Skip to content

Releases: ossf/pvtr-github-repo-scanner

v0.23.2

30 Apr 20:21
c7bd953

Choose a tag to compare

Changelog

🧰 Maintenance

See details of all code changes since previous release

v0.23.1

14 Apr 12:41
c8c42f0

Choose a tag to compare

Changelog

🧰 Maintenance

See details of all code changes since previous release

v0.23.0

07 Apr 20:38
3189150

Choose a tag to compare

Changelog

🚀 Features

  • feat: implement OSPS-QA-05.02 detect unreviewable binary artifacts @vinayada1 (#279)

See details of all code changes since previous release

v0.22.2

07 Apr 19:48
16e5ada

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: stop leaking GITHUB_TOKEN in CI script tracing @vinayada1 (#282)
  • fix: pin GitHub Actions to commit SHAs to prevent supply-chain attacks @vinayada1 (#281)

🧰 Maintenance

See details of all code changes since previous release

v0.22.1

31 Mar 14:07
ee48af8

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: add retry with exponential backoff for transient API failures @jmeridth (#277)

🧰 Maintenance

See details of all code changes since previous release

v0.22.0

27 Mar 02:01
e823cb5

Choose a tag to compare

Changelog

🚀 Features

  • feat: implement OSPS-BR-01.02 branch name sanitization check @vinayada1 (#275)

See details of all code changes since previous release

v0.21.0

27 Mar 01:58
fdb55ff

Choose a tag to compare

Changelog

🚀 Features

🧰 Maintenance

  • chore(deps): bump github.com/privateerproj/privateer-sdk from 1.21.0 to 1.22.0 in the dependencies group @dependabot[bot] (#274)
  • chore(deps): bump the dependencies group with 6 updates @dependabot[bot] (#272)

See details of all code changes since previous release

v0.20.0

20 Mar 02:17
21674ce

Choose a tag to compare

Changelog

  • chore: Update ospo-reusable-workflows to new GitHub org @jmeridth (#258)

🚀 Features

🧰 Maintenance

See details of all code changes since previous release

v0.19.2

04 Mar 18:02
268f1a5

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: use file mode to distinguish executable binaries from non-executable ones @jmeridth (#256)

🧰 Maintenance

  • chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 @dependabot[bot] (#253)
  • chore(deps): bump actions/attest-sbom from 3.0.0 to 4.0.0 @dependabot[bot] (#252)
  • chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 @dependabot[bot] (#251)
  • chore(deps): bump actions/attest-build-provenance from 3 to 4 @dependabot[bot] (#250)
  • chore(deps): bump anchore/sbom-action from 0.22.2 to 0.23.0 in the dependencies group @dependabot[bot] (#249)
  • chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 @dependabot[bot] (#248)
  • chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 @dependabot[bot] (#247)
  • chore(deps): bump github.com/privateerproj/privateer-sdk from 1.18.0 to 1.19.0 in the dependencies group @dependabot[bot] (#246)

See details of all code changes since previous release

v0.19.1

24 Feb 05:00
9b53a1d

Choose a tag to compare

Changelog

🐛 Bug Fixes

  • fix: treat empty and whitespace-only URIs as not insecure (OSPS-BR-03.01) @jmeridth (#245)

See details of all code changes since previous release