Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security fix for dependabot auto merge #670

Merged
merged 1 commit into from
Jan 6, 2025

Conversation

billjh
Copy link
Contributor

@billjh billjh commented Jan 6, 2025

This PR should address a security vulnerability described in https://www.synacktiv.com/publications/github-actions-exploitation-dependabot

Copy link
Contributor

@exoego exoego left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks 🙇
LGTM

@exoego exoego added the github_actions Pull requests that update GitHub Actions code label Jan 6, 2025
Copy link
Contributor

github-actions bot commented Jan 6, 2025

Code Coverage

Package Line Rate Branch Rate Complexity Health
core 100% 100% 0
modules 69% 88% 0
Summary 70% (495 / 705) 89% (74 / 83) 0

Copy link
Contributor

github-actions bot commented Jan 6, 2025

A snapshot release has been created as snapshots/670.

You can test it out with:

uses: scala-steward-org/scala-steward-action@snapshots/670

It will be automatically recreated on any change to this PR.

@exoego exoego merged commit a588569 into scala-steward-org:master Jan 6, 2025
2 checks passed
@billjh billjh deleted the patch-1 branch January 7, 2025 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants