Skip to content

chore(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 in the minor-and-patch group across 1 directory - #66

Merged
rodri-oliveira-dev merged 2 commits into
mainfrom
dependabot/github_actions/minor-and-patch-d305a0f91a
Sep 28, 2026
Merged

rodri-oliveira-dev merged 2 commits into
mainfrom
dependabot/github_actions/minor-and-patch-d305a0f91a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 1 update in the / directory: anchore/sbom-action.

Updates anchore/sbom-action from 0.24.0 to 0.24.2

Release notes

Sourced from anchore/sbom-action's releases.

v0.24.2

Added Features

Additional Changes

(Full Changelog)

Commits
  • 3ad7283 ops: update write permissions for release (#723)
  • 31f5287 chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#724)
  • aa80c8c chore(deps): update Syft to latest release (#722)
  • 74b54e9 chore(deps): bump lodash from 4.17.23 to 4.18.1 (#623)
  • 6b92ff5 chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#721)
  • 4f8983b chore(deps-dev): bump typescript-eslint from 8.65.0 to 8.67.0 (#719)
  • 10f27f4 chore(deps-dev): bump eslint from 10.5.0 to 10.8.1 (#720)
  • 249403a chore(deps-dev): bump @​types/node from 26.1.0 to 26.2.0 (#718)
  • cbf8daa chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#693)
  • 6afc793 fix: pin syft install.sh to the release tag being installed (#716)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: rodri-oliveira-dev/ReliableWebhooks/https://raw.githubusercontent.com/rodri-oliveira-dev/.github/main/coderabbit-templates/dotnet-library.yaml (via .coderabbit.yaml)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: af149760-2a2f-4e7f-91e0-3db020f101f0

📥 Commits

Reviewing files that changed from the base of the PR and between c95f2ce and bd58937.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 97f2ac8a-ca86-482b-b8d6-966a365482c0

📥 Commits

Reviewing files that changed from the base of the PR and between ea474da and 11a1fe7.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

Limit details: You’ve used all 10 included reviews currently available.


📝 Walkthrough

Walkthrough

The release workflow updates the package SBOM generation step from anchore/sbom-action v0.24.0 to v0.24.2.

Changes

Release SBOM generation

Layer / File(s) Summary
Update the pinned SBOM action
.github/workflows/release.yml
The package SBOM generation step now uses the pinned anchore/sbom-action v0.24.2 commit.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: rodri-oliveira-dev

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the dependency update and includes release notes, but it omits the required Related issue, Validation, and Checklist sections. It is therefore largely incomplete against the r… Add the required Summary, Related issue, Validation, and Checklist sections. State the issue reference or explain that none applies, record the validation commands and results or explain why they are not needed, and complete each checklist …
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the dependency and the exact version change from 0.24.0 to 0.24.2. It accurately summarizes the primary change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the dependency update and includes release notes, but it omits the required Related issue, Validation, and Checklist sections. It is therefore largely incomplete against the repository template.

Resolution

Add the required Summary, Related issue, Validation, and Checklist sections. State the issue reference or explain that none applies, record the validation commands and results or explain why they are not needed, and complete each checklist item, including the rationale for any skipped tests or changelog entry.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

Bumps the minor-and-patch group with 1 update in the / directory: [anchore/sbom-action](https://github.com/anchore/sbom-action).


Updates `anchore/sbom-action` from 0.24.0 to 0.24.2
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@e22c389...3ad7283)

---
updated-dependencies:
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 in the minor-and-patch group chore(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 in the minor-and-patch group across 1 directory Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/minor-and-patch-d305a0f91a branch from 11a1fe7 to c95f2ce Compare September 28, 2026 12:39
@rodri-oliveira-dev
rodri-oliveira-dev merged commit ada5f90 into main Sep 28, 2026
11 checks passed
@rodri-oliveira-dev
rodri-oliveira-dev deleted the dependabot/github_actions/minor-and-patch-d305a0f91a branch September 28, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant