Repository navigation
Bump lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.5.0 to 0.7.0 - #39
Conversation
…ifecycle.yaml Bumps [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows) from 0.5.0 to 0.7.0. - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@9219040...bdcf7d8) --- updated-dependencies: - dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #39 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/usecase-ui/+/147613 |
…ifecycle.yaml from 0.5.0 to 0.7.0 ## Release notes Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases. v0.7.0 ✨ New Features ✨ Feat: Adopt go.list as the Go CLM scan target @ModeSevenIndustrialSolutions (#90) Feat: Assert coverage paths reached the analysis @ModeSevenIndustrialSolutions (#89) 🔧 Maintenance 🔧 CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.2.1 to 0.2.2 @dependabot[bot] (#92) CI(actions): Bump lfreleng-actions/sonatype-lifecycle-scan-action from 0.2.0 to 0.2.1 @dependabot[bot] (#93) CI(actions): Bump github/codeql-action/init from 4.37.8 to 4.37.9 @dependabot[bot] (#94) CI(actions): Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#95) CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.1 to 0.2.2 @dependabot[bot] (#96) CI(actions): Bump github/codeql-action/upload-sarif from 4.37.8 to 4.37.9 @dependabot[bot] (#97) CI(actions): Bump github/codeql-action/analyze from 4.37.8 to 4.37.9 @dependabot[bot] (#98) Links Submit bugs/feature requests v0.6.1 🎓 Code Quality 🎓 CI: Bump allow-list pin and quieten repeat summaries @ModeSevenIndustrialSolutions (#91) Links Submit bugs/feature requests v0.6.0 ✨ New Features ✨ Feat: Expose lane outputs and assert on them @ModeSevenIndustrialSolutions (#82) Links Submit bugs/feature requests v0.5.3 🔧 Maintenance 🔧 CI(actions): Bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8 @dependabot[bot] (#83) CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.0.5 to 0.2.1 @dependabot[bot] (#88) CI(actions): Bump github/codeql-action/analyze from 4.37.7 to 4.37.8 @dependabot[bot] (#86) CI(actions): Bump github/codeql-action/init from 4.37.7 to 4.37.8 @dependabot[bot] (#85) ... (truncated) ## Commits bdcf7d8 Merge pull request #89 from modeseven-lfreleng-actions/feat/assert-coverage-f 60fe804 Merge pull request #90 from modeseven-lfreleng-actions/feat/go-list-scan-target a8b7890 Merge pull request #98 from lfreleng-actions/dependabot/github_actions/github 039b81a Merge pull request #97 from lfreleng-actions/dependabot/github_actions/github 6fcfcde Merge pull request #96 from lfreleng-actions/dependabot/github_actions/lfrele 041aa80 Merge pull request #95 from lfreleng-actions/dependabot/github_actions/step-s c4c3891 Merge pull request #94 from lfreleng-actions/dependabot/github_actions/github 7bb43b6 Merge pull request #93 from lfreleng-actions/dependabot/github_actions/lfrele 7fa374e Merge pull request #92 from lfreleng-actions/dependabot/github_actions/lfrele 60082a1 CI(actions): Bump github/codeql-action/analyze from 4.37.8 to 4.37.9 Additional commits viewable in compare view  Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Ia494c98c1aa5673b35440015baccaf86688f3d37 GitHub-PR: #39 GitHub-Hash: d98376749e750a34 Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.5.0 to 0.7.0.
Release notes
Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.
... (truncated)
Commits
bdcf7d8Merge pull request #89 from modeseven-lfreleng-actions/feat/assert-coverage-f...60fe804Merge pull request #90 from modeseven-lfreleng-actions/feat/go-list-scan-targeta8b7890Merge pull request #98 from lfreleng-actions/dependabot/github_actions/github...039b81aMerge pull request #97 from lfreleng-actions/dependabot/github_actions/github...6fcfcdeMerge pull request #96 from lfreleng-actions/dependabot/github_actions/lfrele...041aa80Merge pull request #95 from lfreleng-actions/dependabot/github_actions/step-s...c4c3891Merge pull request #94 from lfreleng-actions/dependabot/github_actions/github...7bb43b6Merge pull request #93 from lfreleng-actions/dependabot/github_actions/lfrele...7fa374eMerge pull request #92 from lfreleng-actions/dependabot/github_actions/lfrele...60082a1CI(actions): Bump github/codeql-action/analyze from 4.37.8 to 4.37.9Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)