Skip to content

Releases: advanced-security/reusable-workflows

v0.3.4

21 May 18:35
Immutable release. Only release title and notes can be modified.
479412f

Choose a tag to compare

  • no changes - just for testing downstream handling of an update ... sorry for the noise!

Full Changelog: v0.3.3...v0.3.4

v0.3.3

21 May 16:35
Immutable release. Only release title and notes can be modified.
fc65a06

Choose a tag to compare

What's Changed

  • deps: bump the production-dependencies group with 5 updates by @dependabot[bot] in #90
  • fix: include prereleases when resolving bump base version by @felickz in #92

Full Changelog: v0.3.2...v0.3.3

v0.3.2

18 May 20:23
Immutable release. Only release title and notes can be modified.
1993dd6

Choose a tag to compare

What's Changed

  • fix: resolve security review findings by @felickz in #89

Full Changelog: v0.3.1...v0.3.2

v0.3.1

18 May 18:54
Immutable release. Only release title and notes can be modified.
811381e

Choose a tag to compare

What's Changed

  • feat(ci): Add Opengrep as a reusable workflow by @GeekMasher in #41
  • feat: Update sec-opengrep.yml by @GeekMasher in #43
  • Update sec-opengrep.yml by @adrienpessu in #44
  • feat(ci): Update codeql-iac.yml by @GeekMasher in #45
  • deps: bump the production-dependencies group with 8 updates by @dependabot[bot] in #42
  • Update container-publish to use build provenance attestations by @GeekMasher in #46
  • feat: Update opengrep pinned version by @GeekMasher in #50
  • Update ql-for-ql to make it update the SARIF file tool name to be CodeQL-Extractor and overwrite the file by @GeekMasher in #49
  • fix: Update codeql-ql.yml by @GeekMasher in #51
  • Container Updates by @GeekMasher in #47
  • feat: Update codeql-dynamic docs and on events by @GeekMasher in #54
  • Fix Code Injection issues by @GeekMasher in #56
  • sec-opengrep.yml to pull latest by @felickz in #62
  • deps: bump the production-dependencies group across 1 directory with 17 updates by @dependabot[bot] in #67
  • deps: bump the production-dependencies group across 1 directory with 7 updates by @dependabot[bot] in #71
  • deps: bump the production-dependencies group across 1 directory with 5 updates by @dependabot[bot] in #75
  • deps: bump the production-dependencies group across 1 directory with 13 updates by @dependabot[bot] in #84
  • Make retry-on-snapshot-warnings opt-in via workflow_call inputs by @Copilot in #76
  • Add snapshot wait by @felickz in #34
  • refactor: make release.yml a pure reusable workflow with bump support by @felickz in #86
  • feat: add opt-in README SHA update to release workflow by @felickz in #87

New Contributors

  • @Copilot made their first contribution in #76

Full Changelog: v0.3.0...v0.3.1

v0.2.1

18 May 18:52
Immutable release. Only release title and notes can be modified.

Choose a tag to compare

Full Changelog: v0.2.0...v0.2.1

v0.2.0

05 Sep 17:17
Immutable release. Only release title and notes can be modified.
14593b7

Choose a tag to compare

What's Changed

Full Changelog: 0.1.0...v0.2.0

v0.3.0

07 Jan 12:49
bc5a760

Choose a tag to compare

What's Changed

Full Changelog: v0.2.0...v0.3.0

v0.1.0

20 Aug 12:52

Choose a tag to compare

What's Changed

  • Add Container build and release workflow by @GeekMasher in #5
  • build(deps): bump actions/checkout from 3 to 4 by @dependabot in #7
  • build(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0 by @dependabot in #6
  • feat(docs): Add Wiki Publishing Action by @GeekMasher in #8
  • Labeler to auto-download default config file by @GeekMasher in #4
  • Update DepReview to use config file by @GeekMasher in #3
  • feat: Update dependabot.yml by @GeekMasher in #10
  • feat: CodeQL set dynamically languages by @GeekMasher in #12
  • feat: Add CodeQL IaC by @GeekMasher in #11
  • Update dependabot.yml by @GeekMasher in #13
  • deps: bump sigstore/cosign-installer from 3.4.0 to 3.5.0 in the production-dependencies group by @dependabot in #15
  • Use repo ref versus downloading config file by @GeekMasher in #16
  • deps: bump actions/github-script from 4 to 7 in the production-dependencies group by @dependabot in #17
  • Workflow automations on self by @felickz in #19
  • Update path to Dep Review file by @GeekMasher in #21
  • fix: Update dependency-review.yml by @GeekMasher in #22
  • fix: Update codeql-iac.yml by @GeekMasher in #23
  • deps: bump docker/login-action from 3.1.0 to 3.2.0 in the production-dependencies group by @dependabot in #24
  • Add workflow for language-based PR assignment by @adrienpessu in #27
  • deps: bump the production-dependencies group with 2 updates by @dependabot in #26
  • deps: bump the production-dependencies group across 1 directory with 2 updates by @dependabot in #30
  • feat(ci): Update docs for dep-review by @GeekMasher in #31

New Contributors

Full Changelog: https://github.com/advanced-security/reusable-workflows/commits/0.1.0