Skip to content

v5.2.0

Compare
Choose a tag to compare
@spencerschrock spencerschrock released this 27 May 21:46
· 30 commits to main since this release
v5.2.0
f08e8fb

What's Changed

General

  • ✨ Scorecard can now generate its output as an in-toto statement by specifying --format=intoto (#4491, @puerco)
  • ✨ Improved the performance of --file-mode git (#4563, @spencerschrock)
  • 🐛 Ensure artifactLocation in sarif output are escaped by @xhochy in #4619
  • ✨ Scorecard now supports configuration files ending in either .yml or .yaml (#4568, @ratancs)
  • 🌱 Go 1.23.0 is now required to build Scorecard or use it as a library. (#4547, @spencerschrock)

Checks

CI-Tests

Contributors

  • ✨ Users listed in CODEOWNERS file in GitHub repos now contribute to Contributors check (#4611, @lharrison13)

SAST

  • 🐛 SAST: Fixed an issue with Sonar Cloud not being detected due to a renamed GitHub app. (#4541, @spencerschrock)

Probes

  • ✨ Added independent probe that checks for ecosystem specific non-memory safety practices in the codebase and flags them. (#4499, @balteravishay)

Documentation

New Contributors

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy