Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

v5.2.0

Compare
Choose a tag to compare
Loading
@spencerschrock spencerschrock released this 27 May 21:46
· 88 commits to main since this release
v5.2.0
f08e8fb

What's Changed

General

  • ✨ Scorecard can now generate its output as an in-toto statement by specifying --format=intoto (#4491, @puerco)
  • ✨ Improved the performance of --file-mode git (#4563, @spencerschrock)
  • 🐛 Ensure artifactLocation in sarif output are escaped by @xhochy in #4619
  • ✨ Scorecard now supports configuration files ending in either .yml or .yaml (#4568, @ratancs)
  • 🌱 Go 1.23.0 is now required to build Scorecard or use it as a library. (#4547, @spencerschrock)

Checks

CI-Tests

Contributors

  • ✨ Users listed in CODEOWNERS file in GitHub repos now contribute to Contributors check (#4611, @lharrison13)

SAST

  • 🐛 SAST: Fixed an issue with Sonar Cloud not being detected due to a renamed GitHub app. (#4541, @spencerschrock)

Probes

  • ✨ Added independent probe that checks for ecosystem specific non-memory safety practices in the codebase and flags them. (#4499, @balteravishay)

Documentation

New Contributors

Morty Proxy This is a proxified and sanitized view of the page, visit original site.