Skip to content

Commit d26dbf5

Browse files
build(deps): bump anchore/scan-action from 7.3.2 to 7.4.0 (#1121)
Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 7.3.2 to 7.4.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/anchore/scan-action/releases">anchore/scan-action's releases</a>.</em></p> <blockquote> <h2>v7.4.0</h2> <ul> <li>chore: update to node 24 (<a href="https://redirect.github.com/anchore/scan-action/issues/629">#629</a>) [<a href="https://github.com/kzantow"><code>@​kzantow</code></a>]</li> <li>fix(dev): move to esbuild (<a href="https://redirect.github.com/anchore/scan-action/issues/601">#601</a>) [<a href="https://github.com/willmurphyscode"><code>@​willmurphyscode</code></a>]</li> <li>chore: update to ES modules + update <code>@actions/*</code> (<a href="https://redirect.github.com/anchore/scan-action/issues/595">#595</a>) [<a href="https://github.com/kzantow"><code>@​kzantow</code></a>]</li> </ul> <h2>⬆️ Dependencies</h2> <ul> <li>chore(deps): update Grype to v0.110.0 (<a href="https://redirect.github.com/anchore/scan-action/issues/618">#618</a>) [@<a href="https://github.com/apps/anchore-actions-token-generator">anchore-actions-token-generator[bot]</a>]</li> <li>chore(deps-dev): bump tar 7.5.11 (<a href="https://redirect.github.com/anchore/scan-action/issues/620">#620</a>) [@<a href="https://github.com/apps/dependabot">dependabot[bot]</a>]</li> <li>chore(deps): bump undici 6.24.1 (<a href="https://redirect.github.com/anchore/scan-action/issues/622">#622</a>) [@<a href="https://github.com/apps/dependabot">dependabot[bot]</a>]</li> <li>chore: bump fast-xml-parser 5.5.7 (<a href="https://redirect.github.com/anchore/scan-action/issues/626">#626</a>) [@<a href="https://github.com/apps/dependabot">dependabot[bot]</a>]</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/anchore/scan-action/commit/e1165082ffb1fe366ebaf02d8526e7c4989ea9d2"><code>e116508</code></a> chore: bump fast-xml-parser from 5.5.6 to 5.5.7 + setup-node (<a href="https://redirect.github.com/anchore/scan-action/issues/631">#631</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/382a23a5be86412134bdf4a65e1a18943e5d31ac"><code>382a23a</code></a> chore(deps): update Grype to v0.110.0 (<a href="https://redirect.github.com/anchore/scan-action/issues/618">#618</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/28982132458e82c788c1b254d367e19d69a896a5"><code>2898213</code></a> chore: update to node 24 (<a href="https://redirect.github.com/anchore/scan-action/issues/629">#629</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/4e1eb5b6d4ff459c3b0ef7f2ea4de674c94d4353"><code>4e1eb5b</code></a> chore: update to modules and bump all deps (required for new <a href="https://github.com/actions"><code>@​actions</code></a> librari...</li> <li><a href="https://github.com/anchore/scan-action/commit/8ed60d1353b11a3d328c30da9f63cacbdd91b37b"><code>8ed60d1</code></a> chore(deps): bump actions/setup-node from 6.2.0 to 6.3.0 (<a href="https://redirect.github.com/anchore/scan-action/issues/617">#617</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/5a271d28d1a95246a5ab1fac675a77692ed468ec"><code>5a271d2</code></a> chore(deps-dev): bump lint-staged from 16.3.1 to 16.3.2 (<a href="https://redirect.github.com/anchore/scan-action/issues/619">#619</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/6d37af257493532b84fda2c1deeac102db78d1dc"><code>6d37af2</code></a> chore(deps-dev): bump jest from 30.2.0 to 30.3.0 (<a href="https://redirect.github.com/anchore/scan-action/issues/625">#625</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/50a8160242150b375f887fa9c071755295719cf6"><code>50a8160</code></a> chore(deps-dev): bump tar from 7.5.10 to 7.5.11 (<a href="https://redirect.github.com/anchore/scan-action/issues/620">#620</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/daeb723982a29db0a021b5fa3af65d08e1f891c8"><code>daeb723</code></a> chore(deps): bump undici from 6.23.0 to 6.24.1 (<a href="https://redirect.github.com/anchore/scan-action/issues/622">#622</a>)</li> <li><a href="https://github.com/anchore/scan-action/commit/6471a7ecdb0c416a386ad58b1064cbc154d0221e"><code>6471a7e</code></a> chore(deps): bump fast-xml-parser from 5.3.6 to 5.5.6 (<a href="https://redirect.github.com/anchore/scan-action/issues/626">#626</a>)</li> <li>Additional commits viewable in <a href="https://github.com/anchore/scan-action/compare/7037fa011853d5a11690026fb85feee79f4c946c...e1165082ffb1fe366ebaf02d8526e7c4989ea9d2">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anchore/scan-action&package-manager=github_actions&previous-version=7.3.2&new-version=7.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 80fe88d commit d26dbf5

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

.github/workflows/serverless-init-vulnerability-scan.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
runs-on: ubuntu-22.04
3636
steps:
3737
- name: Scan latest serverless-init image with grype
38-
uses: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
38+
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
3939
with:
4040
image: "datadog/serverless-init:latest"
4141
only-fixed: true
@@ -44,7 +44,7 @@ jobs:
4444
output-format: table
4545

4646
- name: Scan latest-alpine serverless-init image with grype
47-
uses: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
47+
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
4848
with:
4949
image: "datadog/serverless-init:latest-alpine"
5050
only-fixed: true

.github/workflows/vulnerability-scan.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
runs-on: ubuntu-22.04
3838
steps:
3939
- name: Scan latest release image with grype
40-
uses: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
40+
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
4141
with:
4242
image: "public.ecr.aws/datadog/lambda-extension:latest"
4343
only-fixed: true
@@ -46,7 +46,7 @@ jobs:
4646
output-format: table
4747

4848
- name: Scan latest-alpine release image with grype
49-
uses: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
49+
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
5050
with:
5151
image: "public.ecr.aws/datadog/lambda-extension:latest-alpine"
5252
only-fixed: true

0 commit comments

Comments
 (0)