Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/goreleaser/goreleaser-example-supply-chain

Example goreleaser + github actions config with keyless signing and SBOM generation
https://github.com/goreleaser/goreleaser-example-supply-chain

chore(deps): bump anchore/sbom-action from 0.17.2 to 0.17.3

dependabot[bot] opened this pull request 5 days ago
chore(deps): bump sigstore/cosign-installer from 3.6.0 to 3.7.0

dependabot[bot] opened this pull request 12 days ago
chore(deps): bump anchore/sbom-action from 0.17.1 to 0.17.2

dependabot[bot] opened this pull request about 2 months ago
chore(deps): bump anchore/sbom-action from 0.17.0 to 0.17.1

dependabot[bot] opened this pull request 2 months ago
chore(deps): bump sigstore/cosign-installer from 3.5.0 to 3.6.0

dependabot[bot] opened this pull request 2 months ago
chore(deps): bump anchore/sbom-action from 0.16.1 to 0.17.0

dependabot[bot] opened this pull request 3 months ago
chore(deps): bump anchore/sbom-action from 0.16.0 to 0.16.1

dependabot[bot] opened this pull request 3 months ago
chore(deps): bump goreleaser/goreleaser-action from 5 to 6

dependabot[bot] opened this pull request 5 months ago
chore(deps): bump anchore/sbom-action from 0.15.11 to 0.16.0

dependabot[bot] opened this pull request 5 months ago
chore(deps): bump anchore/sbom-action from 0.15.10 to 0.15.11

dependabot[bot] opened this pull request 6 months ago
chore(deps): bump sigstore/cosign-installer from 3.3.0 to 3.5.0

dependabot[bot] opened this pull request 6 months ago
chore(deps): bump anchore/sbom-action from 0.15.7 to 0.15.9

dependabot[bot] opened this pull request 8 months ago
chore(deps): bump anchore/sbom-action from 0.15.7 to 0.15.8

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.6 to 0.15.7

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.5 to 0.15.6

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.4 to 0.15.5

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.3 to 0.15.4

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.2 to 0.15.3

dependabot[bot] opened this pull request 9 months ago
chore(deps): bump anchore/sbom-action from 0.15.1 to 0.15.2

dependabot[bot] opened this pull request 10 months ago
chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0

dependabot[bot] opened this pull request 10 months ago
chore(deps): bump actions/setup-go from 4 to 5

dependabot[bot] opened this pull request 11 months ago
chore(deps): bump anchore/sbom-action from 0.15.0 to 0.15.1

dependabot[bot] opened this pull request 11 months ago
chore(deps): bump anchore/sbom-action from 0.14.3 to 0.15.0

dependabot[bot] opened this pull request 11 months ago
chore(deps): bump sigstore/cosign-installer from 3.1.2 to 3.2.0

dependabot[bot] opened this pull request 12 months ago
chore(deps): bump docker/login-action from 2 to 3

dependabot[bot] opened this pull request about 1 year ago
chore(deps): bump goreleaser/goreleaser-action from 4 to 5

dependabot[bot] opened this pull request about 1 year ago
chore(deps): bump actions/checkout from 3 to 4

dependabot[bot] opened this pull request about 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.1.1 to 3.1.2

dependabot[bot] opened this pull request about 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.1.0 to 3.1.1

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.0.5 to 3.1.0

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump anchore/sbom-action from 0.14.2 to 0.14.3

dependabot[bot] opened this pull request over 1 year ago
Configure Renovate

renovate[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.0.4 to 3.0.5

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.0.3 to 3.0.4

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump anchore/sbom-action from 0.14.1 to 0.14.2

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.0.2 to 3.0.3

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 3.0.1 to 3.0.2

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump anchore/sbom-action from 0.13.4 to 0.14.1

dependabot[bot] opened this pull request over 1 year ago
fix(.goreleaser.yaml): set signs and docker_sign cosign non-interactive

maxgio92 opened this pull request over 1 year ago
Cosign >=2.0.0 needs non-interactivity

maxgio92 opened this issue over 1 year ago
chore(deps): bump anchore/sbom-action from 0.13.3 to 0.13.4

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump actions/setup-go from 3 to 4

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1

dependabot[bot] opened this pull request over 1 year ago
feat(deps): bump gopkg.in/yaml.v3 from 3.0.0-20210107192922-496545a6307b to 3.0.1

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump anchore/sbom-action from 0.13.2 to 0.13.3

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump anchore/sbom-action from 0.13.1 to 0.13.2

dependabot[bot] opened this pull request over 1 year ago
chore(deps): bump goreleaser/goreleaser-action from 3 to 4

dependabot[bot] opened this pull request almost 2 years ago
chore(deps): bump anchore/sbom-action from 0.13.0 to 0.13.1

dependabot[bot] opened this pull request almost 2 years ago
chore(deps): bump anchore/sbom-action from 0.12.0 to 0.13.0

dependabot[bot] opened this pull request almost 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.8.0 to 2.8.1

dependabot[bot] opened this pull request almost 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.7.0 to 2.8.0

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.6.0 to 2.7.0

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.5.1 to 2.6.0

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump anchore/sbom-action from 0.11.0 to 0.12.0

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.5.0 to 2.5.1

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.4.1 to 2.5.0

dependabot[bot] opened this pull request about 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.4.0 to 2.4.1

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.3.0 to 2.4.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump goreleaser/goreleaser-action from 2 to 3

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump docker/login-action from 1 to 2

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.2.1 to 2.3.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump anchore/sbom-action from 0.10.0 to 0.11.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.2.0 to 2.2.1

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump actions/setup-go from 2 to 3

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump anchore/sbom-action from 0.9.0 to 0.10.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.1.0 to 2.2.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump anchore/sbom-action from 0.8.0 to 0.9.0

dependabot[bot] opened this pull request over 2 years ago
feat: update to go 1.18

caarlos0 opened this pull request over 2 years ago
fix: reproducible builds

caarlos0 opened this pull request over 2 years ago
chore(deps): bump anchore/sbom-action from 0.7.0 to 0.8.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump actions/cache from 2 to 3

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.0.1 to 2.1.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump anchore/sbom-action from 0.6.0 to 0.7.0

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump actions/checkout from 2 to 3

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 2.0.0 to 2.0.1

dependabot[bot] opened this pull request over 2 years ago
chore(deps): bump sigstore/cosign-installer from 1.4.1 to 2.0.0

dependabot[bot] opened this pull request over 2 years ago
Create test.md

darren17082 opened this pull request almost 3 years ago
feat: add source tarball support

shibumi opened this pull request almost 3 years ago