Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update anchore/scan-action action to v4 #464

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 11, 2024

Mend Renovate

This PR contains the following updates:

Package Type Update Change
anchore/scan-action action major v2.0.0 -> v4.0.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

anchore/scan-action (anchore/scan-action)

v4.0.0

Compare Source

New in scan-action v4.0.0

v3.6.4

Compare Source

New in scan-action v3.6.4

v3.6.3

Compare Source

New in scan-action v3.6.3
  • chore: migrate action to use node v20.11.0 (Iron) FROM node v16.x.x (#​278) [spiffcs]

v3.6.2

Compare Source

New in scan-action v3.6.2

v3.6.1

Compare Source

New in scan-action v3.6.1

v3.6.0

Compare Source

New in scan-action v3.6.0

v3.5.0

Compare Source

New in scan-action v3.5.0

v3.4.0

Compare Source

New in scan-action v3.4.0

v3.3.8

Compare Source

New in scan-action v3.3.8

v3.3.7

Compare Source

New in scan-action v3.3.7
🐛 Bug Fixes

v3.3.6

Compare Source

New in scan-action v3.3.6

v3.3.5

Compare Source

New in scan-action v3.3.5

v3.3.4

Compare Source

New in scan-action v3.3.4
  • Update Grype to v0.56.0 (#​205)

v3.3.3

Compare Source

New in scan-action v3.3.3

v3.3.2

Compare Source

New in scan-action v3.3.2

v3.3.1

Compare Source

New in scan-action v3.3.1

v3.3.0

Compare Source

New in scan-action v3.3.0

v3.2.5

Compare Source

New in scan-action v3.2.5

v3.2.4

Compare Source

New in scan-action v3.2.4

  • Update Grype to v0.34.7 (#​163)
  • More closely align parameters with sbom-action (#​158)

v3.2.3

Compare Source

New in scan-action v3.2.3

v3.2.2

Compare Source

New in scan-action v3.2.2

  • Add sub-action to download Grype (#​152)
  • Update Grype to 0.34.4 to fix a nil pointer in SARIF generation (#​151)

v3.2.1

Compare Source

New in scan-action v3.2.1

  • Remove SARIF processing (#​148)

v3.2.0

Compare Source

New in scan-action v3.2.0

  • Update Grype to 0.27.3 (#​136)
  • Output Grype stderr to action logs (#​137)
  • Readme should point to CONTRIBUTING.md (#​126)
  • Improve documentation (#​125)

v3.1.0

Compare Source

New in scan-action v3.1.0

  • Update Grype to 0.22.0 - this includes the ability to ignore vulnerability matches (#​121)

v3.0.0

Compare Source

New in scan-action v3.0.0

  • Upgrade to Grype to 0.17.0 and add tests #​102 (#​112) (#​118)
  • Improve SARIF output #​114 (#​115)
  • Change default behavior so action fails on medium (and higher) severities (#​86)
  • Respect verbosity from action to call Grype (#​82)

v2.0.4

Compare Source

New in scan-action v2.0.4

  • bump grype to 0.7.0 (#​81)

v2.0.3

Compare Source

New in scan-action 2.0.3

  • bump grype to 0.6.1 (#​79)
  • Halt execution when invalid options are provided (#​76)
  • bump grype to 0.5.0 (#​75)

v2.0.2

Compare Source

Minor bug-fix release:

v2.0.1

Compare Source

Minor bug-fix release.

Fixes:

  • Removes unnecessary constraint in deduplication for SARIF reporting
  • Allows defining and referencing the location of the SARIF report file
  • Fixes multiple instances where undefined items in the reporting would break scanning

Configuration

📅 Schedule: Branch creation - "after 10pm every weekday,before 5am every weekday,every weekend" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

Copy link

sonarcloud bot commented Jul 11, 2024

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants