github ossf/scorecard v5.2.0

latest release: v5.2.1
3 months ago

What's Changed

General

  • ✨ Scorecard can now generate its output as an in-toto statement by specifying --format=intoto (#4491, @puerco)
  • ✨ Improved the performance of --file-mode git (#4563, @spencerschrock)
  • 🐛 Ensure artifactLocation in sarif output are escaped by @xhochy in #4619
  • ✨ Scorecard now supports configuration files ending in either .yml or .yaml (#4568, @ratancs)
  • 🌱 Go 1.23.0 is now required to build Scorecard or use it as a library. (#4547, @spencerschrock)

Checks

CI-Tests

Contributors

  • ✨ Users listed in CODEOWNERS file in GitHub repos now contribute to Contributors check (#4611, @lharrison13)

SAST

  • 🐛 SAST: Fixed an issue with Sonar Cloud not being detected due to a renamed GitHub app. (#4541, @spencerschrock)

Probes

  • ✨ Added independent probe that checks for ecosystem specific non-memory safety practices in the codebase and flags them. (#4499, @balteravishay)

Documentation

New Contributors

Don't miss a new scorecard release

NewReleases is sending notifications on new releases.