Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 5, 2022

Bumps actions/checkout from 3.0.2 to 3.1.0.

Release notes

Sourced from actions/checkout's releases.

v3.1.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v3.0.2...v3.1.0

Changelog

Sourced from actions/checkout's changelog.

v3.1.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 3.0.2 to 3.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v3.0.2...v3.1.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies github_actions Pull requests that update GitHub Actions code labels Oct 5, 2022
@nscuro nscuro merged commit 80fa9d2 into master Oct 10, 2022
@dependabot dependabot bot deleted the dependabot/github_actions/actions/checkout-3.1.0 branch October 10, 2022 08:05
sahibamittal added a commit to sahibamittal/dependency-track-frontend-upstream that referenced this pull request Oct 11, 2022
commit 80fa9d2
Merge: fe862fc 5944393
Author: Niklas <nscuro@protonmail.com>
Date:   Mon Oct 10 10:05:33 2022 +0200

    Merge pull request DependencyTrack#273 from DependencyTrack/dependabot/github_actions/actions/checkout-3.1.0

    build(deps): bump actions/checkout from 3.0.2 to 3.1.0

commit fe862fc
Merge: ac99c3b 65bb03b
Author: Niklas <nscuro@protonmail.com>
Date:   Mon Oct 10 10:04:53 2022 +0200

    Merge pull request DependencyTrack#267 from DependencyTrack/dependabot/docker/docker/nginxinc/nginx-unprivileged-ff29830

    build(deps): bump nginxinc/nginx-unprivileged from `de9ed41` to `ff29830` in /docker

commit ac99c3b
Merge: 1eaefe5 122ce55
Author: Niklas <nscuro@protonmail.com>
Date:   Sun Oct 9 15:06:31 2022 +0200

    Merge pull request DependencyTrack#277 from nscuro/enable-new-vulnerable-dependency-group

    Re-enable NEW_VULNERABLE_DEPENDENCY notification

commit 122ce55
Author: nscuro <nscuro@protonmail.com>
Date:   Sun Oct 9 14:47:44 2022 +0200

    Re-enable NEW_VULNERABLE_DEPENDENCY notification

    DependencyTrack/dependency-track#1611
    Signed-off-by: nscuro <nscuro@protonmail.com>

commit 5944393
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Wed Oct 5 02:04:08 2022 +0000

    build(deps): bump actions/checkout from 3.0.2 to 3.1.0

    Bumps [actions/checkout](https://github.com/actions/checkout) from 3.0.2 to 3.1.0.
    - [Release notes](https://github.com/actions/checkout/releases)
    - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
    - [Commits](actions/checkout@v3.0.2...v3.1.0)

    ---
    updated-dependencies:
    - dependency-name: actions/checkout
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

commit 65bb03b
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Thu Sep 29 01:42:55 2022 +0000

    build(deps): bump nginxinc/nginx-unprivileged in /docker

    Bumps nginxinc/nginx-unprivileged from `de9ed41` to `ff29830`.

    ---
    updated-dependencies:
    - dependency-name: nginxinc/nginx-unprivileged
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

commit 1eaefe5
Merge: ed43676 e5da956
Author: Niklas <nscuro@protonmail.com>
Date:   Wed Sep 28 10:43:27 2022 +0200

    Merge pull request DependencyTrack#262 from DependencyTrack/dependabot/github_actions/actions/setup-node-3.5.0

commit ed43676
Merge: f3b6a0c d33ce07
Author: Niklas <nscuro@protonmail.com>
Date:   Wed Sep 28 10:39:06 2022 +0200

    Merge pull request DependencyTrack#261 from DependencyTrack/dependabot/docker/docker/nginxinc/nginx-unprivileged-de9ed41

commit f3b6a0c
Merge: df995f5 2196f55
Author: Niklas <nscuro@protonmail.com>
Date:   Wed Sep 28 10:38:07 2022 +0200

    Merge pull request DependencyTrack#259 from awegg/1948_cvss_on_components

commit e5da956
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Wed Sep 28 01:37:44 2022 +0000

    build(deps): bump actions/setup-node from 3.4.1 to 3.5.0

    Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.4.1 to 3.5.0.
    - [Release notes](https://github.com/actions/setup-node/releases)
    - [Commits](actions/setup-node@v3.4.1...v3.5.0)

    ---
    updated-dependencies:
    - dependency-name: actions/setup-node
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

commit d33ce07
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Tue Sep 27 01:39:41 2022 +0000

    build(deps): bump nginxinc/nginx-unprivileged in /docker

    Bumps nginxinc/nginx-unprivileged from `e916f63` to `de9ed41`.

    ---
    updated-dependencies:
    - dependency-name: nginxinc/nginx-unprivileged
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...

    Signed-off-by: dependabot[bot] <support@github.com>

commit 2196f55
Author: awegg <alexander@weggerle.de>
Date:   Sun Sep 25 13:26:22 2022 +0200

    Add CVSS, EPSS to Component Vulnerabilities

    Make more information available on the component vulnerability tab with default visibility false.

    Fixes DependencyTrack/dependency-track#1948

    Signed-off-by: awegg <alexander@weggerle.de>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants