chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.3 to 1.12.5 - #301
Conversation
…ity-hardening.yml Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.5. - [Release notes](https://github.com/huntridge-labs/argus/releases) - [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md) - [Commits](huntridge-labs/argus@9b444d8...6040db4) --- updated-dependencies: - dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml dependency-version: 1.12.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
🛡️ Security Hardening Pipeline ResultsBranch: Workflow Run: 451 Scan Status
Summaries Collected: 4 Scanner Results🔬 CodeQL SAST (Javascript)Status: Completed Findings Summary
No security findings detected for Javascript. Artifacts: CodeQL Reports (Javascript) 🔗 Dependency ReviewStatus: ✅ No issues found No vulnerable or license-violating dependencies detected in this PR. 🔑 Gitleaks (Secrets)No 🔑 Gitleaks (Secrets) findings summary was produced. 📦 OSV (Dependencies)No 📦 OSV (Dependencies) findings summary was produced. Generated by Argus Generated by Argus |
Rebuilds #301 against beta, which is already on 1.12.4 (#293) while main is still on 1.12.3, so the one-line change conflicted on retarget. SHA 6040db47 verified as the 1.12.5 tag in huntridge-labs/argus. The reusable workflow's own diff across 1.12.4..1.12.5 is only its internal @1.12.4 -> @1.12.5 job references; the release otherwise carries dependency bumps and a clamav digest re-pin (argus#426). Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
|
Rebuilt against This was opened against Dependabot reads |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.3 to 1.12.5.
Release notes
Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's releases.
Changelog
Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's changelog.
... (truncated)
Commits
6040db4chore(release): 1.12.52cfbc4dchore(deps): Update github-actions-minor-patch (#383)13d1e03chore(deps): bump the docker-all group across 2 directories with 2 updates (#...d1fc70bchore(deps): Update dependency opengrep to v1.30.0 (#423)677caaechore(deps): bump cz-emoji-conventional (#424)3a470adchore(deps): Update hashicorp/terraform Docker tag to v1.16.1 (#422)552b9fafix(containers): re-pin clamav 1.5.4 digest after upstream re-push (#426)cc7ef8echore(release): 1.12.48955c51chore(deps): update tool versions and container image pins together (#421)8ae0f54chore(deps): update coverage requirement in the pip-all group (#419)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)