scorecard/probes/releasesHaveProvenance
Spencer Schrock b9c1f3fc7a
🐛 fix signed-releases lookback limit precedence (#4060)
* switch signed-releases lookback limit precedence

if the 6th release had no assets, the lookback limit exit condition was
being skipped. This led to scenarios where too many releases were being
considered by the Signed-Releases check.

https://github.com/ossf/scorecard/issues/4059

Signed-off-by: Spencer Schrock <sschrock@google.com>

* make exit condition stronger

any release after the lookback should be skipped

Signed-off-by: Spencer Schrock <sschrock@google.com>

---------

Signed-off-by: Spencer Schrock <sschrock@google.com>
2024-05-02 10:43:13 -07:00
..
def.yml ⚠️ Allow probes to specify their own bad outcomes (#4020) 2024-04-10 14:12:53 -07:00
impl_test.go 🐛 fix signed-releases lookback limit precedence (#4060) 2024-05-02 10:43:13 -07:00
impl.go 🐛 fix signed-releases lookback limit precedence (#4060) 2024-05-02 10:43:13 -07:00