scorecard/checks/evaluation
Raghav Kaul bfaa9febc2
probe: releases with verified provenance (#4141)
* add projectpackageversions to signed releases raw results

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* finding: add NewNot* helpers, fix error msg

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* probe: releasesHaveVerifiedProvenance

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* logging

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* fix tests and lint

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* address comments

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* remove unused

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

* fix merge conflict

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>

---------

Signed-off-by: Raghav Kaul <raghavkaul+github@google.com>
2024-06-07 10:15:20 -07:00
..
binary_artifacts_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
binary_artifacts.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
branch_protection_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
branch_protection.go 🌱 Bump github.com/golangci/golangci-lint from 1.57.2 to 1.58.1 in /tools (#4108) 2024-05-15 16:58:27 +00:00
ci_tests_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
ci_tests.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
cii_best_practices_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
cii_best_practices.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
code_review_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
code_review.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
contributors_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
contributors.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
dangerous_workflow_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
dangerous_workflow.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
dependency_update_tool_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
dependency_update_tool.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
fuzzing_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
fuzzing.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
license_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
license.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
maintained_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
maintained.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
packaging_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
packaging.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
permissions.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
pinned_dependencies_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
pinned_dependencies.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
sast_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
sast.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
sbom_test.go Add experimental check for published SBOM (#3903) 2024-05-17 18:16:54 +00:00
sbom.go Add experimental check for published SBOM (#3903) 2024-05-17 18:16:54 +00:00
security_policy_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
security_policy.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
signed_releases_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
signed_releases.go probe: releases with verified provenance (#4141) 2024-06-07 10:15:20 -07:00
vulnerabilities_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
vulnerabilities.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
webhooks_test.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00
webhooks.go ⚠️ Replace v4 module references with v5 (#4027) 2024-04-12 14:51:50 -07:00