Repository navigation
Bump midnightntwrk/upload-sarif-github-action from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 362d0346b194663004cb371e8e8523bd1c910917 - #1
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [midnightntwrk/upload-sarif-github-action](https://github.com/midnightntwrk/upload-sarif-github-action) from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 362d0346b194663004cb371e8e8523bd1c910917. - [Release notes](https://github.com/midnightntwrk/upload-sarif-github-action/releases) - [Changelog](https://github.com/midnightntwrk/upload-sarif-github-action/blob/main/CHANGELOG.md) - [Commits](midnightntwrk/upload-sarif-github-action@07dad71...362d034) --- updated-dependencies: - dependency-name: midnightntwrk/upload-sarif-github-action dependency-version: 362d0346b194663004cb371e8e8523bd1c910917 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
4 similar comments
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
Superseded by #4. |
Bumps midnightntwrk/upload-sarif-github-action from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 362d0346b194663004cb371e8e8523bd1c910917.
Changelog
Sourced from midnightntwrk/upload-sarif-github-action's changelog.
... (truncated)
Commits
362d034Merge pull request #139 from midnightntwrk/renovate/pypi-pip-vulnerabilitya03e6f7chore(deps): update dependency pip to v26.2 [security]e90808cMerge pull request #136 from midnightntwrk/giles-scorecard-passes-are-notes0d9beb5fix: success should be a note, not a low6d0d6faMerge pull request #135 from midnightntwrk/giles-document-exclusionsbf5e2c5docs: document how to exclude an expected finding, per scanner98bf87bMerge pull request #134 from midnightntwrk/giles-checkov-skip-secrets8a8f0abfix: checkov was stepping on gitleaks toes and config wasn't overridablef0a23a4Merge pull request #133 from midnightntwrk/giles-scorecard-inconclusivead93c69feat: skip publishing check as it's detection is poorDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)