Skip to content

chore(deps): pin googleapis/release-please-action to SHA#461

Merged
mvillmow merged 1 commit into
mainfrom
368-auto-impl
Apr 26, 2026
Merged

chore(deps): pin googleapis/release-please-action to SHA#461
mvillmow merged 1 commit into
mainfrom
368-auto-impl

Conversation

@mvillmow
Copy link
Copy Markdown
Collaborator

Pins the release-please-action to a specific commit SHA for supply-chain security, following the pattern used by other workflows in the repository.

Closes #368

@mvillmow mvillmow enabled auto-merge (rebase) April 26, 2026 00:27
@github-actions
Copy link
Copy Markdown

✅ Dependency Audit

Severity Count
Critical 0
High 0
Medium 0
Low 0

See the Security tab for detailed findings.


Workflow: Dependency Audit

@github-actions
Copy link
Copy Markdown

Security Scan Results

  • ❌ Secret Scanning: Potential secrets found
  • ✅ SAST: Completed (check Security tab for details)
  • ✅ Dependency Scanning: Completed
  • ✅ C++ Static Analysis: Completed
  • ✅ Docker Image Scanning: 0 high, 22 medium vulnerabilities (acceptable)

Recommendations

  • Review findings in the GitHub Security tab
  • Check artifact uploads for detailed reports
  • Address critical Docker vulnerabilities immediately

Workflow: Security Scanning

@mvillmow mvillmow merged commit 8c073fc into main Apr 26, 2026
8 of 9 checks passed
@mvillmow mvillmow deleted the 368-auto-impl branch April 26, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin release-please-action to a specific SHA

1 participant