Skip to content

🌱 Bump github.com/ossf/scorecard/v5 from 5.4.0 to 5.5.0#1653

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/ossf/scorecard/v5-5.5.0
Open

🌱 Bump github.com/ossf/scorecard/v5 from 5.4.0 to 5.5.0#1653
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/ossf/scorecard/v5-5.5.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 24, 2026

Bumps github.com/ossf/scorecard/v5 from 5.4.0 to 5.5.0.

Release notes

Sourced from github.com/ossf/scorecard/v5's releases.

v5.5.0

What's Changed

General

  • The official Scorecard docker images are hosted on GitHub Container Registry starting with v5.5.0. Older releases will be brought over from Google Container/Artifact Registry, before being discontinued.(@​spencerschrock in ossf/scorecard#4885)
  • Scorecard will now skip checks that don't apply to the current repo type by @​JamieMagee in ossf/scorecard#5000. If any checks no longer run that previously ran, and you think are supported by the underlying forge please file an issue.

Checks

Branch-Protection

CII-Best-Practices

Dangerous-Workflow

Contributors

Dependency-Update-Tool

Fuzzing

Docs

Other

New Contributors

... (truncated)

Commits
  • c395761 🐛 Fix check metadata which skipped some supported checks (#5034)
  • 1852490 🌱 Bump the distroless group across 6 directories with 1 update (#5016)
  • 5d3ec19 🌱 Bump the golang group across 8 directories with 1 update (#5015)
  • be6efba 🌱 Bump github.com/go-git/go-git/v5 from 5.16.5 to 5.18.0 (#5032)
  • cf2aef8 🌱 Bump github.com/jackc/pgx/v5 from 5.7.6 to 5.9.2 in /tools (#5031)
  • a1d03ef 🌱 Add @​JamieMagee as codeowner for Azure DevOps client (#5024)
  • 4b8e9d1 🌱 Bump github.com/sigstore/timestamp-authority/v2 in /tools (#5018)
  • 424f70c 🌱 Bump github.com/aws/aws-sdk-go-v2/service/s3 in /tools (#5007)
  • 29f186e 🌱 Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 (#5011)
  • e8b8afe 🌱 Bump go.opentelemetry.io/otel/sdk in /tools (#5012)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 24, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 24, 2026 21:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 24, 2026
Comment thread go.mod
github.com/google/go-cmp v0.7.0
github.com/google/go-github/v46 v46.0.0
github.com/ossf/scorecard/v5 v5.4.0
github.com/ossf/scorecard/v5 v5.5.0
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also needs to bump the appropriate commit build flag

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/ossf/scorecard/v5-5.5.0 branch 2 times, most recently from 355ef22 to 3fc8227 Compare April 26, 2026 04:45
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 26, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 26.51%. Comparing base (ee561a8) to head (3fc8227).
⚠️ Report is 13 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #1653      +/-   ##
==========================================
+ Coverage   26.32%   26.51%   +0.18%     
==========================================
  Files          13       13              
  Lines         775      777       +2     
==========================================
+ Hits          204      206       +2     
  Misses        549      549              
  Partials       22       22              
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/ossf/scorecard/v5-5.5.0 branch from 3fc8227 to b0a4dd1 Compare April 26, 2026 04:52
Bumps [github.com/ossf/scorecard/v5](https://github.com/ossf/scorecard) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/ossf/scorecard/releases)
- [Changelog](https://github.com/ossf/scorecard/blob/main/RELEASE.md)
- [Commits](ossf/scorecard@v5.4.0...v5.5.0)

---
updated-dependencies:
- dependency-name: github.com/ossf/scorecard/v5
  dependency-version: 5.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/ossf/scorecard/v5-5.5.0 branch from b0a4dd1 to 38a7112 Compare April 26, 2026 05:31
@Kielek
Copy link
Copy Markdown

Kielek commented May 7, 2026

@spencerschrock, any chance to finish job on this PR and as a follow up to make a release?
Looking especially for https://github.com/ossf/scorecard/releases/tag/v5.5.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants