Repository navigation
Releases: platform-sec/opengrep-action
Releases · platform-sec/opengrep-action
Release list
Release v2.0.1
What's Changed
Features
- feat: add Marketplace branding icon and color
Bug Fixes
- fix(ci): accept dotted prerelease suffixes in release tags
- fix(ci): stop floating major tags from triggering releases
- fix(ci): give the major version tag job a git identity
Security
Documentation
- docs: document SHA pinning and use an explicit placeholder
Testing
Other Changes
- ci: bump softprops/action-gh-release from 2.6.2 to 3.0.2
- ci: bump actions/download-artifact from 4.3.0 to 8.0.1
- ci: bump actions/upload-artifact from 4.6.2 to 7.0.1
Full Changelog: https://github.com/platform-sec/opengrep-action/compare/v2.0.0..v2.0.1
Installation
- name: Run OpenGrep Security Scan
uses: platform-sec/opengrep-action@v2.0.1
with:
target: 'src/'
patterns: 'auto'
severity: 'WARNING'Security
This release has been automatically scanned for security vulnerabilities.
Download the security scan results from the release workflow artifacts.
Verification
To verify the integrity of this release:
# Download and verify checksums
curl -L https://github.com/platform-sec/opengrep-action/releases/download/v2.0.1/checksums.txt
sha256sum -c checksums.txtRelease v2.0.0
Changes in v2.0.0
🚀 New Features
- feat!: install the signed OpenGrep CLI asset and verify its signature
- feat: release v1.0.0
🐛 Bug Fixes
- fix(ci): generate real release notes and let curated notes reach the release
- fix(ci): make release tooling produce correct notes and mergeable PRs
- fix(ci): repair the OpenGrep version bump workflow
🔒 Security Updates
📝 Documentation
🧪 Testing
- test: bump tests/unit/bats from
5da6687toeb7f42f
Other Changes
- ci: bump actions/checkout from 4.3.1 to 7.0.1
- ci: bump step-security/harden-runner in the actions-minor-patch group
- ci: track the action supply chain with Dependabot and pin test deps
- ci: run hosted tests natively instead of through act
- chore: initialize repository