From 3dc5e1fc9ef5d4f09f8d4472d9393917d2f153f8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 17 Jan 2022 06:21:16 -0600 Subject: [PATCH] Bump ossf/scorecard-action from 0fe1afdc40f536c78e3dc69147b91b3ecec2cc8a to 1.0.1 (#603) * Bump ossf/scorecard-action Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 0fe1afdc40f536c78e3dc69147b91b3ecec2cc8a to 1.0.1. This release includes the previously tagged commit. - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Commits](https://github.com/ossf/scorecard-action/compare/0fe1afdc40f536c78e3dc69147b91b3ecec2cc8a...e3e75cf2ffbf9364bbff86cdbdf52b23176fe492) --- updated-dependencies: - dependency-name: ossf/scorecard-action dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * add version comment Signed-off-by: Carlos Panato <ctadeu@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Carlos Panato <ctadeu@gmail.com> --- .github/workflows/scorecard_action.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard_action.yml b/.github/workflows/scorecard_action.yml index 9ff5cf0..94344cd 100644 --- a/.github/workflows/scorecard_action.yml +++ b/.github/workflows/scorecard_action.yml @@ -28,7 +28,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@0fe1afdc40f536c78e3dc69147b91b3ecec2cc8a + uses: ossf/scorecard-action@e3e75cf2ffbf9364bbff86cdbdf52b23176fe492 # v1.0.1 with: results_file: results.sarif results_format: sarif -- GitLab