Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependencies using scripts/bump-deps.sh #1441

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

github-actions[bot]
Copy link

This PR created by create-pull-request must be closed and reopened manually to trigger automated checks.

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@github-actions github-actions bot requested a review from a team as a code owner December 24, 2024 10:04
@github-actions github-actions bot added the dependencies Pull requests that update a dependency file label Dec 24, 2024
@austinvazquez austinvazquez reopened this Dec 24, 2024
Copy link
Author

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
gomod/github.com/google/flatbuffers 24.12.23+incompatible 🟢 8.3
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Maintained🟢 1011 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 8Found 25/30 approved changesets -- score normalized to 8
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Signed-Releases🟢 84 out of the last 5 releases have a total of 4 signed artifacts.
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Fuzzing🟢 10project is fuzzed
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 73 existing vulnerabilities detected
gomod/github.com/google/flatbuffers 24.12.23+incompatible 🟢 8.3
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Maintained🟢 1011 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 8Found 25/30 approved changesets -- score normalized to 8
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Signed-Releases🟢 84 out of the last 5 releases have a total of 4 signed artifacts.
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Fuzzing🟢 10project is fuzzed
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 73 existing vulnerabilities detected

Scanned Files

  • cmd/go.mod
  • go.mod

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant