From 66817fccc34fdabf8e013924883c3ecf2a65cf1b Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Fri, 16 Aug 2024 10:54:17 +0200 Subject: [PATCH] script/setup/install-dev-tools: include patch version in versions The OpenSSF scorecard is complaining about these two dependencies being installed without a patch version specified; Warn: goCommand not pinned by hash: script/setup/install-dev-tools:27 Warn: goCommand not pinned by hash: script/setup/install-dev-tools:28 While the error indicates it expects a hash, it looks like it's fine with other modules in the same file, the difference being that those specify a full version, including path version, e.g.; https://github.com/containerd/containerd/blob/919beb1cf7d4edda26a3b95bf1b0d83b178e995e/script/setup/install-dev-tools#L26 This patch updates `protoc-gen-go` and `protoc-gen-go-grpc` to the latest patch release for the specified versions. Signed-off-by: Sebastiaan van Stijn --- script/setup/install-dev-tools | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/script/setup/install-dev-tools b/script/setup/install-dev-tools index e3e4e70cc..fbf179fbd 100755 --- a/script/setup/install-dev-tools +++ b/script/setup/install-dev-tools @@ -24,6 +24,6 @@ go install github.com/containerd/protobuild@v0.3.0 go install github.com/containerd/protobuild/cmd/go-fix-acronym@v0.3.0 go install github.com/cpuguy83/go-md2man/v2@v2.0.2 go install github.com/golangci/golangci-lint/cmd/golangci-lint@v1.54.2 -go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.28 -go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.2 +go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.28.1 +go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.2.0 go install github.com/containerd/ttrpc/cmd/protoc-gen-go-ttrpc@v1.2.5