Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: bump google/osv-scanner from 12331be44c5c3d32b59eb006e8613bc53c3317a5 to f4985f9e195671251d845829181dce6bb91e9efb #6265

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 3, 2023

Bumps google/osv-scanner from 12331be44c5c3d32b59eb006e8613bc53c3317a5 to f4985f9e195671251d845829181dce6bb91e9efb.

Changelog

Sourced from google/osv-scanner's changelog.

v1.4.0:

Features

API Features

  • [Feature #451](google/osv-scanner#451) The lockfile package now support extracting dependencies directly from any io.Reader, removing the requirement of a file path.

Fixes

v1.3.6:

Minor Updates

Fixes

  • [Feature #439](google/osv-scanner#439) Fix PURLToPackage not returning the full namespace of packages in ecosystems that use them (e.g. golang).

v1.3.5:

Features

API Features

... (truncated)

Commits
  • f4985f9 chore(deps): update dependency jekyll-feed to v0.17.0 (#568)
  • 2964602 chore(deps): update github/codeql-action action to v2.21.9 (#567)
  • d551c40 chore(deps): update golang:alpine docker digest to 4bc6541 (#566)
  • 85f01cf chore(deps): update alpine:3.18 docker digest to eece025 (#565)
  • 993bbed ci: don't fetch the whole repository history when its not needed (#562)
  • d683cfb ci: ensure that actions/checkout is pinned (#563)
  • fac0935 Block release on vuln scan (#561)
  • 5f725bd ci: use .go-version file (#564)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [google/osv-scanner](https://github.com/google/osv-scanner) from 12331be44c5c3d32b59eb006e8613bc53c3317a5 to f4985f9e195671251d845829181dce6bb91e9efb.
- [Release notes](https://github.com/google/osv-scanner/releases)
- [Changelog](https://github.com/google/osv-scanner/blob/main/CHANGELOG.md)
- [Commits](google/osv-scanner@12331be...f4985f9)

---
updated-dependencies:
- dependency-name: google/osv-scanner
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@metaclips metaclips added this pull request to the merge queue Oct 3, 2023
Merged via the queue into develop with commit fb4bc57 Oct 3, 2023
20 checks passed
@metaclips metaclips deleted the dependabot/github_actions/google/osv-scanner-f4985f9e195671251d845829181dce6bb91e9efb branch October 3, 2023 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant