Skip to content

chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.3 to 1.12.5 - #301

Closed
dependabot[bot] wants to merge 1 commit into
betafrom
dependabot/github_actions/huntridge-labs/argus/dot-github/workflows/reusable-security-hardening.yml-1.12.5
Closed

dependabot[bot] wants to merge 1 commit into
betafrom
dependabot/github_actions/huntridge-labs/argus/dot-github/workflows/reusable-security-hardening.yml-1.12.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.3 to 1.12.5.

Release notes

Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's releases.

Release 1.12.5

1.12.5 (2026-09-15)

Bug Fixes

  • containers: re-pin clamav 1.5.4 digest after upstream re-push (#426) (552b9fa)

Maintenance

  • deps: bump cz-emoji-conventional (#424) (677caae)
  • deps: bump the docker-all group across 2 directories with 2 updates (#425) (13d1e03)
  • deps: Update dependency opengrep to v1.30.0 (#423) (d1fc70b)
  • deps: Update github-actions-minor-patch (#383) (2cfbc4d)
  • deps: Update hashicorp/terraform Docker tag to v1.16.1 (#422) (3a470ad)

Release 1.12.4

1.12.4 (2026-09-08)

Bug Fixes

  • containers: re-pin clamav digest after upstream tag re-push (#420) (ee83fe8)

Maintenance

  • deps: bump conventional-changelog-conventionalcommits (#414) (b8da3af)
  • deps: bump node (#415) (ca3f188)
  • deps: update coverage requirement in the pip-all group (#419) (8ae0f54)
  • deps: update tool versions and container image pins together (#421) (8955c51)
Changelog

Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

1.12.5 (2026-09-15)

Bug Fixes

  • containers: re-pin clamav 1.5.4 digest after upstream re-push (#426) (552b9fa)

Security Tools

  • deps: Update dependency opengrep to v1.30.0 (#423) (d1fc70b)

Dependencies

  • deps: bump cz-emoji-conventional (#424) (677caae)
  • deps: bump the docker-all group across 2 directories with 2 updates (#425) (13d1e03)
  • deps: Update github-actions-minor-patch (#383) (2cfbc4d)
  • deps: Update hashicorp/terraform Docker tag to v1.16.1 (#422) (3a470ad)

1.12.4 (2026-09-08)

Bug Fixes

  • containers: re-pin clamav digest after upstream tag re-push (#420) (ee83fe8)

Dependencies

  • deps: bump conventional-changelog-conventionalcommits (#414) (b8da3af)
  • deps: bump node (#415) (ca3f188)
  • deps: update coverage requirement in the pip-all group (#419) (8ae0f54)
  • deps: update tool versions and container image pins together (#421) (8955c51)

1.12.3 (2026-08-26)

Bug Fixes

  • ci: only report a pin stale when upstream is actually newer (#413) (c7309cf), closes #174-1
  • containers: refresh clamav 1.5.4 digest after upstream tag re-push (#410) (4ba8286)
  • scanner-codeql: stop summary crash on empty counts and fail the severity gate closed (#409) (20d7f1e)

Security Tools

... (truncated)

Commits
  • 6040db4 chore(release): 1.12.5
  • 2cfbc4d chore(deps): Update github-actions-minor-patch (#383)
  • 13d1e03 chore(deps): bump the docker-all group across 2 directories with 2 updates (#...
  • d1fc70b chore(deps): Update dependency opengrep to v1.30.0 (#423)
  • 677caae chore(deps): bump cz-emoji-conventional (#424)
  • 3a470ad chore(deps): Update hashicorp/terraform Docker tag to v1.16.1 (#422)
  • 552b9fa fix(containers): re-pin clamav 1.5.4 digest after upstream re-push (#426)
  • cc7ef8e chore(release): 1.12.4
  • 8955c51 chore(deps): update tool versions and container image pins together (#421)
  • 8ae0f54 chore(deps): update coverage requirement in the pip-all group (#419)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…ity-hardening.yml

Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.5.
- [Release notes](https://github.com/huntridge-labs/argus/releases)
- [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md)
- [Commits](huntridge-labs/argus@9b444d8...6040db4)

---
updated-dependencies:
- dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml
  dependency-version: 1.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown
Contributor

🛡️ Security Hardening Pipeline Results

Branch: dependabot/github_actions/huntridge-labs/argus/dot-github/workflows/reusable-security-hardening.yml-1.12.5
Commit: 8fb1f6e

Workflow Run: 451
Branch: dependabot/github_actions/huntridge-labs/argus/dot-github/workflows/reusable-security-hardening.yml-1.12.5
Commit: 8fb1f6e

Scan Status

Scanner Status
bandit ⏭️ skipped
checkov ⏭️ skipped
clamav ⏭️ skipped
codeql ✅ PASS
container ⏭️ skipped
dependency-review ✅ PASS
gitleaks ✅ PASS
grype ⏭️ skipped
lint ⏭️ skipped
opengrep ⏭️ skipped
osv ✅ PASS
sbom ⏭️ skipped
supply-chain ⏭️ skipped
trivy-container ⏭️ skipped
trivy-iac ⏭️ skipped
zap ⏭️ skipped

✅ All enabled scanners completed successfully.

Summaries Collected: 4

Scanner Results

🔬 CodeQL SAST (Javascript)

Status: Completed

Findings Summary

Critical High Medium Low Total
0 0 0 0 0

No security findings detected for Javascript.

Artifacts: CodeQL Reports (Javascript)

🔗 Dependency Review

Status: ✅ No issues found

No vulnerable or license-violating dependencies detected in this PR.
📋 View full report

🔑 Gitleaks (Secrets)

No 🔑 Gitleaks (Secrets) findings summary was produced.

📦 OSV (Dependencies)

No 📦 OSV (Dependencies) findings summary was produced.


Generated by Argus


Generated by Argus

@eFAILution
eFAILution changed the base branch from main to beta September 21, 2026 17:57
eFAILution added a commit that referenced this pull request Sep 21, 2026
Rebuilds #301 against beta, which is already on 1.12.4 (#293) while main
is still on 1.12.3, so the one-line change conflicted on retarget.

SHA 6040db47 verified as the 1.12.5 tag in huntridge-labs/argus. The
reusable workflow's own diff across 1.12.4..1.12.5 is only its internal
@1.12.4 -> @1.12.5 job references; the release otherwise carries
dependency bumps and a clamav digest re-pin (argus#426).

Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
@eFAILution

Copy link
Copy Markdown
Owner

Rebuilt against beta and merged: #306 (ae88710).

This was opened against main, which trails beta by everything not yet released, so it duplicated versions beta already carried and its diff no longer applied on retarget.

Dependabot reads .github/dependabot.yml from the default branch, so the target-branch: "beta" added in #296 has no effect until it reaches main with the next release. Until then these will keep opening here.

@eFAILution eFAILution closed this Sep 21, 2026
@eFAILution
eFAILution deleted the dependabot/github_actions/huntridge-labs/argus/dot-github/workflows/reusable-security-hardening.yml-1.12.5 branch September 21, 2026 18:04
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant