Skip to content

build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3#9

Closed
dependabot[bot] wants to merge 29 commits intomasterfrom
dependabot/github_actions/ossf/scorecard-action-2.4.3
Closed

build(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3#9
dependabot[bot] wants to merge 29 commits intomasterfrom
dependabot/github_actions/ossf/scorecard-action-2.4.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 3, 2026

Bumps ossf/scorecard-action from 2.4.0 to 2.4.3.

Release notes

Sourced from ossf/scorecard-action's releases.

v2.4.3

What's Changed

This update bumps the Scorecard version to the v5.3.0 release. For a complete list of changes, please refer to the Scorecard v5.3.0 release notes.

Documentation

Other

New Contributors

Full Changelog: ossf/scorecard-action@v2.4.2...v2.4.3

v2.4.2

What's Changed

This update bumps the Scorecard version to the v5.2.1 release. For a complete list of changes, please refer to the Scorecard v5.2.0 and v5.2.1 release notes.

Full Changelog: ossf/scorecard-action@v2.4.1...v2.4.2

v2.4.1

What's Changed

  • This update bumps the Scorecard version to the v5.1.1 release. For a complete list of changes, please refer to the v5.1.0 and v5.1.1 release notes.
  • Publishing results now uses half the API quota as before. The exact savings depends on the repository in question.
  • Some errors were made into annotations to make them more visible
  • There is now an optional file_mode input which controls how repository files are fetched from GitHub. The default is archive, but git produces the most accurate results for repositories with .gitattributes files at the cost of analysis speed.
  • The underlying container for the action is now hosted on GitHub Container Registry. There should be no functional changes.

Docs

New Contributors

Commits
  • 4eaacf0 bump docker to ghcr v2.4.3 (#1587)
  • 42e3a01 🌱 Bump the github-actions group with 3 updates (#1585)
  • 88c07ac 🌱 Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)
  • 6c690f2 Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)
  • 92083b5 📖 Fix recommended command to test the image in development (#1583)
  • 7975ea6 🌱 Bump the docker-images group across 1 directory with 2 updates (#1...
  • 0d1a743 🌱 Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)
  • 46e6e0c 🌱 Bump the github-actions group with 2 updates (#1580)
  • c3f1350 🌱 Improve printing options (#1584)
  • 43e475b 🌱 Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

srpatcha and others added 29 commits April 1, 2026 00:40
- Fix SEGFAULT in eni_decoder_tests on Windows (MSVC C4700)
  Zero-initialize eni_decode_result_t and eni_eeg_packet_t variables
  to prevent MSVC optimizer UB with uninitialized locals in Release mode

- Fix 'eosim simulate' command not found in EoSim Sanity and Simulation Test workflows
  Replace 'eosim simulate --platform P --duration N --headless' with
  'eosim run P --headless --timeout N' (correct command in eosim 0.1.0)
eosim run/simulate requires the platforms/ directory from the source
tree, which is not bundled in the published wheel. Jobs that need
eosim run now clone EoSim and pip install -e (editable) so __file__
resolves to the source tree with platforms/ available.
Platform names must include OS suffix (x86_64-linux, arm64-linux,
riscv64-linux) to match eosim platform registry entries.
Phase 1: Modernize Build System
- Upgrade CMake to 3.20+, fix version to 0.2.0
- Add CMakePresets.json (linux/windows/macos/arm/riscv/asan/ubsan)
- Add ARM Cortex-M4 and RISC-V 32-bit cross-compilation toolchains
- Add coverage, sanitizer, and static analysis CMake modules

Phase 2: Cross-Platform CI/CD & Docker
- Add GitHub Actions workflows: CI, nightly, weekly, release, simulation, eosim-sanity, CodeQL
- Add Docker multi-stage build and test images with docker-compose
- Add Dependabot and CodeQL security scanning

Phase 3-4: C++ Bindings & Math Library
- Add C++17 RAII bindings (Provider, Pipeline, types)
- Add header-only DSP math (vector ops, activations, windows)
- Add Q15/Q31 fixed-point arithmetic library

Phase 5: Testing Infrastructure Overhaul
- Add mock neural input generator (10 signal patterns)
- Add mock provider with failure injection
- Add extended tests for DSP, NN, decoder, stim safety, provider lifecycle
- Add full pipeline integration test

Phase 6: Enhanced Neural Signal Processing
- Add real-time artifact removal (blink, EMG, saturation)
- Add adaptive filters (LMS, NLMS, RLS)
- Add multi-channel feature fusion (CSP, coherence, channel selection)

Phase 7: Neural Network Integration
- Add minimal ONNX model loader (self-contained protobuf parser)
- Add LSTM layer with 4-gate architecture
- Add INT8 quantized inference engine
- Add CNN intent decoder (conv1d -> pool -> dense -> softmax)

Phase 8: HAL & Advanced Providers
- Add Hardware Abstraction Layer (SPI, I2C, GPIO, UART, ADC)
- Add wireless BCI provider (BLE/WiFi/Serial)
- Add template provider for third-party development
- Add simulation environment with EEG and BCI signal generators

Phase 9: Python/Node.js SDKs & Web GUI
- Add Python SDK with ctypes bindings, streaming, visualization
- Add Node.js/TypeScript SDK with event-driven streaming
- Add React web GUI with WebSocket backend

Phase 10: Edge AI, TinyML & Standards Compliance
- Add TFLite Micro integration bridge
- Add online learning with SGD and experience replay
- Add multi-modal feedback loop with latency tracking
- Add ROS 2 integration (node, messages, launch file)
- Add ONI (Open Neural Interface) compliance layer
- Add EIPC real-time streaming with delta compression
- Add model quantization tool and models directory
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 1 to 2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v1...v2)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
CLOCK_MONOTONIC and clock_gettime are not available on bare-metal ARM
targets using newlib. Added preprocessor guard to skip POSIX clock on
bare-metal platforms (arm/thumb/aarch64 with newlib).
The Weekly workflow was reporting ALL tests as 'Not Run' because:

1. clang-tidy's --warnings-as-errors=bugprone-*,cert-* caused compilation
   of test binaries to fail during 'cmake --build build'.

2. The pipeline 'cmake --build ... | tee build-analysis.log' masked the
   non-zero exit code because tee always returns 0, so the workflow step
   appeared to pass and ctest ran against missing executables.

Fixes:
- Disable CMAKE_C_CPPCHECK and CMAKE_C_CLANG_TIDY in tests/CMakeLists.txt
  so static analysis runs on library code but not on test code (CMake
  scoping via add_subdirectory keeps this isolated).
- Add 'set -o pipefail' before the build pipeline in weekly.yml so any
  build failure correctly propagates and fails the step.
- dsp.c: NOLINT(bugprone-easily-swappable-parameters) on eni_dsp_artifact_detect and eni_dsp_epoch_init
- config.c: replace atof() with strtod(), atoi() with strtol() (cert-err34-c), check fclose() return value (cert-err33-c)
- nn.c: NOLINT(bugprone-easily-swappable-parameters) on nn_apply_activation
- CI: multi-OS build, cross-compile (aarch64/arm/riscv64), sanitizers, coverage
- Release: automated GitHub Releases with cross-compiled artifacts
- Security: CodeQL analysis + OSSF Scorecard
- Dependencies: Dependabot for GitHub Actions
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.0 to 2.4.3.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@v2.4.0...v2.4.3)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 3, 2026
@dependabot dependabot Bot added github_actions Pull requests that update GitHub Actions code dependencies Pull requests that update a dependency file labels Apr 3, 2026
@srpatcha srpatcha closed this Apr 3, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 3, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/github_actions/ossf/scorecard-action-2.4.3 branch April 3, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant