Skip to content

Bump lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.7.0 to 0.9.0 - #19

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.7.0 to 0.9.0.

Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.9.0

Downloads for this release

✨ New Features ✨

🔧 Maintenance 🔧

Links

v0.8.0

Downloads for this release

✨ New Features ✨

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

Commits
  • 76ea523 Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness
  • 3bd6689 Docs: Name Python among scan_targets exceptions
  • ab0f5c6 Feat: Add a python build_type to the CLM lane
  • 4c88685 Test: Run the lanes' validation steps on every PR
  • 37d4e67 Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu...
  • 430b1ba Merge pull request #111 from lfreleng-actions/dependabot/github_actions/githu...
  • bb7e758 Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel...
  • 95377d3 Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu...
  • a12865c Merge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel...
  • 9d6aa08 CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…ifecycle.yaml

Bumps [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows) from 0.7.0 to 0.9.0.
- [Release notes](https://github.com/lfreleng-actions/security-workflows/releases)
- [Commits](lfreleng-actions/security-workflows@bdcf7d8...76ea523)

---
updated-dependencies:
- dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@github-actions

Copy link
Copy Markdown

PR: #19
Mode: squash
Topic: GH-sdc-19
Change-Ids:
Ic90f0245d793f356255e57aa8a9442354006690a
Digest: fbf3444cd555
GitHub-Hash: 0c5b4d63443df616

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/sdc/+/147934

onap-github pushed a commit that referenced this pull request Oct 5, 2026
…ifecycle.yaml from 0.7.0 to 0.9.0

## Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.9.0

✨ New Features ✨

Feat: Test lane steps per PR and add Python CLM @​ModeSevenIndustrialSolutions (#113)

🔧 Maintenance 🔧

CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.1 to 0.5.2 @dependabot[bot] (#108)
CI(actions): Bump github/codeql-action/analyze from 4.37.9 to 4.38.0 @dependabot[bot] (#109)
CI(actions): Bump lfreleng-actions/go-test-action from 0.1.0 to 0.1.1 @dependabot[bot] (#110)
CI(actions): Bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0 @dependabot[bot] (#111)
CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0 @dependabot[bot] (#112)

Links

Submit bugs/feature requests

v0.8.0

✨ New Features ✨

Feat: Settle the migration-audit input regressions @​ModeSevenIndustrialSolutions (#99)

🔧 Maintenance 🔧

CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#101)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#102)
CI(actions): Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#103)
CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.0 to 0.5.1 @dependabot[bot] (#104)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#80)
Chore: Default Maven to 3.9.11 on the build lanes @​ModeSevenIndustrialSolutions (#106)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#107)

🎓 Code Quality 🎓

CI: Adopt the self-repository reference syntax @​ModeSevenIndustrialSolutions (#105)

Links

Submit bugs/feature requests

## Commits

76ea523 Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness
3bd6689 Docs: Name Python among scan_targets exceptions
ab0f5c6 Feat: Add a python build_type to the CLM lane
4c88685 Test: Run the lanes' validation steps on every PR
37d4e67 Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu
430b1ba Merge pull request #111 from lfreleng-actions/dependabot/github_actions/githu
bb7e758 Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel
95377d3 Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu
a12865c Merge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel
9d6aa08 CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Change-Id: Ic90f0245d793f356255e57aa8a9442354006690a
GitHub-PR: #19
GitHub-Hash: 0c5b4d63443df616
Signed-off-by: onap.gh2gerrit <[email protected]>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.0 branch October 5, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants