Bump the minor-and-patch group across 1 directory with 4 updates - #185
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the minor-and-patch group across 1 directory with 4 updates#185dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the minor-and-patch group with 4 updates in the / directory: [oxsecurity/megalinter/flavors/python](https://github.com/oxsecurity/megalinter), [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) and [wesley-dean/publish_container](https://github.com/wesley-dean/publish_container). Updates `oxsecurity/megalinter/flavors/python` from 9.4.0 to 9.6.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@8fbdead...ef3e84b) Updates `stefanzweifel/git-auto-commit-action` from 7.1.0 to 7.2.0 - [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases) - [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md) - [Commits](stefanzweifel/git-auto-commit-action@04702ed...4a55954) Updates `github/codeql-action/upload-sarif` from 4.35.3 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e46ed2c...8aad20d) Updates `wesley-dean/publish_container` from 1.0.16 to 1.0.19 - [Release notes](https://github.com/wesley-dean/publish_container/releases) - [Commits](wesley-dean/publish_image@f9a254a...6d4b9c6) --- updated-dependencies: - dependency-name: oxsecurity/megalinter/flavors/python dependency-version: 9.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: stefanzweifel/git-auto-commit-action dependency-version: 7.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: wesley-dean/publish_container dependency-version: 1.0.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 3 | 0 | 0 | 0.27s | |
| zizmor | 3 | 0 | 1 | 0 | 0.33s | |
| ✅ DOCKERFILE | hadolint | 1 | 0 | 0 | 0.29s | |
| ✅ JSON | jsonlint | 2 | 0 | 0 | 0.33s | |
| ✅ JSON | prettier | 2 | 0 | 0 | 0 | 0.34s |
| ✅ JSON | v8r | 2 | 0 | 0 | 1.97s | |
| ✅ MARKDOWN | markdownlint | 1 | 0 | 0 | 0 | 0.6s |
| ✅ MARKDOWN | markdown-table-formatter | 1 | 0 | 0 | 0 | 0.2s |
| ✅ PYTHON | bandit | 1 | 0 | 0 | 2.35s | |
| ✅ PYTHON | black | 1 | 0 | 0 | 0 | 1.24s |
| ✅ PYTHON | flake8 | 1 | 0 | 0 | 1.03s | |
| ✅ PYTHON | isort | 1 | 0 | 0 | 0 | 0.28s |
| ✅ PYTHON | mypy | 1 | 0 | 0 | 3.12s | |
| ✅ PYTHON | pylint | 1 | 0 | 0 | 3.9s | |
| ✅ PYTHON | pyright | 1 | 0 | 0 | 2.62s | |
| ✅ PYTHON | ruff | 1 | 0 | 0 | 0 | 0.03s |
| ✅ REPOSITORY | betterleaks | yes | no | no | 1.49s | |
| ✅ REPOSITORY | checkov | yes | no | no | 24.45s | |
| ✅ REPOSITORY | gitleaks | yes | no | no | 0.27s | |
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | |
| grype | yes | 4 | 5 | 51.26s | ||
| osv-scanner | yes | 9 | no | 0.71s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 1.22s | |
| ✅ REPOSITORY | syft | yes | no | no | 2.18s | |
| trivy | yes | 4 | 5 | 10.0s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.18s | |
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.87s | |
| ✅ SPELL | lychee | 10 | 0 | 0 | 0.97s | |
| ✅ YAML | prettier | 6 | 0 | 0 | 0 | 0.4s |
| ✅ YAML | v8r | 6 | 0 | 0 | 7.39s | |
| ✅ YAML | yamllint | 6 | 0 | 0 | 0.45s |
Detailed Issues
⚠️ REPOSITORY / grype - 4 errors
error: A high vulnerability in python package: urllib3, version 2.6.3 was found at: /requirements.txt
error: A high vulnerability in python package: urllib3, version 2.6.3 was found at: /requirements.txt
warning: A medium vulnerability in python package: idna, version 3.11 was found at: /requirements.txt
error: A high vulnerability in python package: pyjwt, version 2.12.1 was found at: /requirements.txt
warning: A medium vulnerability in python package: pyjwt, version 2.12.1 was found at: /requirements.txt
warning: A medium vulnerability in python package: pyjwt, version 2.12.1 was found at: /requirements.txt
note: A low vulnerability in python package: pyjwt, version 2.12.1 was found at: /requirements.txt
warning: A medium vulnerability in python package: pyjwt, version 2.12.1 was found at: /requirements.txt
error: A high vulnerability in python package: cryptography, version 46.0.7 was found at: /requirements.txt
warning: 4 warnings emitted
error: 4 errors emitted
⚠️ REPOSITORY / osv-scanner - 9 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned requirements.txt file and found 13 packages
End status: 32 dirs visited, 94 inodes visited, 1 Extract calls, 8.114686ms elapsed, 8.114826ms wall time
Total 4 packages affected by 9 known vulnerabilities (0 Critical, 4 High, 4 Medium, 1 Low, 0 Unknown) from 1 ecosystem.
9 vulnerabilities can be fixed.
+-------------------------------------+------+-----------+--------------+---------+---------------+------------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-------------------------------------+------+-----------+--------------+---------+---------------+------------------+
| https://osv.dev/GHSA-537c-gmf6-5ccf | 7.5 | PyPI | cryptography | 46.0.7 | 48.0.1 | requirements.txt |
| https://osv.dev/PYSEC-2026-215 | 6.9 | PyPI | idna | 3.11 | 3.15 | requirements.txt |
| https://osv.dev/GHSA-65pc-fj4g-8rjx | | | | | | |
| https://osv.dev/PYSEC-2026-175 | 4.2 | PyPI | pyjwt | 2.12.1 | 2.13.0 | requirements.txt |
| https://osv.dev/GHSA-993g-76c3-p5m4 | | | | | | |
| https://osv.dev/PYSEC-2026-177 | 3.7 | PyPI | pyjwt | 2.12.1 | 2.13.0 | requirements.txt |
| https://osv.dev/GHSA-fhv5-28vv-h8m8 | | | | | | |
| https://osv.dev/PYSEC-2026-178 | 5.3 | PyPI | pyjwt | 2.12.1 | 2.13.0 | requirements.txt |
| https://osv.dev/GHSA-w7vc-732c-9m39 | | | | | | |
| https://osv.dev/PYSEC-2026-179 | 7.4 | PyPI | pyjwt | 2.12.1 | 2.13.0 | requirements.txt |
| https://osv.dev/GHSA-xgmm-8j9v-c9wx | | | | | | |
| https://osv.dev/GHSA-jq35-7prp-9v3f | 5.4 | PyPI | pyjwt | 2.12.1 | 2.13.0 | requirements.txt |
| https://osv.dev/PYSEC-2026-141 | 8.2 | PyPI | urllib3 | 2.6.3 | 2.7.0 | requirements.txt |
| https://osv.dev/GHSA-qccp-gfcp-xxvc | | | | | | |
| https://osv.dev/PYSEC-2026-142 | 8.9 | PyPI | urllib3 | 2.6.3 | 2.7.0 | requirements.txt |
| https://osv.dev/GHSA-mf9v-mfxr-j63j | | | | | | |
+-------------------------------------+------+-----------+--------------+---------+---------------+------------------+
⚠️ REPOSITORY / trivy - 4 errors
error: Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: [GHSA-537c-gmf6-5ccf](https://github.com/advisories/GHSA-537c-gmf6-5ccf)
┌─ requirements.txt:230:1
│
230 │ cryptography==46.0.7 \
│ ^
│
= Vulnerable OpenSSL included in cryptography wheels
= pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.
If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.
warning: Package: idna
Installed Version: 3.11
Vulnerability CVE-2026-45409
Severity: MEDIUM
Fixed Version: 3.15
Link: [CVE-2026-45409](https://avd.aquasec.com/nvd/cve-2026-45409)
┌─ requirements.txt:281:1
│
281 │ idna==3.11 \
│ ^
│
= Internationalized Domain Names in Applications (IDNA) for Python provi ...
= Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.
error: Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48526
Severity: HIGH
Fixed Version: 2.13.0
Link: [CVE-2026-48526](https://avd.aquasec.com/nvd/cve-2026-48526)
┌─ requirements.txt:293:1
│
293 │ pyjwt[crypto]==2.12.1 \
│ ^
│
= python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
= PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.
warning: Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48522
Severity: MEDIUM
Fixed Version: 2.13.0
Link: [CVE-2026-48522](https://avd.aquasec.com/nvd/cve-2026-48522)
┌─ requirements.txt:293:1
│
293 │ pyjwt[crypto]==2.12.1 \
│ ^
│
= python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient
= PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parameter), the attacker can cause PyJWKClient to read arbitrary local files via file:// (SSRF on local filesystem), cause PyJWKClient to attempt FTP / data-URI fetches (broader SSRF surface), or forge tokens that PyJWT verifies as valid. The library does not directly return non-HTTP(S) URI contents to the attacker; the chained "plant a JWKS to forge tokens" scenario described in the original report requires additional application-layer flaws (attacker write access to a filesystem path, untrusted jku derivation) that this fix does not address. This vulnerability is fixed in 2.13.0.
warning: Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48523
Severity: MEDIUM
Fixed Version: 2.13.0
Link: [CVE-2026-48523](https://avd.aquasec.com/nvd/cve-2026-48523)
┌─ requirements.txt:293:1
│
293 │ pyjwt[crypto]==2.12.1 \
│ ^
│
= python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access
= PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, advertise an allowed algorithm in the JWT header, and still be accepted. The issue affects the documented PyJWKClient.get_signing_key_from_jwt(...) flow. This vulnerability is fixed in 2.13.0.
warning: Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48525
Severity: MEDIUM
Fixed Version: 2.13.0
Link: [CVE-2026-48525](https://avd.aquasec.com/nvd/cve-2026-48525)
┌─ requirements.txt:293:1
│
293 │ pyjwt[crypto]==2.12.1 \
│ ^
│
= python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens
= PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled “work amplifier”: a remote client can supply an arbitrarily large Base64URL payload segment that forces CPU work + memory allocations even if the signature is invalid. This creates an unauthenticated DoS vector against any endpoint that verifies detached JWS using PyJWT. This vulnerability is fixed in 2.13.0.
note: Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48524
Severity: LOW
Fixed Version: 2.13.0
Link: [CVE-2026-48524](https://avd.aquasec.com/nvd/cve-2026-48524)
┌─ requirements.txt:293:1
│
293 │ pyjwt[crypto]==2.12.1 \
│ ^
│
= python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs
= PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0.
error: Package: urllib3
Installed Version: 2.6.3
Vulnerability CVE-2026-44431
Severity: HIGH
Fixed Version: 2.7.0
Link: [CVE-2026-44431](https://avd.aquasec.com/nvd/cve-2026-44431)
┌─ requirements.txt:336:1
│
336 │ urllib3==2.6.3 \
│ ^
│
= urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
= urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
error: Package: urllib3
Installed Version: 2.6.3
Vulnerability CVE-2026-44432
Severity: HIGH
Fixed Version: 2.7.0
Link: [CVE-2026-44432](https://avd.aquasec.com/nvd/cve-2026-44432)
┌─ requirements.txt:336:1
│
336 │ urllib3==2.6.3 \
│ ^
│
= urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
= urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.
warning: 4 warnings emitted
error: 4 errors emitted
⚠️ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'impostor-commit' audit failed on file://.github/workflows/dependabot_automerge.yml
Caused by:
0: error in 'impostor-commit' audit
1: couldn't list tags for dependabot/fetch-metadata
2: request error while accessing GitHub API
3: HTTP status client error (401 Unauthorized) for url (https://github.com/dependabot/fetch-metadata.git/git-upload-pack)
Notices
📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)
See detailed reports in MegaLinter artifacts
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters PYTHON_PYLINT,PYTHON_BLACK,PYTHON_FLAKE8,PYTHON_ISORT,PYTHON_BANDIT,PYTHON_MYPY,PYTHON_PYRIGHT,PYTHON_RUFF,ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-and-patch group with 4 updates in the / directory: oxsecurity/megalinter/flavors/python, stefanzweifel/git-auto-commit-action, github/codeql-action/upload-sarif and wesley-dean/publish_container.
Updates
oxsecurity/megalinter/flavors/pythonfrom 9.4.0 to 9.6.0Release notes
Sourced from oxsecurity/megalinter/flavors/python's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter/flavors/python's changelog.
... (truncated)
Commits
ef3e84bRelease MegaLinter v9.6.08b9259bSkill prepare-release (#8245)5810155chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /.config/python/...aca415cchore(deps): update dependency semver to v7.8.5 (#8198)2d8b274Remove max-parallel for linterse9ab3e9chore(ci): manual run of deploy linters beta job (#8242)a8a6368Changelog (#8241)7f363c6[automation] Auto-update linters version, help and documentation (#8215)bce5232chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.11.25 (#8232)9d98266chore(deps): update dependency realm/swiftlint to v0.65.0 (#8240)Updates
stefanzweifel/git-auto-commit-actionfrom 7.1.0 to 7.2.0Release notes
Sourced from stefanzweifel/git-auto-commit-action's releases.
Changelog
Sourced from stefanzweifel/git-auto-commit-action's changelog.
... (truncated)
Commits
4a55954Update README.md9f6c933Add hooks to run shell snippets around git operations (#411)c365a74Emit warning for pull_request_target trigger usage (#410)d28176cBump actions/checkout from 6 to 7 (#409)25df622Add EXAMPLES.md32e9844docs(action): fix input and output descriptions in action.yml (#406)a3ed46fdocs: fix typos, grammar, and formatting across markdown files (#408)b4d688cdocs: fix broken and redirecting URLs in README.md (#407)f53a62cREADME: clearify meaning of the repository field (#404)4fc4bbfBump release-drafter/release-drafter from 6 to 7 (#403)Updates
github/codeql-action/upload-sariffrom 4.35.3 to 4.36.2Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
8aad20dMerge pull request #3949 from github/update-v4.36.2-dcb947ce1f521b08Add additional changelog notes8aeff0fUpdate changelog for v4.36.2dcb947cMerge pull request #3948 from github/update-bundle/codeql-bundle-v2.25.6c251bceAdd changelog note62953c1Update default bundle to codeql-bundle-v2.25.6423b570Merge pull request #3946 from github/dependabot/npm_and_yarn/npm-minor-5d507a...c35d1b1Merge pull request #3947 from github/dependabot/github_actions/dot-github/wor...cb1a588Merge pull request #3937 from github/robertbrignull/waitForProcessing_backoffba47406Merge pull request #3943 from github/henrymercer/cache-cli-version-infoUpdates
wesley-dean/publish_containerfrom 1.0.16 to 1.0.19Release notes
Sourced from wesley-dean/publish_container's releases.
Commits
6d4b9c6Merge pull request #88 from wesley-dean/dependabot/github_actions/dependabot/...856faa9Merge pull request #86 from wesley-dean/dependabot/github_actions/docker/buil...9aeb362Merge pull request #84 from wesley-dean/dependabot/github_actions/minor-and-p...6fac9e6Merge pull request #85 from wesley-dean/dependabot/github_actions/crazy-max/g...b5d7fb0Merge pull request #76 from wesley-dean/renamec456226Merge branch 'main' into renameb744269build(deps): bump dependabot/fetch-metadata from 2.5.0 to 3.1.0697fe10build(deps): bump docker/build-push-action from 6.18.0 to 7.1.046e0d92build(deps): bump crazy-max/ghaction-import-gpg from 6.3.0 to 7.0.088a1b86build(deps): bump github/codeql-action in the minor-and-patch groupDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions