Skip to content

Bump lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.3.0 to 0.9.2 - #35

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.2
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.3.0 to 0.9.2.

Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.9.2

Downloads for this release

🐛 Bug Fixes 🐛

🎓 Code Quality 🎓

Links

v0.9.1

Downloads for this release

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

Links

v0.9.0

Downloads for this release

✨ New Features ✨

🔧 Maintenance 🔧

... (truncated)

Commits
  • 4da5165 Merge pull request #116 from modeseven-lfreleng-actions/fix/scorecard-publish...
  • 81e09a2 Fix(scorecard): Tighten the publish-rule guard
  • b050a69 Fix(scorecard): Hard-code the scan runner label
  • 34374ce Merge pull request #114 from modeseven-lfreleng-actions/test/submodule-scan-c...
  • ae96a8d Merge pull request #130 from lfreleng-actions/dependabot/github_actions/lfrel...
  • b952d9e Merge pull request #129 from lfreleng-actions/dependabot/github_actions/githu...
  • 17e0bd6 Merge pull request #128 from lfreleng-actions/dependabot/github_actions/lfrel...
  • d5a60f0 Merge pull request #127 from lfreleng-actions/dependabot/github_actions/lfrel...
  • 8becb40 Merge pull request #126 from lfreleng-actions/dependabot/github_actions/astra...
  • d184f53 Merge pull request #125 from lfreleng-actions/dependabot/github_actions/lfrel...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…ifecycle.yaml

Bumps [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows) from 0.3.0 to 0.9.2.
- [Release notes](https://github.com/lfreleng-actions/security-workflows/releases)
- [Commits](lfreleng-actions/security-workflows@5882f13...4da5165)

---
updated-dependencies:
- dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

PR: #35
Mode: squash
Topic: GH-so-35
Change-Ids:
Ic63d8bae5327484ee3b8dbf8201881bf66e1d93f
Digest: 84a61edac224
GitHub-Hash: 591706d47880444b

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/so/+/148042

onap-github pushed a commit that referenced this pull request Oct 7, 2026
…ifecycle.yaml from 0.3.0 to 0.9.2

## Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.9.2

🐛 Bug Fixes 🐛

Fix(scorecard): Hard-code the scan runner label @​ModeSevenIndustrialSolutions (#116)

🎓 Code Quality 🎓

Test: Assert submodule content reaches both scans @​ModeSevenIndustrialSolutions (#114)

Links

Submit bugs/feature requests

v0.9.1

🐛 Bug Fixes 🐛

Fix(ci): Repin maven-xml-settings-action v0.1.1 @​ModeSevenIndustrialSolutions (#118)

🔧 Maintenance 🔧

Chore: pre-commit autoupdate @pre-commit-ci[bot] (#117)
Docs: Record why the Go SBOM stays on cyclonedx-gomod @​ModeSevenIndustrialSolutions (#115)
CI(actions): Bump github/codeql-action/upload-sarif from 4.38.0 to 4.38.1 @dependabot[bot] (#119)
CI(actions): Bump lfreleng-actions/maven-build-action from 0.4.2 to 0.4.3 @dependabot[bot] (#120)
CI(actions): Bump lfreleng-actions/harden-runner-block-action from 0.12.1 to 0.12.2 @dependabot[bot] (#121)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.3.1 to 0.4.0 @dependabot[bot] (#122)
CI(actions): Bump lfreleng-actions/build-metadata-action from 0.8.0 to 0.8.2 @dependabot[bot] (#123)
CI(actions): Bump github/codeql-action/analyze from 4.38.0 to 4.38.1 @dependabot[bot] (#124)
CI(actions): Bump lfreleng-actions/sonatype-lifecycle-scan-action from 0.2.1 to 0.2.2 @dependabot[bot] (#125)
CI(actions): Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 @dependabot[bot] (#126)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.3.1 to 0.4.0 @dependabot[bot] (#127)
CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.2 to 0.5.3 @dependabot[bot] (#128)
CI(actions): Bump github/codeql-action/init from 4.38.0 to 4.38.1 @dependabot[bot] (#129)
CI(actions): Bump lfreleng-actions/sonarqube-cloud-scan-action from 1.6.0 to 1.6.1 @dependabot[bot] (#130)

Links

Submit bugs/feature requests

v0.9.0

✨ New Features ✨

Feat: Test lane steps per PR and add Python CLM @​ModeSevenIndustrialSolutions (#113)

🔧 Maintenance 🔧

... (truncated)

## Commits

4da5165 Merge pull request #116 from modeseven-lfreleng-actions/fix/scorecard-publish
81e09a2 Fix(scorecard): Tighten the publish-rule guard
b050a69 Fix(scorecard): Hard-code the scan runner label
34374ce Merge pull request #114 from modeseven-lfreleng-actions/test/submodule-scan-c
ae96a8d Merge pull request #130 from lfreleng-actions/dependabot/github_actions/lfrel
b952d9e Merge pull request #129 from lfreleng-actions/dependabot/github_actions/githu
17e0bd6 Merge pull request #128 from lfreleng-actions/dependabot/github_actions/lfrel
d5a60f0 Merge pull request #127 from lfreleng-actions/dependabot/github_actions/lfrel
8becb40 Merge pull request #126 from lfreleng-actions/dependabot/github_actions/astra
d184f53 Merge pull request #125 from lfreleng-actions/dependabot/github_actions/lfrel
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Change-Id: Ic63d8bae5327484ee3b8dbf8201881bf66e1d93f
GitHub-PR: #35
GitHub-Hash: 591706d47880444b
Signed-off-by: onap.gh2gerrit <[email protected]>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

Gerrit change URL: https://gerrit.onap.org/r/c/so/+/148042

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Oct 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/lfreleng-actions/security-workflows/dot-github/workflows/sonatype-lifecycle.yaml-0.9.2 branch October 7, 2026 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants