Bump the github-actions group with 2 updates#56
Conversation
Bumps the github-actions group with 2 updates: [github/codeql-action](https://github.com/github/codeql-action) and [anchore/scan-action](https://github.com/anchore/scan-action). Updates `github/codeql-action` from 3.29.2 to 3.29.4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@181d5ee...4e828ff) Updates `anchore/scan-action` from 6.4.0 to 6.5.0 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@16910ac...df39580) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 3.29.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: anchore/scan-action dependency-version: 6.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
🔍 Vulnerabilities of
|
| digest | sha256:e997091a6cc4d1961cdb97f468815b7b8c0133308c2843c9420e6fc7639d665c |
| vulnerabilities | |
| platform | linux/amd64 |
| size | 155 MB |
| packages | 205 |
📦 Base Image postgres:16
| also known as |
|
| digest | sha256:f83a8e9cf19080d7d8aef6241cf510da41dabfacaaa3e39c7ae2dee3b8c5ded9 |
| vulnerabilities |
# Dockerfile (6:6)
FROM postgres:${POSTGRES_VERSION}
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
# Dockerfile (6:6)
FROM postgres:${POSTGRES_VERSION}
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
# Dockerfile (6:6)
FROM postgres:${POSTGRES_VERSION}
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
# Dockerfile (6:6)
FROM postgres:${POSTGRES_VERSION}
Description
|
Bumps the github-actions group with 2 updates: github/codeql-action and anchore/scan-action.
Updates
github/codeql-actionfrom 3.29.2 to 3.29.4Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
4e828ffMerge pull request #2989 from github/update-v3.29.4-37264dc0bb3114b8Update changelog for v3.29.437264dcMerge pull request #2988 from github/koesie10/disable-combine-single-file5a29823Merge remote-tracking branch 'origin/main' into koesie10/disable-combine-sing...5a2327aMerge pull request #2987 from github/mbg/combine-sarif-error287d421Disable combining runs within a single file43afe6eTreat processing error for multiple runs with the same category as configurat...8f2e636Merge pull request #2981 from github/dependabot/npm_and_yarn/npm-fe13dfda4676bf77dMerge pull request #2980 from github/dependabot/github_actions/actions-504b6c...9e7d13dMerge pull request #2983 from github/koesie10/update-changelog-linkUpdates
anchore/scan-actionfrom 6.4.0 to 6.5.0Release notes
Sourced from anchore/scan-action's releases.
Commits
df39580chore(deps-dev): bump jest from 30.0.4 to 30.0.5 (#492)e4ff89echore(deps): update Grype to v0.96.1 (#493)b8370fafix: output stderr to log, more accurate nonzero exit code behavior (#491)a0ef9a0chore(deps-dev): bump jest from 30.0.3 to 30.0.4 (#487)0fc8134chore(deps-dev): bump eslint from 9.30.1 to 9.31.0 (#488)0743469chore(deps): update Grype to v0.96.0 (#489)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions