Skip to content

⬆ Bump SonarSource/sonarqube-scan-action from 7.1.0 to 7.2.1#11

Merged
Chisanan232 merged 2 commits into
masterfrom
dependabot/github_actions/SonarSource/sonarqube-scan-action-7.2.1
May 2, 2026
Merged

⬆ Bump SonarSource/sonarqube-scan-action from 7.1.0 to 7.2.1#11
Chisanan232 merged 2 commits into
masterfrom
dependabot/github_actions/SonarSource/sonarqube-scan-action-7.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 29, 2026

Bumps SonarSource/sonarqube-scan-action from 7.1.0 to 7.2.1.

Release notes

Sourced from SonarSource/sonarqube-scan-action's releases.

v7.2.1

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v7...v7.2.1

v7.2.0

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v7...v7.2.0

Commits
  • c7ee0f9 SQSCANGHA-140 Set skipSignatureVerification default value to true to avoid br...
  • 55e4480 SQSCANGHA-140 Add OpenPGP signature verification for scanner downloads (#235)
  • 30dbe5c SQSCANGHA-138 Update dist and add ci test (#233)
  • c835722 SQSCANGHA-134 Upgrade the libraries to latest version (#227)
  • f00de44 SC-45750 Migrate to dateless license headers (#229)
  • f099b44 SQSCANGHA-133 Upgrade the Node version used in UTs + contribution guide (#226)
  • d899ed2 BUILD-10861 Dependabot 5-day cooldown + internal excludes (#225)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 7.1.0 to 7.2.1.
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](SonarSource/sonarqube-scan-action@v7.1.0...v7.2.1)

---
updated-dependencies:
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 7.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 29, 2026

Labels

The following labels could not be found: dependencies, 🔍 enhancement, 🤖 github actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot requested a review from Chisanan232 as a code owner April 29, 2026 08:57
@Chisanan232
Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 2, 2026

Dependabot can't parse your native-core-build.yml. Because of this, Dependabot cannot update this pull request.

@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented May 2, 2026

@codecov
Copy link
Copy Markdown

codecov Bot commented May 2, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Copy link
Copy Markdown
Contributor

@Chisanan232 Chisanan232 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CI is fully green after rebasing onto master (which includes the dependabot actor guard fix from PR #23). All tests, codecov uploads, and SonarCloud analysis passed. Approving for merge.

@Chisanan232 Chisanan232 merged commit 9335962 into master May 2, 2026
22 checks passed
@Chisanan232 Chisanan232 deleted the dependabot/github_actions/SonarSource/sonarqube-scan-action-7.2.1 branch May 2, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant