Skip to content

Bump midnightntwrk/upload-sarif-github-action from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 4e7a363e1fcd1be102b28485ad17bcb507deada6 - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/midnightntwrk/upload-sarif-github-action-4e7a363e1fcd1be102b28485ad17bcb507deada6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/midnightntwrk/upload-sarif-github-action-4e7a363e1fcd1be102b28485ad17bcb507deada6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown

Bumps midnightntwrk/upload-sarif-github-action from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 4e7a363e1fcd1be102b28485ad17bcb507deada6.

Changelog

Sourced from midnightntwrk/upload-sarif-github-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Changed

  • checkov 3.2.531 -> 3.3.19. 3.3.10 widened the aiohttp<3.14 cap that had held it back. It adds ecdsa, whose Minerva CVE has no fix; .trivyignore waives it until 2026-12-31. asteval stays at 1.0.6, because checkov pins it exactly
  • opengrep v1.30.0, trivy 0.74.0, zizmor v1.30.1, earthbuild v0.8.19.
  • +checkov-requirements runs again. pip 26.2 broke pip-tools 7.6.0; 7.6.1 supports it
  • A scorecard check that passed is NOTE, not LOW. A score of 8 or better means the check found nothing wrong, yet LOW License README.md license file detected sat in the same column as things to fix, and eight passes read as eight findings. NOTE ranks 0: still listed in the summary, never gated at any threshold
  • A scanned repository's .checkov.yml is honoured instead of being overwritten. The action used to copy its own config to /src/.checkov.yml, over the top of the repository's, and pass that to --config-file - which sets rather than merges. A repository therefore had no lever at all, fatal for JSON, which takes no # checkov:skip= comment. The two are now merged: list values union so the action's entries survive, scalars are the repository's to set, and output, soft-fail and download-external-modules stay pinned because the pipeline depends on them
  • checkov no longer scans for secrets. That is gitleaks' job, and unlike checkov it honours a repository's own config. CKV_SECRET_* is a bare entropy heuristic that fires on any high-entropy literal - public keys and hashes in a chain spec, for instance - with no way for the repository to suppress it
  • Severities are recalibrated per tool onto one ladder, with CRITICAL at the top. INFO 0 · LOW 1 · MEDIUM 2 · HIGH 3 · CRITICAL 4. SARIF level is a reporting level, not an impact, and it stops at error - read straight through, every tool that speaks only level was capped below CRITICAL and the default threshold gated almost nothing. A severity the tool states is now used as-is; only a bare level is calibrated. ERROR is no longer a severity, but

... (truncated)

Commits
  • 4e7a363 Merge pull request #143 from midnightntwrk/giles-bump-scanners
  • ed3cecf chore(deps): bump opengrep, trivy, zizmor, earthbuild
  • 544fc97 chore(deps): bump checkov 3.2.531 -> 3.3.19, pip-tools 7.6.0 -> 7.6.1
  • 27db698 Merge pull request #142 from midnightntwrk/giles-apt-retry-install
  • 01cec81 Merge branch 'main' into giles-apt-retry-install
  • c130bd2 Merge pull request #141 from midnightntwrk/dependabot/pip/gitpython-3.1.59
  • 9b9ce7d fix: install retry
  • 7b9b5bd chore(deps): bump gitpython from 3.1.58 to 3.1.59
  • 362d034 Merge pull request #139 from midnightntwrk/renovate/pypi-pip-vulnerability
  • a03e6f7 chore(deps): update dependency pip to v26.2 [security]
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [midnightntwrk/upload-sarif-github-action](https://github.com/midnightntwrk/upload-sarif-github-action) from 07dad711370cc5985885ebcf07cb8c9264bc4167 to 4e7a363e1fcd1be102b28485ad17bcb507deada6.
- [Release notes](https://github.com/midnightntwrk/upload-sarif-github-action/releases)
- [Changelog](https://github.com/midnightntwrk/upload-sarif-github-action/blob/main/CHANGELOG.md)
- [Commits](midnightntwrk/upload-sarif-github-action@07dad71...4e7a363)

---
updated-dependencies:
- dependency-name: midnightntwrk/upload-sarif-github-action
  dependency-version: 4e7a363e1fcd1be102b28485ad17bcb507deada6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 26, 2026
@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for venturegate-mid canceled.

Name Link
🔨 Latest commit 26e4ba8
🔍 Latest deploy log https://app.netlify.com/projects/venturegate-mid/deploys/6ab79f4fcd54cb0008b28f78

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Looks like midnightntwrk/upload-sarif-github-action is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/midnightntwrk/upload-sarif-github-action-4e7a363e1fcd1be102b28485ad17bcb507deada6 branch September 28, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants