Skip to content

chore(deps): bump AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml from 1.3.0 to 1.4.1 in the github-actions group - #80

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/github-actions-b8cd05bf93
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/github-actions-b8cd05bf93

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update: AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml.

Updates AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml from 1.3.0 to 1.4.1

Release notes

Sourced from AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml's releases.

v1.4.1

Bugfixes 🛠

Full Changelog

AbsaOSS/organizational-workflows@v1.4.0...v1.4.1

v1.4.0

New Features 🎉

  • Feature: #101 Phase 1: Migrate AquaSec security issues from type:tech-debt to a dedicated type:aquasec label by @​tmikula-dev in #102
    • AquaSec-generated issues are now labelled type:aquasec instead of type:tech-debt (dedicated filterable label)
    • Existing AquaSec issues, including closed ones, are migrated to the new label automatically
  • Feature: #105 Improve sync summary logging: severity breakdowns by @​tmikula-dev in #106
    • Adds extra info about the AquaSec sync actions.
  • Feature: #111 Redesign Teams notification as a single rich Adaptive Card by @​tmikula-dev in #112
    • Every security sync run now posts a single Adaptive Card to a configured Teams webhook, summarizing issue activities

Bugfixes 🛠

  • #94 Publish Docs workflow fails: pinned knowledge-base action manifest has a YAML syntax error by @​oto-macenauer-absa in #95
  • PR: #96 Update slug for security automation documentation by @​tmikula-dev
    • Correcting the URL slug to security-automation instead of org-workflows
  • #99 AquaSec issue bodies are regenerated on every commit to the scanned branch by @​tmikula-dev in #100
    • This fix denies to update the issue body only because the master HEAD changed. This update is done with changing commit HEAD for main branch of the project.
    • #113 Fix Pylint warnings: W1201, W1203, E1101, W0718 by @​tmikula-dev in #114

Documentation 📜

Full Changelog

AbsaOSS/organizational-workflows@v1.3.0...v1.4.0

Commits
  • 277660d fix: don't hard-fail dry-run when Aqua label is missing (#119)
  • 721a78a chore(deps): bump the python-dependencies group across 1 directory with 2 upd...
  • ca6b7a9 chore(deps): bump softprops/action-gh-release (#109)
  • dbe1e00 Solving pylint warnings: W1201, W1203, E1101, W0718 (#114)
  • 648b771 Updating Teams notification Adaptive card (#112)
  • 12a06fb feat: Updated logging for live and dry runs (#106)
  • 025f7b0 feat: Migrate from label type:tech-debt to type:aquasec Phase 1 (#102)
  • 6f74579 fix: No update for security issue body once the master is updated. (#100)
  • 4d0c948 fix(ci): re-pin publish-single-page-docs to knowledge-base v1.0.0 (#108)
  • 6322aa5 chore(deps): bump the python-dependencies group across 1 directory with 3 upd...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated the scheduled security scan workflow to use a newer approved configuration.

…aquasec-scan.yml

Bumps the github-actions group with 1 update: [AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml](https://github.com/absaoss/organizational-workflows).


Updates `AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml` from 1.3.0 to 1.4.1
- [Release notes](https://github.com/absaoss/organizational-workflows/releases)
- [Commits](AbsaOSS/organizational-workflows@ab0b537...277660d)

---
updated-dependencies:
- dependency-name: AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: auto update. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added infrastructure Project setup and deployment no RN No release notes required labels Sep 20, 2026
@dependabot dependabot Bot added infrastructure Project setup and deployment no RN No release notes required labels Sep 20, 2026
@coderabbitai

coderabbitai Bot commented Sep 20, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5a371aee-9bc9-471d-8dca-fdde51f75c08

📥 Commits

Reviewing files that changed from the base of the PR and between 299046c and bb5a226.

📒 Files selected for processing (1)
  • .github/workflows/aquasec-night-scan.yml

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


Walkthrough

The Aquasec night-scan job now references commit 277660de348163abf9855fcedfcfa9ec0da1c176 of the reusable organizational workflow.

Changes

Aquasec scan workflow

Layer / File(s) Summary
Update Aquasec workflow reference
.github/workflows/aquasec-night-scan.yml
The reusable Aquasec scan workflow reference changed from ab0b5372e2ec35be6f9bccf364dd024486e59bc1 to 277660de348163abf9855fcedfcfa9ec0da1c176.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the GitHub Actions dependency, the version change from 1.3.0 to 1.4.1, and the Dependabot update scope. It matches the pull request changes.
Description check ✅ Passed The description clearly explains the dependency update and includes relevant release notes and commit details. It does not use the template headings or include a Related issue section, but it remains …
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

A rabbit reads each line,
The patch grows clear beneath the moon,
Small changes hop in place,
Tests guard the garden path,
Reviews bloom before the dawn.

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infrastructure Project setup and deployment no RN No release notes required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants