Skip to content

chore(deps): bump dependabot/fetch-metadata from 2.4.0 to 2.5.0

d0cae66
Select commit
Loading
Failed to load commit list.
Merged

chore(deps): bump dependabot/fetch-metadata from 2.4.0 to 2.5.0 #2666

chore(deps): bump dependabot/fetch-metadata from 2.4.0 to 2.5.0
d0cae66
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL completed Jan 5, 2026 in 3s

1 configuration not found

Warning: Code scanning may not have found all the alerts introduced by this pull request, because 1 configuration present on refs/heads/main was not found:

API upload

  • ❓  <default>

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 22 in .github/workflows/auto-merge-dependabot.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Auto-merge dependabot updates' step
Uses Step: metadata
uses 'dependabot/fetch-metadata' with ref 'v2.5.0', not a pinned commit hash