14.0 (#3643)
dependabot[bot] Nov 8, 2023
e16d3e3
:seedling: Bump github.com/golangci/golangci-lint in /tools (#3645)
dependabot[bot] Nov 8, 2023
6d35c86
🐛 Pinned-Dependencies continues on error (#3515)
pnacht Nov 8, 2023
e12e537
:seedling: Bump actions/dependency-review-action from 3.1.0 to 3.1.2 …
dependabot[bot] Nov 8, 2023
6de7eba
:seedling: Bump kubernetes-sigs/kubebuilder-release-tools (#3637)
dependabot[bot] Nov 8, 2023
e123f4c
:seedling: Bump tj-actions/changed-files from 39.2.3 to 40.1.1 (#3657)
dependabot[bot] Nov 9, 2023
5bfe68d
:seedling: Bump sigstore/cosign-installer from 3.1.2 to 3.2.0 (#3651)
dependabot[bot] Nov 9, 2023
694d563
:seedling: Bump slsa-framework/slsa-verifier from 2.4.0 to 2.4.1 (#3652)
dependabot[bot] Nov 9, 2023
0fc8296
:seedling: Bump github.com/onsi/gomega from 1.29.0 to 1.30.0 (#3659)
dependabot[bot] Nov 9, 2023
2c959b7
:seedling: speedup slowest e2e tests (#3656)
spencerschrock Nov 9, 2023
b3d1a5a
:seedling: Add dependency remediation in raw results instead of at lo…
AdamKorcz Nov 9, 2023
934f170
:seedling: configure dependabot to group (most) GitHub actions weekly…
spencerschrock Nov 10, 2023
87c2d3c
:warning: Remove OneFuzz from fuzzing checks (#3666)
DavidKorczynski Nov 13, 2023
6dffe65
:seedling: Bump github.com/sigstore/cosign/v2 from 2.1.1 to 2.2.1 in …
dependabot[bot] Nov 13, 2023
a4ee314
:seedling: bump project minimum Go version to go1.21 (#3661)
spencerschrock Nov 13, 2023
14f864b
:sparkles: Add commit depth support for GitLab (#3672)
ashearin Nov 15, 2023
8ac1b43
:seedling: Bump github.com/xanzy/go-gitlab from 0.93.2 to 0.94.0 (#3674)
dependabot[bot] Nov 15, 2023
6541b0d
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools (#3668)
dependabot[bot] Nov 15, 2023
ea626de
:seedling: update CI-Tests e2e to reflect 30 commits (#3676)
spencerschrock Nov 15, 2023
288319a
:seedling: scdiff: Add workflow to run `scdiff` against PRs on demand…
spencerschrock Nov 15, 2023
92470de
:seedling: enable `nolintlint` linter and fix violations (#3650)
spencerschrock Nov 15, 2023
be0b915
:bug: Ignore unpinned dependencies in Dockerfiles in vendored directo…
AdamKorcz Nov 16, 2023
1c3d9eb
:seedling: Migrate Maintained check to probes (#3507)
AdamKorcz Nov 17, 2023
82692a8
:seedling: allow contributors to call scdiff workflow (#3683)
spencerschrock Nov 17, 2023
0f0808a
:seedling: Bump github.com/google/ko from 0.15.0 to 0.15.1 in /tools …
dependabot[bot] Nov 18, 2023
a0dfec2
:seedling: Bump golang.org/x/oauth2 from 0.13.0 to 0.14.0 (#3658)
dependabot[bot] Nov 18, 2023
0276a7c
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.13.0 to 2.13.1 (#3669)
dependabot[bot] Nov 18, 2023
76878e5
:seedling: Bump the github-actions group with 2 updates (#3686)
dependabot[bot] Nov 20, 2023
1a17bb8
:bug: add retry loop to graphQL commit queries which timeout on large…
spencerschrock Nov 20, 2023
f8198b0
:seedling: refactor pinned dependencies (#3667)
AdamKorcz Nov 27, 2023
84bd607
:seedling: fix script injection (#3695)
spencerschrock Nov 27, 2023
04ea8be
:seedling: Bump github.com/go-git/go-git/v5 from 5.10.0 to 5.10.1 (#3…
dependabot[bot] Nov 28, 2023
6857320
:seedling: make maintained values keys constants (#3700)
AdamKorcz Nov 28, 2023
9b5d762
:seedling: convert CII Best Practices check to probes (#3520)
AdamKorcz Nov 28, 2023
fea2f45
:seedling: Bump golang.org/x/oauth2 from 0.14.0 to 0.15.0 (#3697)
dependabot[bot] Nov 28, 2023
3cbafa9
:book: fix typo (#3699)
AdamKorcz Nov 28, 2023
0e7e58a
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.13.1 to 2.13.2 (#3704)
dependabot[bot] Nov 29, 2023
ce0b54e
📖 Add beginner's guide to scorecard checks docs (#3617)
ariathaker Nov 29, 2023
0c40e14
:bug: Trust pinned GitHub download URLs (#3694)
martincostello Nov 30, 2023
4d1621b
:seedling: Bump github.com/google/go-containerregistry (#3708)
dependabot[bot] Nov 30, 2023
1625b0c
:seedling: Disable more style linters for test files (#3707)
spencerschrock Dec 4, 2023
d882fc7
:seedling: re-enable paralleltest linter (#3705)
spencerschrock Dec 4, 2023
e4fc815
🐛 Parse Gitlab Status fields to align w/Github Status and Conclusion …
ashearin Dec 4, 2023
7656dc7
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools (#3703)
dependabot[bot] Dec 4, 2023
483cc31
:seedling: Bump github.com/moby/buildkit from 0.12.3 to 0.12.4 (#3710)
dependabot[bot] Dec 4, 2023
cb721a8
:seedling: convert binary artifact check to probe (#3508)
AdamKorcz Dec 5, 2023
c089856
remove ununsed directives (#3713)
spencerschrock Dec 5, 2023
ec36916
:seedling: convert Webhook check to probes (#3522)
AdamKorcz Dec 5, 2023
320ce05
:seedling: Bump the github-actions group with 3 updates (#3715)
dependabot[bot] Dec 5, 2023
6ea9c8d
:seedling: Pinned dependencies: create findings from processing error…
AdamKorcz Dec 6, 2023
5dc03b7
:seedling: Bump github.com/google/osv-scanner from 1.4.3 to 1.5.0 (#3…
dependabot[bot] Dec 6, 2023
30ef6b1
:seedling: convert CI-Tests check to probes (#3621)
AdamKorcz Dec 11, 2023
db7b6e7
:sparkles: branch protection: requiring PRs gives partial credit (#3499)
diogoteles08 Dec 12, 2023
3ce1daa
:seedling: Add probes to main call (#3688)
AdamKorcz Dec 12, 2023
663e1a9
🌱 Use backlog and "help wanted" labels on issues/PRs to keep stale-bo…
pnacht Dec 12, 2023
d03c8cb
:bug: revert making RequiredPullRequestReviews a pointer (#3728)
spencerschrock Dec 13, 2023
2c20be0
convert Signed Releases to probes (#3610)
AdamKorcz Dec 13, 2023
39d1b33
:seedling: Bump the github-actions group with 2 updates (#3725)
dependabot[bot] Dec 13, 2023
eefb6bf
:seedling: fix rangeValCopy linter issues (#3735)
spencerschrock Dec 13, 2023
d5900ed
:seedling: Bump github.com/go-git/go-git/v5 from 5.10.1 to 5.11.0 (#3…
dependabot[bot] Dec 14, 2023
f4bf574
:book: fixup transposition typos in remediation package (#3734)
daveworth Dec 18, 2023
df7d888
🌱 differentiate between refs and sha gitab (#3729)
ashearin Dec 18, 2023
21bbe80
:seedling: Bump golang.org/x/crypto from 0.16.0 to 0.17.0 (#3742)
dependabot[bot] Dec 19, 2023
2ef20f1
🌱 SAST: add Snyk probe (#3689)
DavidKorczynski Dec 19, 2023
4fafac9
:seedling: Bump golang.org/x/crypto from 0.15.0 to 0.17.0 in /tools (…
dependabot[bot] Dec 27, 2023
12e4ff1
:seedling: Bump gocloud.dev from 0.34.0 to 0.35.0
dependabot[bot] Dec 27, 2023
c1a0557
:seedling: Bump github.com/xanzy/go-gitlab from 0.94.0 to 0.95.2
dependabot[bot] Dec 27, 2023
2e1059b
:seedling: Add probes for Branch Protection (#3691)
AdamKorcz Dec 27, 2023
6a226ce
:seedling: Bump actions/setup-go from 4.1.0 to 5.0.0 (#3726)
dependabot[bot] Dec 28, 2023
2bad4e9
:bug: Fix nils (#3750)
naveensrinivasan Dec 28, 2023
0e8dad8
:seedling: Bump google.golang.org/protobuf from 1.31.0 to 1.32.0
dependabot[bot] Dec 28, 2023
5d8767e
:seedling: Update Go version to 1.21 for tools (#3754)
naveensrinivasan Dec 28, 2023
90792d9
:seedling: Bump github.com/go-git/go-git/v5 in /tools (#3749)
dependabot[bot] Dec 28, 2023
3c93389
:seedling: Bump github.com/jszwec/csvutil from 1.8.0 to 1.9.0 (#3722)
dependabot[bot] Dec 28, 2023
c90e0bb
:seedling: Bump the github-actions group with 4 updates (#3747)
dependabot[bot] Dec 28, 2023
9b5de80
:seedling: Bump github.com/go-logr/logr from 1.3.0 to 1.4.1 (#3758)
dependabot[bot] Dec 29, 2023
69bb742
:bug: Dependency-Update-Tool: ignore search commit data for repo clie…
spencerschrock Dec 29, 2023
9986f70
:bug: Update token permissions check and scoring (#3755)
naveensrinivasan Dec 30, 2023
a34f0bf
:seedling: Bump github.com/goreleaser/goreleaser in /tools
dependabot[bot] Dec 30, 2023
1177c3c
:bug: Fix signed release error for empty gitlab repo (#3753)
naveensrinivasan Dec 30, 2023
04340ee
:seedling: Bump gocloud.dev from 0.35.0 to 0.36.0 (#3751)
dependabot[bot] Jan 1, 2024
6c2a266
:seedling: Bump google.golang.org/protobuf in /tools
dependabot[bot] Jan 1, 2024
99c455b
🌱 SAST: dedupe and add Pysa and Qodana probe (#3743)
DavidKorczynski Jan 2, 2024
da6d7ec
:book: Update README with zoom meeting info (#3739)
leec94 Jan 2, 2024
2bad6e7
:book: document scdiff in the release process (#3730)
spencerschrock Jan 3, 2024
658a77b
:bug: ensure Signed-Releases only scores 5 releases (#3768)
spencerschrock Jan 3, 2024
141ac4d
:bug: handle gitlab repos with no commits (#3731)
ashearin Jan 4, 2024
55b6b76
:seedling: Use const keys for SAST and Pinned-Dependencies probe Valu…
spencerschrock Jan 4, 2024
0e8e57d
Support `.sigstore` bundles to check for signed releases (#3772)
edgarrmondragon Jan 5, 2024
b1d3121
:seedling: cron: add two additional replicas (#3721)
spencerschrock Jan 5, 2024
7a4c1bd
:bug: Fix OSV URI in probe remediation text (#3770)
spencerschrock Jan 5, 2024
a4148d9
:seedling: Included additional method to git client (#3761)
naveensrinivasan Jan 7, 2024
6f31d2d
:seedling: Bump the github-actions group with 1 update (#3775)
dependabot[bot] Jan 8, 2024
9468390
:seedling: Bump github.com/bradleyfalzon/ghinstallation/v2 (#3776)
dependabot[bot] Jan 8, 2024
b3fcc0e
:seedling: Bump github.com/cloudflare/circl from 1.3.3 to 1.3.7 (#3778)
dependabot[bot] Jan 8, 2024
62457a7
:seedling: Bump github.com/cloudflare/circl in /tools
dependabot[bot] Jan 8, 2024
fdf3fb2
:seedling: Added URL from GitHub Actions marketplace (#3732)
manishtiwari25 Jan 8, 2024
45425b6
:seedling: Add some more projects to be scanned in the cron (#3764)
katzj Jan 9, 2024
f41f8f4
:seedling: refactor permissions (#3693)
AdamKorcz Jan 9, 2024
1917fc8
:seedling: Bump golang.org/x/oauth2 from 0.15.0 to 0.16.0 (#3781)
dependabot[bot] Jan 10, 2024
c59e93b
:seedling: Switch probe tests to helper func (#3782)
spencerschrock Jan 10, 2024
6c345f1
:book: Clarify lack of 2FA check in README.md (#3784)
raghavkaul Jan 10, 2024
e15264d
:bug: Refactor Dockerfile validation code to handle here-documents (#…
jkreileder Jan 10, 2024
8c21a49
:seedling: use a single source of truth for fuzzer names (#3786)
spencerschrock Jan 11, 2024
c48cd15
:seedling: add the rest of Metal3 repos to the project list (#3783)
tuminoid Jan 11, 2024
b3b40d0
:seedling: Fix struct size govet issues (#3787)
naveensrinivasan Jan 11, 2024
a3321e2
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.13.2 to 2.14.0 (#3789)
dependabot[bot] Jan 13, 2024
497b851
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools
dependabot[bot] Jan 13, 2024
8ac9ca1
:seedling: Bump the github-actions group with 4 updates (#3794)
dependabot[bot] Jan 15, 2024
21edf40
:seedling: Change the chan to write only (#3793)
naveensrinivasan Jan 16, 2024
4a2dfa9
:seedling: Bump github.com/google/osv-scanner from 1.5.0 to 1.6.0 (#3…
dependabot[bot] Jan 17, 2024
f1d7a62
:seedling: Fixed field alignment (#3799)
naveensrinivasan Jan 17, 2024
8a78cb7
:seedling: Bump github.com/onsi/ginkgo/v2 from 2.14.0 to 2.15.0 (#3807)
dependabot[bot] Jan 18, 2024
51f1732
:seedling: Bump cloud.google.com/go/bigquery from 1.57.1 to 1.58.0 (#…
dependabot[bot] Jan 19, 2024
b556d93
:bug: Handle osvscanner errors on projects with no dependencies (#3803)
spencerschrock Jan 19, 2024
0dcad3a
:sparkles: enforce check scores are between the min and max (#3769)
spencerschrock Jan 19, 2024
ee4e83a
:seedling: Enforce `make add-projects` for GitHub and GitLab repos (#…
spencerschrock Jan 19, 2024
efc5180
:seedling: Bump github.com/onsi/ginkgo/v2 in /tools (#3805)
dependabot[bot] Jan 19, 2024
da216ed
:seedling: Bump github.com/google/osv-scanner from 1.6.0 to 1.6.1 (#3…
dependabot[bot] Jan 20, 2024
e41a3fe
:seedling: Bump the github-actions group with 4 updates (#3815)
dependabot[bot] Jan 22, 2024
1a1d9b1
:book: Add documentation about probes and contributing (#3762)
AdamKorcz Jan 23, 2024
ba69f13
:seedling: Bump cloud.google.com/go/pubsub from 1.33.0 to 1.34.0 (#3813)
dependabot[bot] Jan 24, 2024
ce0905a
:seedling: Bump github.com/onsi/gomega from 1.30.0 to 1.31.1 (#3818)
dependabot[bot] Jan 24, 2024
a021b23
:seedling: Bump github.com/google/go-containerregistry (#3808)
dependabot[bot] Jan 24, 2024
e61e7e6
:seedling: Bump github.com/xanzy/go-gitlab from 0.95.2 to 0.96.0 (#3814)
dependabot[bot] Jan 25, 2024
1fad598
:seedling: Bump cloud.google.com/go/pubsub from 1.34.0 to 1.35.0 (#3820)
dependabot[bot] Jan 26, 2024
9440b76
✨ New probes: code-review (#3302)
andrelmbackman Jan 26, 2024
da3e5ad
:seedling: Add active cisco-open projects to cronjob (#3822)
lelia Jan 26, 2024
3b94825
📖 Fix spelling (#3804)
jsoref Jan 26, 2024
301208c
:sparkles: dependency-update-tool: detect GitLab Renovate config file…
spencerschrock Jan 29, 2024
a25f108
:seedling: Bump the github-actions group with 3 updates (#3825)
dependabot[bot] Jan 29, 2024
19047e8
:seedling: Bump github.com/google/go-containerregistry (#3828)
dependabot[bot] Jan 30, 2024
83ff808
:seedling: Enhance test output and management in ValidateTestReturn (…
spencerschrock Jan 30, 2024
e10dbb1
:bug: Support self-hosted GitLab instances where base URL has a path …
spencerschrock Jan 31, 2024
6f816c8
:seedling: Bump github.com/google/osv-scanner from 1.6.1 to 1.6.2 (#3…
dependabot[bot] Jan 31, 2024
db86b8b
:seedling: Bump github.com/moby/buildkit from 0.12.4 to 0.12.5 (#3836)
dependabot[bot] Feb 1, 2024
df5e563
Merge remote-tracking branch 'upstream/main' into upgradeScorecardVer…
cx-monicac Feb 1, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 4 additions & 5 deletions .codecov.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,16 +23,15 @@ coverage:
status:
project:
default:
enabled: true
# allowed to drop coverage and still result in a "success" commit status
threshold: null
informational: true
if_not_found: success
if_no_uploads: success
if_ci_failed: error
patch:
default:
enabled: true
threshold: 90%
# patch coverage should be within 10% of existing coverage
target: auto
threshold: 10%
if_not_found: success
if_no_uploads: success
if_ci_failed: error
Expand Down
10 changes: 3 additions & 7 deletions .github/CODEOWNERS
Validating CODEOWNERS rules …
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,8 @@
# the repo. Unless a later match takes precedence,
# the following users/teams will be requested for
# review when someone opens a pull request.
# TODO(owners): For ease of management, this should eventually shift to a
# defined GitHub team instead of individual usernames
* @azeemshaikh38 @justaugustus @laurentsimon @naveensrinivasan @spencerschrock @raghavkaul
* @ossf/scorecard-maintainers

# Docs
# TODO(owners): For ease of management, this should eventually shift to a
# defined GitHub team instead of individual usernames
*.md @olivekl
/docs/ @olivekl
*.md @ossf/scorecard-doc-maintainers
/docs/ @ossf/scorecard-doc-maintainers
18 changes: 17 additions & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,19 @@ updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
interval: "weekly"
rebase-strategy: disabled
commit-message:
prefix: ":seedling:"
groups:
github-actions:
patterns:
- "*"
# These actions directly influence the build process and are excluded from grouped updates
exclude-patterns:
- "actions/setup-go"
- "arduino/setup-protoc"
- "goreleaser/goreleaser-action"
- package-ecosystem: docker
directory: "/"
schedule:
Expand Down Expand Up @@ -74,3 +83,10 @@ updates:
rebase-strategy: disabled
commit-message:
prefix: ":seedling:"
- package-ecosystem: docker
directory: "/attestor"
schedule:
interval: weekly
rebase-strategy: disabled
commit-message:
prefix: ":seedling:"
16 changes: 14 additions & 2 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,9 @@ on:
permissions:
contents: read

env:
GO_VERSION: 1.21

jobs:
analyze:
permissions:
Expand All @@ -52,12 +55,21 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v1
uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 # v1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Checkout repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v2.3.4
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1

# don't use the default version of Go from GitHub runners
# https://github.com/github/codeql-action/issues/1842#issuecomment-1704398087
- name: Setup Go
uses: actions/setup-go@0c52d547c9bc32b1aa3301fd7a9cb496313a4491 # v5.0.0
with:
go-version: ${{ env.GO_VERSION }}
check-latest: true
cache: false # CodeQL needs to build everything itself to do its analysis

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/depsreview.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: 'Checkout Repository'
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: 'Dependency Review'
uses: actions/dependency-review-action@1360a344ccb0ab6e9475edef90ad2f46bf8003b1
uses: actions/dependency-review-action@4901385134134e04cec5fbe5ddfe3b2c5bd5d976 # v4.0.0
233 changes: 30 additions & 203 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,7 @@ on:
- main

env:
PROTOC_VERSION: 3.17.3
GO_VERSION_FILE: go.mod # no good way of getting a mutual version between go.mod and tools/go.mod
CACHE_DEPENDENCY_PATH: "**/go.sum" # include both go.sum and tools/go.sum
GO_VERSION: 1.21

jobs:
docs_only_check:
Expand All @@ -37,225 +35,54 @@ jobs:
docs_only: ${{ steps.docs_only_check.outputs.docs_only }}
steps:
- name: Check out code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 #v3.5.3
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 #v4.1.1
with:
fetch-depth: 2 # needed to diff changed files
- id: files
name: Get changed files
uses: tj-actions/changed-files@ec1e14cf27f4585783f463070881b2c499349a8a #v37.0.3
uses: tj-actions/changed-files@90a06d6ba9543371ab4df8eeca0be07ca6054959 #v42.0.2
with:
files_ignore: '**.md'
- id: docs_only_check
if: steps.files.outputs.any_changed != 'true'
name: Check for docs-only changes
run: echo "docs_only=true" >> $GITHUB_OUTPUT

scorecard:
name: scorecard-docker
docker_matrix:
strategy:
matrix:
target:
- 'scorecard-docker'
- 'cron-controller-docker'
- 'cron-worker-docker'
- 'cron-cii-worker-docker'
- 'cron-bq-transfer-docker'
- 'cron-webhook-docker'
- 'cron-github-server-docker'
- 'build-attestor-docker'
name: ${{ matrix.target }}
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
needs: docs_only_check
# ideally we put one "if" here, but due to how skipped matrix jobs work, we need one for each step
# https://github.com/orgs/community/discussions/9141
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
if: (needs.docs_only_check.outputs.docs_only != 'true')
uses: step-security/harden-runner@eb238b55efaa70779f274895e782ed17c84f2895 # v2.6.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make scorecard-docker
cron-controller:
name: cron-controller-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make cron-controller-docker
cron-worker:
name: cron-worker-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make cron-worker-docker
cron-cii-worker:
name: cron-cii--worker-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make cron-cii-worker-docker
cron-bq-transfer:
name: cron-bq-transfer-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make cron-bq-transfer-docker
cron-webhook:
name: cron-webhook-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
check-latest: true
cache: true
cache-dependency-path: ${{ env.CACHE_DEPENDENCY_PATH }}
- name: docker build
run: make cron-webhook-docker
cron-github-server:
name: cron-github-server-docker
runs-on: ubuntu-latest
permissions:
contents: read
needs:
- docs_only_check
if: (needs.docs_only_check.outputs.docs_only != 'true')
steps:
- name: Harden Runner
uses: step-security/harden-runner@55d479fb1c5bcad5a4f9099a5d9f37c8857b2845 # v2.4.1
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs

- name: Install Protoc
uses: arduino/setup-protoc@149f6c87b92550901b26acd1632e11c3662e381f # v1.3.0
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Clone the code
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
- name: Setup Go
uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
if: (needs.docs_only_check.outputs.docs_only != 'true')
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Setup Go # needed for some of the Makefile evaluations, even if building happens in Docker
if: (needs.docs_only_check.outputs.docs_only != 'true')
uses: actions/setup-go@0c52d547c9bc32b1aa3301fd7a9cb496313a4491 # v5.0.0
with:
go-version-file: ${{ env.GO_VERSION_FILE }}
go-version: ${{ env.GO_VERSION }}
check-latest: true
cache: true
cache: false # the building happens in Docker, so saving this cache would negatively impact other builds
- name: docker build
run: make cron-github-server-docker
if: (needs.docs_only_check.outputs.docs_only != 'true')
run: make ${{ matrix.target }}
Loading
Loading