Skip to content

build(deps): Bump hashgraph-online/codex-plugin-scanner from 1.4.2 to 1.4.10#30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashgraph-online/codex-plugin-scanner-1.4.10
Open

build(deps): Bump hashgraph-online/codex-plugin-scanner from 1.4.2 to 1.4.10#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashgraph-online/codex-plugin-scanner-1.4.10

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 6, 2026

Bumps hashgraph-online/codex-plugin-scanner from 1.4.2 to 1.4.10.

Release notes

Sourced from hashgraph-online/codex-plugin-scanner's releases.

v1.4.10

What's Changed

  • fix: harden scorecard release signals (#51) (c9983aa)

Installation

uv tool install codex-plugin-scanner==1.4.10
docker pull ghcr.io/hashgraph-online/codex-plugin-scanner:1.4.10

Full Changelog: hashgraph-online/codex-plugin-scanner@v1.4.9...v1.4.10

v1.4.9

What's Changed

  • feat: add explicit dogfood and container install paths (#50) (29183ef)

Installation

uv tool install codex-plugin-scanner==1.4.9
docker pull ghcr.io/hashgraph-online/codex-plugin-scanner:1.4.9

Full Changelog: hashgraph-online/codex-plugin-scanner@v1.4.8...v1.4.9

v1.4.8

What's Changed

  • fix: harden action package provenance (#49) (4078d8c)

Installation

uv tool install codex-plugin-scanner==1.4.8

Full Changelog: hashgraph-online/codex-plugin-scanner@v1.4.7...v1.4.8

v1.4.7

What's Changed

  • fix: bump Cisco scanner to 2.0.8 (#48) (191caaa)

Installation

... (truncated)

Commits
  • c9983aa fix: harden scorecard release signals (#51)
  • 29183ef feat: add explicit dogfood and container install paths (#50)
  • 4078d8c fix: harden action package provenance (#49)
  • 191caaa fix: bump Cisco scanner to 2.0.8 (#48)
  • f56de45 fix: authenticate action repo release pushes (#45)
  • c1d2d31 fix: publish action repo releases automatically (#44)
  • d93e5ad feat: support multi-plugin Codex marketplace repos (#43)
  • 6e62149 fix: restore publishable cisco extra metadata (#42)
  • ada6c1a fix: remediate scanner security alerts (#41)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hashgraph-online/codex-plugin-scanner](https://github.com/hashgraph-online/codex-plugin-scanner) from 1.4.2 to 1.4.10.
- [Release notes](https://github.com/hashgraph-online/codex-plugin-scanner/releases)
- [Commits](hashgraph-online/codex-plugin-scanner@f1757d7...c9983aa)

---
updated-dependencies:
- dependency-name: hashgraph-online/codex-plugin-scanner
  dependency-version: 1.4.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies github_actions Pull requests that update GitHub Actions code labels Apr 6, 2026
@github-actions github-actions Bot added the ci label Apr 6, 2026
@kilo-code-bot
Copy link
Copy Markdown

kilo-code-bot Bot commented Apr 6, 2026

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 file)
  • .github/workflows/ci.yml - No issues

Review Notes

This is a straightforward Dependabot dependency bump updating the codex-plugin-scanner action from version 1.4.2 to 1.4.10. The change consists of updating the Git commit SHA reference in the CI workflow.

Changes observed:

  • .github/workflows/ci.yml line 62: Updated action reference from f1757d75f68c97afb4622d6d90f65a00f55c59ea to c9983aaef2fad3ab1b11d4f1fd634cda316802fb

This appears to be a legitimate security-focused update. According to the PR description, version 1.4.10 includes several hardening fixes related to release signals, package provenance, and scanner updates.

No code logic changes - this is purely a dependency version bump with no reviewable implementation details.


Reviewed by minimax-m2.5 · 78,328 tokens

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants