Skip to content

Commit 049eb0c

Browse files
🌱 Bump github.com/ossf/scorecard/v4 from 4.2.0 to 4.3.0 (#313)
* 🌱 Bump github.com/ossf/scorecard/v4 from 4.2.0 to 4.3.0 Bumps [github.com/ossf/scorecard/v4](https://github.com/ossf/scorecard) from 4.2.0 to 4.3.0. - [Release notes](https://github.com/ossf/scorecard/releases) - [Changelog](https://github.com/ossf/scorecard/blob/main/.goreleaser.yml) - [Commits](ossf/scorecard@v4.2.0...v4.3.0) --- updated-dependencies: - dependency-name: github.com/ossf/scorecard/v4 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> * options: Restore logic for publishing results Signed-off-by: Stephen Augustus <foo@auggie.dev> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Stephen Augustus <foo@auggie.dev>
1 parent 5c8bc69 commit 049eb0c

File tree

5 files changed

+230
-48
lines changed

5 files changed

+230
-48
lines changed

entrypoint/entrypoint.go

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,13 @@ func New() (*cobra.Command, error) {
4949
"path to output results to",
5050
)
5151

52+
actionCmd.Flags().BoolVar(
53+
&opts.PublishResults,
54+
"publish",
55+
opts.PublishResults,
56+
"if set, results will be published (for public repositories only)",
57+
)
58+
5259
// Adapt scorecard's PreRunE to support an output file
5360
// TODO(scorecard): Move this into scorecard
5461
var out, stdout *os.File

go.mod

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ require (
66
github.com/caarlos0/env/v6 v6.9.2
77
github.com/google/go-cmp v0.5.8
88
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79
9-
github.com/ossf/scorecard/v4 v4.2.0
9+
github.com/ossf/scorecard/v4 v4.3.0
1010
github.com/sigstore/cosign v1.8.0
1111
github.com/sirupsen/logrus v1.8.1
1212
github.com/spf13/cobra v1.4.0
@@ -64,7 +64,7 @@ require (
6464
github.com/cncf/udpa/go v0.0.0-20210930031921-04548b0d99d4 // indirect
6565
github.com/cncf/xds/go v0.0.0-20211130200136-a8f946100490 // indirect
6666
github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
67-
github.com/containerd/stargz-snapshotter/estargz v0.10.1 // indirect
67+
github.com/containerd/stargz-snapshotter/estargz v0.11.3 // indirect
6868
github.com/containerd/typeurl v1.0.2 // indirect
6969
github.com/coreos/go-oidc/v3 v3.1.0 // indirect
7070
github.com/coreos/go-semver v0.3.0 // indirect
@@ -73,7 +73,7 @@ require (
7373
github.com/cyberphone/json-canonicalization v0.0.0-20210823021906-dc406ceaf94b // indirect
7474
github.com/davecgh/go-spew v1.1.1 // indirect
7575
github.com/dimchansky/utfbom v1.1.1 // indirect
76-
github.com/docker/cli v20.10.12+incompatible // indirect
76+
github.com/docker/cli v20.10.13+incompatible // indirect
7777
github.com/docker/distribution v2.8.0+incompatible // indirect
7878
github.com/docker/docker v20.10.12+incompatible // indirect
7979
github.com/docker/docker-credential-helpers v0.6.4 // indirect
@@ -91,6 +91,7 @@ require (
9191
github.com/go-git/go-billy/v5 v5.3.1 // indirect
9292
github.com/go-git/go-git/v5 v5.4.2 // indirect
9393
github.com/go-logr/logr v1.2.3 // indirect
94+
github.com/go-logr/stdr v1.2.2 // indirect
9495
github.com/go-openapi/analysis v0.21.2 // indirect
9596
github.com/go-openapi/errors v0.20.2 // indirect
9697
github.com/go-openapi/jsonpointer v0.19.5 // indirect
@@ -158,7 +159,7 @@ require (
158159
github.com/miekg/pkcs11 v1.1.1 // indirect
159160
github.com/mitchellh/go-homedir v1.1.0 // indirect
160161
github.com/mitchellh/mapstructure v1.5.0 // indirect
161-
github.com/moby/buildkit v0.8.3 // indirect
162+
github.com/moby/buildkit v0.10.3 // indirect
162163
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
163164
github.com/modern-go/reflect2 v1.0.2 // indirect
164165
github.com/oklog/ulid v1.3.1 // indirect
@@ -177,7 +178,6 @@ require (
177178
github.com/rhysd/actionlint v1.6.12 // indirect
178179
github.com/rivo/uniseg v0.2.0 // indirect
179180
github.com/robfig/cron v1.2.0 // indirect
180-
github.com/rogpeppe/go-internal v1.8.1 // indirect
181181
github.com/russross/blackfriday/v2 v2.1.0 // indirect
182182
github.com/sassoftware/relic v0.0.0-20210427151427-dfb082b79b74 // indirect
183183
github.com/secure-systems-lab/go-securesystemslib v0.3.1 // indirect
@@ -223,15 +223,15 @@ require (
223223
go.etcd.io/etcd/v3 v3.5.0 // indirect
224224
go.mongodb.org/mongo-driver v1.8.3 // indirect
225225
go.opencensus.io v0.23.0 // indirect
226-
go.opentelemetry.io/contrib v1.3.0 // indirect
227-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.20.0 // indirect
228-
go.opentelemetry.io/otel v0.20.0 // indirect
226+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.29.0 // indirect
227+
go.opentelemetry.io/otel v1.4.1 // indirect
229228
go.opentelemetry.io/otel/exporters/otlp v0.20.0 // indirect
230-
go.opentelemetry.io/otel/metric v0.20.0 // indirect
231-
go.opentelemetry.io/otel/sdk v0.20.0 // indirect
229+
go.opentelemetry.io/otel/internal/metric v0.27.0 // indirect
230+
go.opentelemetry.io/otel/metric v0.27.0 // indirect
231+
go.opentelemetry.io/otel/sdk v1.4.1 // indirect
232232
go.opentelemetry.io/otel/sdk/export/metric v0.20.0 // indirect
233233
go.opentelemetry.io/otel/sdk/metric v0.20.0 // indirect
234-
go.opentelemetry.io/otel/trace v0.20.0 // indirect
234+
go.opentelemetry.io/otel/trace v1.4.1 // indirect
235235
go.opentelemetry.io/proto/otlp v0.12.0 // indirect
236236
go.uber.org/atomic v1.9.0 // indirect
237237
go.uber.org/multierr v1.8.0 // indirect
@@ -247,9 +247,9 @@ require (
247247
golang.org/x/time v0.0.0-20220224211638-0e9765cccd65 // indirect
248248
golang.org/x/tools v0.1.10 // indirect
249249
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
250-
google.golang.org/api v0.75.0 // indirect
250+
google.golang.org/api v0.76.0 // indirect
251251
google.golang.org/appengine v1.6.7 // indirect
252-
google.golang.org/genproto v0.0.0-20220414192740-2d67ff6cf2b4 // indirect
252+
google.golang.org/genproto v0.0.0-20220426171045-31bebdecfb46 // indirect
253253
google.golang.org/grpc v1.46.0 // indirect
254254
google.golang.org/protobuf v1.28.0 // indirect
255255
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
@@ -268,7 +268,7 @@ require (
268268
k8s.io/kube-openapi v0.0.0-20220124234850-424119656bbf // indirect
269269
k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9 // indirect
270270
knative.dev/pkg v0.0.0-20220325200448-1f7514acd0c2 // indirect
271-
mvdan.cc/sh/v3 v3.4.3 // indirect
271+
mvdan.cc/sh/v3 v3.5.0 // indirect
272272
sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 // indirect
273273
sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
274274
sigs.k8s.io/yaml v1.3.0 // indirect

0 commit comments

Comments
 (0)