Skip to content

Conversation

@mend-for-github-com
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Jun 16, 2024

This PR contains the following updates:

Package Type Update Change
@actions/core (source) dependencies minor 1.0.0 -> 1.2.6

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Low Low 3.5 CVE-2020-15228

Release Notes

actions/toolkit (@​actions/core)

v1.2.6

v1.2.5

v1.2.4

v1.2.3

v1.2.2

v1.2.1

v1.2.0

  • saveState and getState functions for wrapper tasks (on finally entry points that run post job)

v1.1.3

  • setSecret added to register a secret with the runner to be masked from the logs
  • exportSecret which was not implemented and never worked was removed after clarification from product.

v1.1.1

  • Add support for action input variables with multiple spaces #​127
  • Switched ## commands to :: commands (should have no noticeable impact) [#​110)(#​110)

v1.1.0

Compare Source

  • Added helpers for group and endgroup #​98

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jun 16, 2024
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/actions-core-1.x-lockfile branch from ca53580 to df2d2c1 Compare January 27, 2025 06:09
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/actions-core-1.x-lockfile branch from df2d2c1 to c5b6480 Compare March 20, 2025 10:18
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/actions-core-1.x-lockfile branch from c5b6480 to 7fb1559 Compare April 29, 2025 18:11
@mend-for-github-com mend-for-github-com bot changed the title Update dependency @actions/core to v1.9.1 Update dependency @actions/core to v1.2.6 Apr 29, 2025
@mend-for-github-com
Copy link
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant