Skip to content
This repository has been archived by the owner on Jan 17, 2024. It is now read-only.

v2.1.3 GH actions security improvements and dependabot merges

Latest
Compare
Choose a tag to compare
@ewastempel ewastempel released this 25 Jan 18:10
· 147 commits to main since this release
93824bd

What's Changed

  • Add OSSF scorecards and pin github actions to specific versions as recommended in the github actions security hardening guidance by @davidkelliott in #28
  • Bump actions/upload-artifact from 3.1.0 to 3.1.1 by @dependabot in #29
  • Remove reliance on remote backend by @dms1981 in #30
  • Github actions security improvements by @davidkelliott in #32
  • Amending provider name to fix terratests by @julialawrence in #35
  • Bump github/codeql-action from 2.1.32 to 2.1.35 by @dependabot in #34
  • Bump actions/setup-go from 3.3.1 to 3.4.0 by @dependabot in #33
  • Bump github/codeql-action from 2.1.35 to 2.1.36 by @dependabot in #36
  • Bump actions/checkout from 3.1.0 to 3.2.0 by @dependabot in #38
  • Bump ministryofjustice/github-actions from 8 to 9 by @dependabot in #37
  • Bump actions/setup-go from 3.4.0 to 3.5.0 by @dependabot in #39
  • Bump github/codeql-action from 2.1.36 to 2.1.37 by @dependabot in #40
  • Bump ossf/scorecard-action from 2.0.6 to 2.1.0 by @dependabot in #41
  • Bump ossf/scorecard-action from 2.1.0 to 2.1.1 by @dependabot in #42
  • Bump ossf/scorecard-action from 2.1.1 to 2.1.2 by @dependabot in #43
  • Bump actions/upload-artifact from 3.1.1 to 3.1.2 by @dependabot in #45
  • Bump actions/checkout from 3.2.0 to 3.3.0 by @dependabot in #44
  • Bump ministryofjustice/github-actions from 9 to 10 by @dependabot in #46
  • Bump github/codeql-action from 2.1.37 to 2.1.38 by @dependabot in #47
  • Bump github/codeql-action from 2.1.38 to 2.1.39 by @dependabot in #48

Full Changelog: v.2.1.2...v2.1.3