Skip to content

chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.3#3516

Merged
mdelapenya merged 1 commit intomainfrom
dependabot/github_actions/ossf/scorecard-action-2.4.3
Jan 2, 2026
Merged

chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.3#3516
mdelapenya merged 1 commit intomainfrom
dependabot/github_actions/ossf/scorecard-action-2.4.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jan 1, 2026

Bumps ossf/scorecard-action from 2.4.1 to 2.4.3.

Release notes

Sourced from ossf/scorecard-action's releases.

v2.4.3

What's Changed

This update bumps the Scorecard version to the v5.3.0 release. For a complete list of changes, please refer to the Scorecard v5.3.0 release notes.

Documentation

Other

New Contributors

Full Changelog: ossf/scorecard-action@v2.4.2...v2.4.3

v2.4.2

What's Changed

This update bumps the Scorecard version to the v5.2.1 release. For a complete list of changes, please refer to the Scorecard v5.2.0 and v5.2.1 release notes.

Full Changelog: ossf/scorecard-action@v2.4.1...v2.4.2

Commits
  • 4eaacf0 bump docker to ghcr v2.4.3 (#1587)
  • 42e3a01 🌱 Bump the github-actions group with 3 updates (#1585)
  • 88c07ac 🌱 Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)
  • 6c690f2 Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)
  • 92083b5 📖 Fix recommended command to test the image in development (#1583)
  • 7975ea6 🌱 Bump the docker-images group across 1 directory with 2 updates (#1...
  • 0d1a743 🌱 Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)
  • 46e6e0c 🌱 Bump the github-actions group with 2 updates (#1580)
  • c3f1350 🌱 Improve printing options (#1584)
  • 43e475b 🌱 Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.1 to 2.4.3.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@f49aabe...4eaacf0)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependencies or external services github_actions Pull requests that update GitHub Actions code labels Jan 1, 2026
@dependabot dependabot Bot requested a review from a team as a code owner January 1, 2026 11:13
@dependabot dependabot Bot added dependencies Dependencies or external services github_actions Pull requests that update GitHub Actions code labels Jan 1, 2026
@netlify
Copy link
Copy Markdown

netlify Bot commented Jan 1, 2026

Deploy Preview for testcontainers-go ready!

Name Link
🔨 Latest commit d3d2313
🔍 Latest deploy log https://app.netlify.com/projects/testcontainers-go/deploys/695656d524dc7100088cb25d
😎 Deploy Preview https://deploy-preview-3516--testcontainers-go.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions github-actions Bot added the chore Changes that do not impact the existing functionality label Jan 1, 2026
@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Jan 1, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@mdelapenya mdelapenya removed the chore Changes that do not impact the existing functionality label Jan 2, 2026
@mdelapenya mdelapenya merged commit 6d1db32 into main Jan 2, 2026
16 checks passed
@mdelapenya mdelapenya deleted the dependabot/github_actions/ossf/scorecard-action-2.4.3 branch January 2, 2026 10:32
mdelapenya added a commit that referenced this pull request Jan 2, 2026
…util/v4-4.25.12

* main:
  chore(deps): bump golang.org/x/sys from 0.38.0 to 0.39.0 (#3521)
  chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.3 (#3516)
  chore(deps): bump github.com/docker/docker from 28.5.1+incompatible to 28.5.2+incompatible (#3537)
  chore(deps): bump pymdown-extensions from 10.8.1 to 10.16.1 (#3513)
  chore(deps): bump actions/checkout from 4.2.2 to 6.0.1 (#3517)
  chore(metrics): update usage metrics (2026-01-01) (#3515)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies or external services github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant