Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump docker/scout-action from 1.15.1 to 1.16.1 #352

Merged
merged 2 commits into from
Jan 24, 2025

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 16, 2024

Bumps docker/scout-action from 1.15.1 to 1.16.1.

Release notes

Sourced from docker/scout-action's releases.

v1.16.1

What's Changed

  • Fix in-toto subject digest for the docker scout attestation add command by @​cdupuis

v1.16.0

What's Changed

  • Add secret scanning to sbom command by @​cdupuis
  • Keep original pattern to find nested matches too by @​cdupuis
  • Make licenses unqiue by @​cdupuis
  • Print platform in markdown output by @​cdupuis
  • Normalize licenses using spdx license list by @​cdupuis
  • Updates to make spdx output spec compliant by @​cdupuis
  • Check dir exists before creating temp file by @​chrispatrick
  • Update Go, crypto module and alpine by @​cdupuis
  • Add support for attestations for images from Tanzu Application Catalog by @​cdupuis
  • Fix behaviour with multi images in attest cmd by @​cdupuis
Commits
  • b23590d Merge 95bd05b11d612059dab025c80072e80894133594 into d3343f4e1411fc42690966f3a...
  • 95bd05b [BOT] Publish v1.16.1 release
  • d3343f4 Update CODEOWNERS
  • 4d5cab6 Merge 2bfc559301a561e2462f0eba7d35917644f0e71e into 6ac950eb733f8b2811f25c05d...
  • 2bfc559 [BOT] Publish v1.16.0 release
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [docker/scout-action](https://github.com/docker/scout-action) from 1.15.1 to 1.16.1.
- [Release notes](https://github.com/docker/scout-action/releases)
- [Commits](docker/scout-action@v1.15.1...v1.16.1)

---
updated-dependencies:
- dependency-name: docker/scout-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Copy link

github-actions bot commented Jan 24, 2025

🔍 Vulnerabilities of liquibase/liquibase:5abe3fcd8037fe719878d2052ef6e65e555ecbca

📦 Image Reference liquibase/liquibase:5abe3fcd8037fe719878d2052ef6e65e555ecbca
digestsha256:780211e47fa808cc308bc010e426105f2464e0bbafdbf3a8497fd9d756ea5d82
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size471 MB
packages240
📦 Base Image eclipse-temurin:17-jre-jammy
also known as
  • 17.0.13_11-jre-jammy
digestsha256:c0a4e9ce589b256e6bfd30977c5a5ae90d83628887dcff9bd0ce37e7d7a9b4a8
vulnerabilitiescritical: 0 high: 0 medium: 6 low: 16

@jnewton03 jnewton03 merged commit e348326 into main Jan 24, 2025
12 checks passed
@jnewton03 jnewton03 deleted the dependabot/github_actions/docker/scout-action-1.16.1 branch January 24, 2025 17:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants