build(deps): Bump hashicorp/vault-action from 3 to 3.4.0#999
build(deps): Bump hashicorp/vault-action from 3 to 3.4.0#999dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [hashicorp/vault-action](https://github.com/hashicorp/vault-action) from 3 to 3.4.0. - [Release notes](https://github.com/hashicorp/vault-action/releases) - [Changelog](https://github.com/hashicorp/vault-action/blob/main/CHANGELOG.md) - [Commits](hashicorp/vault-action@v3...v3.4.0) --- updated-dependencies: - dependency-name: hashicorp/vault-action dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
🤖 Cursor Dependency AnalysisSupply-Chain Malware ReviewVerifying how Verdict: benign Evidence
Scanner vs manual read: The volume of heuristic matches disagrees with a malware conclusion—they are overwhelmingly bundled-library noise and pattern overlap ( Practical merge check: Confirm the PR diff only updates the workflow Compatibility AnalysisSearching the repo for 1) Where it’s used
In each case: Vault auth is done first with The 2) Overlap with release-note changes
3) Risks / unknowns
4) RecommendationMerge. This is a same-major bump with security and bug fixes; current workflows use a narrow, stable pattern that does not hinge on the changed areas (JWT/AppRole PKI, wildcards). Optionally watch the next Crowdin or review-deploy workflow run after merge for confidence. Malware Scan Summary
Top findings
|
Bumps hashicorp/vault-action from 3 to 3.4.0.
Release notes
Sourced from hashicorp/vault-action's releases.
Changelog
Sourced from hashicorp/vault-action's changelog.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Low Risk
Low risk dependency pin in GitHub Actions workflows; behavior should be unchanged aside from upstream bugfix/security improvements in Vault secret fetching.
Overview
Bumps
hashicorp/vault-actionfromv3tov3.4.0across the workflows that read secrets from Vault (Crowdin pull/push and review app deploy/delete). No other workflow logic is changed.Reviewed by Cursor Bugbot for commit 5b06504. Bugbot is set up for automated code reviews on this repo. Configure here.