Repository navigation
Bump lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.3.0 to 0.9.2 - #35
Conversation
…ifecycle.yaml Bumps [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows) from 0.3.0 to 0.9.2. - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@5882f13...4da5165) --- updated-dependencies: - dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml dependency-version: 0.9.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
|
PR: #35 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/so/+/148042 |
…ifecycle.yaml from 0.3.0 to 0.9.2 ## Release notes Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases. v0.9.2 🐛 Bug Fixes 🐛 Fix(scorecard): Hard-code the scan runner label @ModeSevenIndustrialSolutions (#116) 🎓 Code Quality 🎓 Test: Assert submodule content reaches both scans @ModeSevenIndustrialSolutions (#114) Links Submit bugs/feature requests v0.9.1 🐛 Bug Fixes 🐛 Fix(ci): Repin maven-xml-settings-action v0.1.1 @ModeSevenIndustrialSolutions (#118) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#117) Docs: Record why the Go SBOM stays on cyclonedx-gomod @ModeSevenIndustrialSolutions (#115) CI(actions): Bump github/codeql-action/upload-sarif from 4.38.0 to 4.38.1 @dependabot[bot] (#119) CI(actions): Bump lfreleng-actions/maven-build-action from 0.4.2 to 0.4.3 @dependabot[bot] (#120) CI(actions): Bump lfreleng-actions/harden-runner-block-action from 0.12.1 to 0.12.2 @dependabot[bot] (#121) CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.3.1 to 0.4.0 @dependabot[bot] (#122) CI(actions): Bump lfreleng-actions/build-metadata-action from 0.8.0 to 0.8.2 @dependabot[bot] (#123) CI(actions): Bump github/codeql-action/analyze from 4.38.0 to 4.38.1 @dependabot[bot] (#124) CI(actions): Bump lfreleng-actions/sonatype-lifecycle-scan-action from 0.2.1 to 0.2.2 @dependabot[bot] (#125) CI(actions): Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 @dependabot[bot] (#126) CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.3.1 to 0.4.0 @dependabot[bot] (#127) CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.2 to 0.5.3 @dependabot[bot] (#128) CI(actions): Bump github/codeql-action/init from 4.38.0 to 4.38.1 @dependabot[bot] (#129) CI(actions): Bump lfreleng-actions/sonarqube-cloud-scan-action from 1.6.0 to 1.6.1 @dependabot[bot] (#130) Links Submit bugs/feature requests v0.9.0 ✨ New Features ✨ Feat: Test lane steps per PR and add Python CLM @ModeSevenIndustrialSolutions (#113) 🔧 Maintenance 🔧 ... (truncated) ## Commits 4da5165 Merge pull request #116 from modeseven-lfreleng-actions/fix/scorecard-publish 81e09a2 Fix(scorecard): Tighten the publish-rule guard b050a69 Fix(scorecard): Hard-code the scan runner label 34374ce Merge pull request #114 from modeseven-lfreleng-actions/test/submodule-scan-c ae96a8d Merge pull request #130 from lfreleng-actions/dependabot/github_actions/lfrel b952d9e Merge pull request #129 from lfreleng-actions/dependabot/github_actions/githu 17e0bd6 Merge pull request #128 from lfreleng-actions/dependabot/github_actions/lfrel d5a60f0 Merge pull request #127 from lfreleng-actions/dependabot/github_actions/lfrel 8becb40 Merge pull request #126 from lfreleng-actions/dependabot/github_actions/astra d184f53 Merge pull request #125 from lfreleng-actions/dependabot/github_actions/lfrel Additional commits viewable in compare view  Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <[email protected]> Change-Id: Ic63d8bae5327484ee3b8dbf8201881bf66e1d93f GitHub-PR: #35 GitHub-Hash: 591706d47880444b Signed-off-by: onap.gh2gerrit <[email protected]>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ Gerrit change URL: https://gerrit.onap.org/r/c/so/+/148042 The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.3.0 to 0.9.2.
Release notes
Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.
... (truncated)
Commits
4da5165Merge pull request #116 from modeseven-lfreleng-actions/fix/scorecard-publish...81e09a2Fix(scorecard): Tighten the publish-rule guardb050a69Fix(scorecard): Hard-code the scan runner label34374ceMerge pull request #114 from modeseven-lfreleng-actions/test/submodule-scan-c...ae96a8dMerge pull request #130 from lfreleng-actions/dependabot/github_actions/lfrel...b952d9eMerge pull request #129 from lfreleng-actions/dependabot/github_actions/githu...17e0bd6Merge pull request #128 from lfreleng-actions/dependabot/github_actions/lfrel...d5a60f0Merge pull request #127 from lfreleng-actions/dependabot/github_actions/lfrel...8becb40Merge pull request #126 from lfreleng-actions/dependabot/github_actions/astra...d184f53Merge pull request #125 from lfreleng-actions/dependabot/github_actions/lfrel...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)