From 26dc0a649643b22f5a5ced683aed77e3356fd827 Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 09:35:17 +0700 Subject: [PATCH 1/7] feat(footer): use dynamic year variable --- _layouts/_includes/footer.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_layouts/_includes/footer.html b/_layouts/_includes/footer.html index 42b4394..3f0f8f3 100644 --- a/_layouts/_includes/footer.html +++ b/_layouts/_includes/footer.html @@ -28,7 +28,7 @@

Contact Us

From b29e9e9df450d61553469f17cc7d0649114328e3 Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 09:54:27 +0700 Subject: [PATCH 2/7] ci(scorecard): add manually trigger --- .github/workflows/scorecard.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index baf286b..f4b2b91 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -13,6 +13,8 @@ on: - cron: "22 15 * * 4" push: branches: ["gh-pages"] + + workflow_dispatch: # Declare default permissions as read only. permissions: read-all From 90ef6b1d2f3803212281f7e4194e409d3005be04 Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 09:59:14 +0700 Subject: [PATCH 3/7] ci(scorecard): update upload artifact name --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index f4b2b91..1e5f84e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -63,7 +63,7 @@ jobs: - name: "Upload artifact" uses: actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20 with: - name: SARIF file + name: scorecard-sarif path: results.sarif retention-days: 5 From a4c24d2bdf016b6b443e29ff0b2b96da24a9b881 Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 10:01:32 +0700 Subject: [PATCH 4/7] ci(scorecard): switch upload-artifact to v4 --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1e5f84e..b00426f 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -61,7 +61,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20 + uses: actions/upload-artifact@v4 with: name: scorecard-sarif path: results.sarif From 30278636b7124d378a7eddcfc91accfac710b20f Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 10:04:14 +0700 Subject: [PATCH 5/7] ci(scorecard): switch to v4 --- .github/workflows/scorecard.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b00426f..57bdc36 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -39,7 +39,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1 + uses: ossf/scorecard-action@v4 with: results_file: results.sarif results_format: sarif @@ -70,6 +70,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: results.sarif From 775df2a6fbbc4afeebf0557532262d65f5f6abde Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 10:06:13 +0700 Subject: [PATCH 6/7] ci(scorecard): switch to v2.4.3 --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 57bdc36..23f730d 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -39,7 +39,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@v4 + uses: ossf/scorecard-action@v2.4.3 with: results_file: results.sarif results_format: sarif From b84659206d3e3a61d983498e7d1b2b8b6aad57ba Mon Sep 17 00:00:00 2001 From: danielcristho Date: Fri, 9 Jan 2026 10:20:50 +0700 Subject: [PATCH 7/7] ci(scorecard): fix pre-commit --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 23f730d..44e9cf3 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -13,7 +13,7 @@ on: - cron: "22 15 * * 4" push: branches: ["gh-pages"] - + workflow_dispatch: # Declare default permissions as read only.