build(deps): Bump google/osv-scanner-action/osv-scanner-action from a82132c0bd6c7261ffcb78e754c46c70ab57ad9a to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc - #602
Conversation
Bumps [google/osv-scanner-action/osv-scanner-action](https://github.com/google/osv-scanner-action) from a82132c0bd6c7261ffcb78e754c46c70ab57ad9a to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc. - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@a82132c...9fd1bcc) --- updated-dependencies: - dependency-name: google/osv-scanner-action/osv-scanner-action dependency-version: 9fd1bcce27f67e3bd819a0a7620e332803dc43bc dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Automated code review started - full review. Results will be posted here. |
hermes-exosphere
left a comment
There was a problem hiding this comment.
✅ Auto-approved: all 10 CI checks passing. Ready to merge.
|
⏳ [progress] Build & test phase complete. Running 2357 tests across 131 test files... |
|
✅ Build & test complete. Results:
|
🔍 Automated Code Review📋 Executive SummaryThis is a routine Dependabot version bump for the 📊 Change Architecturegraph TD
A["osv-scanner.yml workflow"] -->|"pin: a82132c → 9fd1bcc"| B["google/osv-scanner-action@v2.3.8"]
B --> C["Internal: GOTOOLCHAIN=auto env added"]
C --> D["Fixes Go toolchain resolution in Docker"]
D --> E["Same scan behavior, no user-visible change"]
style C fill:#90EE90
style B fill:#87CEEB
style A fill:#87CEEB
Legend: 🟢 New | 🔵 Modified | 🟡 Breaking Change Risk 🔴 Breaking Changes✅ No breaking changes detected. The pin is a forward move within the same v2.3.8 release. The action inputs (
|
hermes-exosphere
left a comment
There was a problem hiding this comment.
Automated review: Approved. ✅
Bumps google/osv-scanner-action/osv-scanner-action from a82132c0bd6c7261ffcb78e754c46c70ab57ad9a to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc.
Commits
9fd1bccMerge pull request #138 from google/fix/gotoolchain-auto01a87d5fix: add GOTOOLCHAIN=auto env to osv-scanner callsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)