Skip to content

Releases: ossf/pvtr-github-repo-scanner

v0.24.0

30 May 03:16
04dda37

Choose a tag to compare

Changelog

🚀 Features

🐛 Bug Fixes

  • fix: grant discussions:write and add Breaking Changes drafter category @jmeridth (#322)
  • fix: backwards compatible catalog for 'osps-baseline' id @eddie-knight (#307)

🧰 Maintenance

  • chore(deps): bump privateer from 0.21.0 to 0.21.2 @github-actions[bot] (#328)
  • chore(deps): bump golang from 1.26.2-alpine3.22 to 1.26.3-alpine3.22 @dependabot[bot] (#314)
  • chore(deps): bump the dependencies group with 4 updates @dependabot[bot] (#329)
  • chore(deps): bump github/codeql-action from 4.35.4 to 4.35.5 in the dependencies group @dependabot[bot] (#324)
  • chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 @dependabot[bot] (#323)
  • chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 in the dependencies group @dependabot[bot] (#309)
  • ci: align release workflow with ospo-reusable-workflows v1.0.1 @jmeridth (#317)
  • chore(deps): bump github-community-projects/ospo-reusable-workflows/.github/workflows/pr-title.yaml from 0.6.0 to 1.0.1 @dependabot[bot] (#310)
  • chore(deps): bump github-community-projects/ospo-reusable-workflows/.github/workflows/release.yaml from 0.6.0 to 1.0.1 @dependabot[bot] (#312)
  • chore(deps): bump github-community-projects/ospo-reusable-workflows/.github/workflows/auto-labeler.yaml from 0.6.0 to 1.0.1 @dependabot[bot] (#313)
  • chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 @dependabot[bot] (#306)
  • chore: added typed step to simplify payload verification @eddie-knight (#302)
  • chore(deps): bump privateer from 0.20.3 to 0.21.0 @github-actions[bot] (#303)
  • chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 in the dependencies group @dependabot[bot] (#304)

See details of all code changes since previous release

v0.23.2

30 Apr 20:21
c7bd953

Choose a tag to compare

Changelog

🧰 Maintenance

See details of all code changes since previous release

v0.23.1

14 Apr 12:41
c8c42f0

Choose a tag to compare

Changelog

🧰 Maintenance

See details of all code changes since previous release

v0.23.0

07 Apr 20:38
3189150

Choose a tag to compare

Changelog

🚀 Features

  • feat: implement OSPS-QA-05.02 detect unreviewable binary artifacts @vinayada1 (#279)

See details of all code changes since previous release

v0.22.2

07 Apr 19:48
16e5ada

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: stop leaking GITHUB_TOKEN in CI script tracing @vinayada1 (#282)
  • fix: pin GitHub Actions to commit SHAs to prevent supply-chain attacks @vinayada1 (#281)

🧰 Maintenance

See details of all code changes since previous release

v0.22.1

31 Mar 14:07
ee48af8

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: add retry with exponential backoff for transient API failures @jmeridth (#277)

🧰 Maintenance

See details of all code changes since previous release

v0.22.0

27 Mar 02:01
e823cb5

Choose a tag to compare

Changelog

🚀 Features

  • feat: implement OSPS-BR-01.02 branch name sanitization check @vinayada1 (#275)

See details of all code changes since previous release

v0.21.0

27 Mar 01:58
fdb55ff

Choose a tag to compare

Changelog

🚀 Features

🧰 Maintenance

  • chore(deps): bump github.com/privateerproj/privateer-sdk from 1.21.0 to 1.22.0 in the dependencies group @dependabot[bot] (#274)
  • chore(deps): bump the dependencies group with 6 updates @dependabot[bot] (#272)

See details of all code changes since previous release

v0.20.0

20 Mar 02:17
21674ce

Choose a tag to compare

Changelog

  • chore: Update ospo-reusable-workflows to new GitHub org @jmeridth (#258)

🚀 Features

🧰 Maintenance

See details of all code changes since previous release

v0.19.2

04 Mar 18:02
268f1a5

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: use file mode to distinguish executable binaries from non-executable ones @jmeridth (#256)

🧰 Maintenance

  • chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 @dependabot[bot] (#253)
  • chore(deps): bump actions/attest-sbom from 3.0.0 to 4.0.0 @dependabot[bot] (#252)
  • chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 @dependabot[bot] (#251)
  • chore(deps): bump actions/attest-build-provenance from 3 to 4 @dependabot[bot] (#250)
  • chore(deps): bump anchore/sbom-action from 0.22.2 to 0.23.0 in the dependencies group @dependabot[bot] (#249)
  • chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 @dependabot[bot] (#248)
  • chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 @dependabot[bot] (#247)
  • chore(deps): bump github.com/privateerproj/privateer-sdk from 1.18.0 to 1.19.0 in the dependencies group @dependabot[bot] (#246)

See details of all code changes since previous release