Skip to content

build(deps): update dependency ossf/scorecard to v5.5.0#239

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/ossf-scorecard-5.x
May 1, 2026
Merged

build(deps): update dependency ossf/scorecard to v5.5.0#239
renovate[bot] merged 1 commit into
mainfrom
renovate/ossf-scorecard-5.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 28, 2026

This PR contains the following updates:

Package Update Change OpenSSF
ossf/scorecard minor v5.4.0v5.5.0 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

ossf/scorecard (ossf/scorecard)

v5.5.0

Compare Source

What's Changed

General

  • The official Scorecard docker images are hosted on GitHub Container Registry starting with v5.5.0.
    Older releases will be brought over from Google Container/Artifact Registry, before being discontinued.(@​spencerschrock in #​4885)
  • Scorecard will now skip checks that don't apply to the current repo type by @​JamieMagee in #​5000.
    If any checks no longer run that previously ran, and you think are supported by the underlying forge please file an issue.

Checks

Branch-Protection
  • 🌱 Use rulesets if one exists when classic branch protection rule is inaccessible by @​trask in #​4853
CII-Best-Practices
Dangerous-Workflow
Contributors
Dependency-Update-Tool
Fuzzing

Docs

Other

New Contributors

Full Changelog: ossf/scorecard@v5.4.0...v5.5.0


Configuration

📅 Schedule: (in timezone Europe/Stockholm)

  • Branch creation
    • "after 8:00pm on Saturday,before 11:59pm on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Related to project dependencies label Apr 28, 2026
renovate-approve[bot]
renovate-approve Bot previously approved these changes Apr 28, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot merged commit e6c34d9 into main May 1, 2026
21 checks passed
@renovate renovate Bot deleted the renovate/ossf-scorecard-5.x branch May 1, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Related to project dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants