Skip to content

Patch Outstanding Vulnerabilities + Bump Version Deps#24

Open
matoszz wants to merge 1 commit intomainfrom
feat-patchvulns
Open

Patch Outstanding Vulnerabilities + Bump Version Deps#24
matoszz wants to merge 1 commit intomainfrom
feat-patchvulns

Conversation

@matoszz
Copy link
Copy Markdown
Member

@matoszz matoszz commented Apr 6, 2026

Patches the 11 outstanding vulnerabilities and the majority of the Renovate PR's (aside from go 1.26). The additional outstanding code scanning issues will be reviewed / addressed in a separate PR.

@matoszz matoszz requested a review from a team as a code owner April 6, 2026 04:31
@github-actions github-actions Bot added enhancement New feature or request ci labels Apr 6, 2026
@matoszz matoszz enabled auto-merge April 6, 2026 04:31
cli/go.sum
- name: Install Syft
uses: anchore/sbom-action/download-syft@28d71544de8eaf1b958d335707167c5f783590ad # v0.22.2
uses: anchore/sbom-action/download-syft@v0.24.0

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Release' step
Uses Step
uses 'anchore/sbom-action/download-syft' with ref 'v0.24.0', not a pinned commit hash
- name: Run GoReleaser
id: run-goreleaser
uses: goreleaser/goreleaser-action@v6
uses: goreleaser/goreleaser-action@v7

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Release' step
Uses Step: run-goreleaser
uses 'goreleaser/goreleaser-action' with ref 'v7', not a pinned commit hash
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants