Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(SEC-1211): update semgrep version #154

Merged
merged 10 commits into from
Sep 19, 2024
Merged

Conversation

pankajmouriyakong
Copy link
Contributor

@pankajmouriyakong pankajmouriyakong commented Sep 5, 2024

Why to update?
Semgrep is giving following message in the scan runs A new version of Semgrep is available. See https://semgrep.dev/docs/upgrading

Note:
We use latest version tag of the image but looks like semgrep has made few new tag releases but have not rolled out their Latest tag to the latest version that is 1.86.0

@pankajmouriyakong pankajmouriyakong requested a review from a team as a code owner September 5, 2024 06:49
Copy link

github-actions bot commented Sep 5, 2024

Luacheck Report

1 files  ±0  1 suites  ±0   0s ⏱️ ±0s
4 tests ±0  4 ✅ ±0  0 💤 ±0  0 ❌ ±0 
8 runs  ±0  8 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit 263c9fb. ± Comparison against base commit d379af8.

♻️ This comment has been updated with latest results.

Specify the directory as /security-actions/semgrep to ensure that Dependabot monitors changes to the Semgrep Docker image

The commit-message section uses the prefix semgrep and includes the scope to make it clear in the PR message

Dependabot version updates does not support docker:// hence remove the use of this URI

Ref: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#github-actions
@pankajmouriyakong pankajmouriyakong requested a review from a team as a code owner September 5, 2024 22:02
Copy link
Collaborator

@saisatishkarra saisatishkarra left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gtm

@saisatishkarra saisatishkarra merged commit 6d6e601 into main Sep 19, 2024
12 checks passed
@saisatishkarra saisatishkarra deleted the feat/update-semgrep branch September 19, 2024 20:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants