Releases: advanced-security/reusable-workflows
Releases · advanced-security/reusable-workflows
v0.3.4
Immutable
release. Only release title and notes can be modified.
- no changes - just for testing downstream handling of an update ... sorry for the noise!
Full Changelog: v0.3.3...v0.3.4
v0.3.3
Immutable
release. Only release title and notes can be modified.
What's Changed
- deps: bump the production-dependencies group with 5 updates by @dependabot[bot] in #90
- fix: include prereleases when resolving bump base version by @felickz in #92
Full Changelog: v0.3.2...v0.3.3
v0.3.2
Immutable
release. Only release title and notes can be modified.
What's Changed
Full Changelog: v0.3.1...v0.3.2
v0.3.1
Immutable
release. Only release title and notes can be modified.
What's Changed
- feat(ci): Add Opengrep as a reusable workflow by @GeekMasher in #41
- feat: Update sec-opengrep.yml by @GeekMasher in #43
- Update sec-opengrep.yml by @adrienpessu in #44
- feat(ci): Update codeql-iac.yml by @GeekMasher in #45
- deps: bump the production-dependencies group with 8 updates by @dependabot[bot] in #42
- Update container-publish to use build provenance attestations by @GeekMasher in #46
- feat: Update opengrep pinned version by @GeekMasher in #50
- Update ql-for-ql to make it update the SARIF file tool name to be
CodeQL-Extractorand overwrite the file by @GeekMasher in #49 - fix: Update codeql-ql.yml by @GeekMasher in #51
- Container Updates by @GeekMasher in #47
- feat: Update codeql-dynamic docs and on events by @GeekMasher in #54
- Fix Code Injection issues by @GeekMasher in #56
- sec-opengrep.yml to pull latest by @felickz in #62
- deps: bump the production-dependencies group across 1 directory with 17 updates by @dependabot[bot] in #67
- deps: bump the production-dependencies group across 1 directory with 7 updates by @dependabot[bot] in #71
- deps: bump the production-dependencies group across 1 directory with 5 updates by @dependabot[bot] in #75
- deps: bump the production-dependencies group across 1 directory with 13 updates by @dependabot[bot] in #84
- Make retry-on-snapshot-warnings opt-in via workflow_call inputs by @Copilot in #76
- Add snapshot wait by @felickz in #34
- refactor: make release.yml a pure reusable workflow with bump support by @felickz in #86
- feat: add opt-in README SHA update to release workflow by @felickz in #87
New Contributors
- @Copilot made their first contribution in #76
Full Changelog: v0.3.0...v0.3.1
v0.2.1
Immutable
release. Only release title and notes can be modified.
Full Changelog: v0.2.0...v0.2.1
v0.2.0
Immutable
release. Only release title and notes can be modified.
What's Changed
- fix: Update container workflow by @GeekMasher in #37
- Python workflows by @GeekMasher in #35
- Release Workflows by @GeekMasher in #36
Full Changelog: 0.1.0...v0.2.0
v0.3.0
What's Changed
- feat(ci): Improve Python concurrency + Python 3.13 by @GeekMasher in #38
- Add initial QL for QL support by @GeekMasher in #39
Full Changelog: v0.2.0...v0.3.0
v0.1.0
What's Changed
- Add Container build and release workflow by @GeekMasher in #5
- build(deps): bump actions/checkout from 3 to 4 by @dependabot in #7
- build(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0 by @dependabot in #6
- feat(docs): Add Wiki Publishing Action by @GeekMasher in #8
- Labeler to auto-download default config file by @GeekMasher in #4
- Update DepReview to use config file by @GeekMasher in #3
- feat: Update dependabot.yml by @GeekMasher in #10
- feat: CodeQL set dynamically languages by @GeekMasher in #12
- feat: Add CodeQL IaC by @GeekMasher in #11
- Update dependabot.yml by @GeekMasher in #13
- deps: bump sigstore/cosign-installer from 3.4.0 to 3.5.0 in the production-dependencies group by @dependabot in #15
- Use repo ref versus downloading config file by @GeekMasher in #16
- deps: bump actions/github-script from 4 to 7 in the production-dependencies group by @dependabot in #17
- Workflow automations on self by @felickz in #19
- Update path to Dep Review file by @GeekMasher in #21
- fix: Update dependency-review.yml by @GeekMasher in #22
- fix: Update codeql-iac.yml by @GeekMasher in #23
- deps: bump docker/login-action from 3.1.0 to 3.2.0 in the production-dependencies group by @dependabot in #24
- Add workflow for language-based PR assignment by @adrienpessu in #27
- deps: bump the production-dependencies group with 2 updates by @dependabot in #26
- deps: bump the production-dependencies group across 1 directory with 2 updates by @dependabot in #30
- feat(ci): Update docs for dep-review by @GeekMasher in #31
New Contributors
- @GeekMasher made their first contribution in #5
- @dependabot made their first contribution in #7
- @felickz made their first contribution in #19
- @adrienpessu made their first contribution in #27
Full Changelog: https://github.com/advanced-security/reusable-workflows/commits/0.1.0