Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the github-actions group with 3 updates #1469

Commits on Dec 20, 2023

  1. Bump the github-actions group with 3 updates

    Bumps the github-actions group with 3 updates: [anchore/scan-action](https://github.com/anchore/scan-action), [github/codeql-action](https://github.com/github/codeql-action) and [actions/upload-artifact](https://github.com/actions/upload-artifact).
    
    
    Updates `anchore/scan-action` from 3.3.7 to 3.3.8
    - [Release notes](https://github.com/anchore/scan-action/releases)
    - [Changelog](https://github.com/anchore/scan-action/blob/main/CHANGELOG.md)
    - [Commits](anchore/scan-action@62370b5...896d5f4)
    
    Updates `github/codeql-action` from 2.22.8 to 3.22.11
    - [Release notes](https://github.com/github/codeql-action/releases)
    - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
    - [Commits](github/codeql-action@407ffaf...b374143)
    
    Updates `actions/upload-artifact` from 3.1.3 to 4.0.0
    - [Release notes](https://github.com/actions/upload-artifact/releases)
    - [Commits](actions/upload-artifact@a8a3f3a...c7d193f)
    
    ---
    updated-dependencies:
    - dependency-name: anchore/scan-action
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: github-actions
    - dependency-name: github/codeql-action
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: github-actions
    - dependency-name: actions/upload-artifact
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: github-actions
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    dependabot[bot] authored Dec 20, 2023
    Configuration menu
    Copy the full SHA
    0b998e3 View commit details
    Browse the repository at this point in the history

Commits on Dec 21, 2023

  1. Bump golang.org/x/crypto to v0.17.0

    Signed-off-by: Tom Pantelis <[email protected]>
    tpantelis committed Dec 21, 2023
    Configuration menu
    Copy the full SHA
    c049009 View commit details
    Browse the repository at this point in the history