update: bump the gh-actions-packages group with 4 updates #1433
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the gh-actions-packages group with 4 updates: snok/container-retention-policy, github/codeql-action, bridgecrewio/checkov-action and anchore/sbom-action.
Updates
snok/container-retention-policy
from 2.1.3 to 2.2.1Release notes
Sourced from snok/container-retention-policy's releases.
Commits
b56f4ff
fix: default9505983
docs: Add an example usingGITHUB_TOKEN
919ae1b
chore: Run pre-commit linter0eed829
tests: Add test case for badtoken_type
valuecaada23
docs: Movetoken-type
closer totoken
a13f7f0
fix: Changeuse-github-token
totoken-type
94ec214
fix: Resolve pre-commit errors after rebasingc432357
tests: Add test foruse-github-token
d8fcd36
docs: Update README with newuse-github-token
inputcbce1ab
feat: Adduse-github-token
as action inputUpdates
github/codeql-action
from 2.22.8 to 3.22.11Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
b374143
Merge pull request #2034 from github/update-v3.22.11-64e61baeae2b5cc7
Update changelog for v3.22.1164e61ba
Merge pull request #2006 from github/nickfyson/node-20c757f9f
Apply suggestions from code review7898bc2
add pr check for node version consistency6b5b958
remove dedundant single quotes from node version stringsea1e72c
Update .github/workflows/pr-checks.ymlb974542
Merge branch 'main' into nickfyson/node-20b995212
Bump the actions group with 2 updates (#2024)3c1878d
Merge pull request #2029 from github/mergeback/v2.22.10-to-main-305f6546Updates
bridgecrewio/checkov-action
from 12.2598.0 to 12.2621.0Commits
097919d
Bump checkov container version to 3.1.401048b04
Bump checkov container version to 3.1.397f9dcb2
Bump checkov container version to 3.1.3817f0fe3
Bump checkov container version to 3.1.37bbda709
Bump checkov container version to 3.1.368e27cd4
Bump checkov container version to 3.1.35d82d114
Bump checkov container version to 3.1.34c19f68b
Bump checkov container version to 3.1.331d8e18d
Bump checkov container version to 3.1.326cd9fd8
Bump checkov container version to 3.1.31Updates
anchore/sbom-action
from 0.15.0 to 0.15.1Release notes
Sourced from anchore/sbom-action's releases.
Commits
5ecf649
chore(deps): update Syft to v0.98.0 (#431)a4126e6
Add config input (#430)9d0277c
chore: pin and upgrade gh actions (#429)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions