Repository navigation
chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.6 to 1.12.7 - #340
Conversation
…ity-hardening.yml Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.6 to 1.12.7. - [Release notes](https://github.com/huntridge-labs/argus/releases) - [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md) - [Commits](huntridge-labs/argus@3fb133a...309e971) --- updated-dependencies: - dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml dependency-version: 1.12.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
🛡️ Security Hardening Pipeline ResultsBranch: Workflow Run: 539 Scan Status
Summaries Collected: 4 Scanner Results🔬 CodeQL SAST (Javascript)Status: Completed Findings Summary
No security findings detected for Javascript. Artifacts: CodeQL Reports (Javascript) 🔗 Dependency ReviewStatus: ✅ No issues found No vulnerable or license-violating dependencies detected in this PR. 🔑 Gitleaks (Secrets)No 🔑 Gitleaks (Secrets) findings summary was produced. 📦 OSV (Dependencies)No 📦 OSV (Dependencies) findings summary was produced. Generated by Argus Generated by Argus |
Bumps huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.6 to 1.12.7.
Release notes
Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's releases.
Changelog
Sourced from huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml's changelog.
... (truncated)
Commits
309e971chore(release): 1.12.71779318chore(deps): bump the docker-all group across 1 directory with 2 updates (#451)0c231fachore(deps): bump the npm-minor-patch group across 1 directory with 3 updates...a50e85bchore(deps): update python-slugify requirement (#440)3f52427chore(deps): update grype, syft, checkov and terraform pins (#450)98456e0chore(deps): Update github-actions-minor-patch (#435)9105252fix(core): apply each tool's ignore file to that tool only (#447)9fae8bachore: remove the stale package-lock.json; pnpm-lock.yaml is the lockfile (#446)bb6acedfix(deps): raise fast-uri, ip-address and undici override floors (#445)9f57edafix(examples): pin third-party actions; annotate Argus self-references (#444)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)