Skip to content

chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 - #33

Merged
kriptoburak merged 2 commits into
mainfrom
dependabot/github_actions/ossf/scorecard-action-2.4.4
Aug 11, 2026
Merged

chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4#33
kriptoburak merged 2 commits into
mainfrom
dependabot/github_actions/ossf/scorecard-action-2.4.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps ossf/scorecard-action from 2.4.3 to 2.4.4.

Release notes

Sourced from ossf/scorecard-action's releases.

v2.4.4

What's Changed

This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.

Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4

Commits
  • 2d11466 Bump action tag for v2.4.4 release (#1688)
  • 1bd3285 🌱 Bump the docker-images group across 1 directory with 2 updates (#1...
  • 913edce 🌱 Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#1671)
  • 0957b8f 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#1680)
  • f0061eb 🌱 Bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#1687)
  • 20ee732 🌱 Bump github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.4 (#1685)
  • 9f295ef 🌱 Bump the github-actions group with 6 updates (#1686)
  • 69bf556 🌱 Bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.0 (#1681)
  • 94e8b96 🌱 Bump github.com/sigstore/rekor from 1.5.0 to 1.5.2 (#1673)
  • c7a1b37 🌱 Bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6 (#1675)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Bump ossf/scorecard-action from v2.4.3 to v2.4.4

Updates the ossf/scorecard-action pin in scorecard.yml to commit 2d11466 (v2.4.4).

Macroscope summarized a6ab2af.


Summary by cubic

Upgrade CI to ossf/scorecard-action v2.4.4 for Scorecard scans, bringing Scorecard v5.5.0 and more resilient result uploads. The action now logs POST upload failures instead of failing the workflow.

Written for commit a6ab2af. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated the automated security scorecard workflow to use the latest pinned action version.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from kriptoburak as a code owner August 3, 2026 03:11
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Aug 3, 2026
@dependabot
dependabot Bot requested a review from furkanerday as a code owner August 3, 2026 03:11
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The Scorecard workflow updates its pinned ossf/scorecard-action dependency from v2.4.3 to v2.4.4.

Changes

Scorecard Action Update

Layer / File(s) Summary
Update Scorecard action pin
.github/workflows/scorecard.yml
The Scorecard analysis step now uses the v2.4.4 action commit.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: furkanerday, kriptoburak

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the dependency and the version change described in the pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/ossf/scorecard-action-2.4.4

Comment @coderabbitai help to get the list of available commands.

dependabot Bot and others added 2 commits August 11, 2026 17:35
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.3 to 2.4.4.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@4eaacf0...2d11466)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedtypescript-eslint@​8.66.01001007498100
Added@​types/​node@​26.1.21001008196100
Addedpublint@​0.3.231001008192100
Addedeslint@​10.8.09710010097100

View full report

@kriptoburak
kriptoburak merged commit 3eda594 into main Aug 11, 2026
12 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/ossf/scorecard-action-2.4.4 branch August 11, 2026 14:55
@stainless-app stainless-app Bot mentioned this pull request Aug 11, 2026
@stainless-app stainless-app Bot mentioned this pull request Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants