GenomicDataInfrastructure / gdi-userportal-ckan-docker

Scripts and images to run CKAN using Docker Compose
0 stars 2 forks source link

chore(deps): update aquasecurity/trivy-action action to v0.29.0 #147

Closed LNDS-Sysadmins closed 1 week ago

LNDS-Sysadmins commented 1 week ago

This PR contains the following updates:

Package Type Update Change
aquasecurity/trivy-action action minor 0.28.0 -> 0.29.0

Release Notes

aquasecurity/trivy-action (aquasecurity/trivy-action) ### [`v0.29.0`](https://redirect.github.com/aquasecurity/trivy-action/releases/tag/0.29.0) [Compare Source](https://redirect.github.com/aquasecurity/trivy-action/compare/0.28.0...0.29.0) ##### What's Changed - feat: Allow skipping setup by [@​rvesse](https://redirect.github.com/rvesse) in [https://github.com/aquasecurity/trivy-action/pull/414](https://redirect.github.com/aquasecurity/trivy-action/pull/414) - Fix oras command not found in "Update Trivy Cache" action by [@​Tiryoh](https://redirect.github.com/Tiryoh) in [https://github.com/aquasecurity/trivy-action/pull/413](https://redirect.github.com/aquasecurity/trivy-action/pull/413) - Update README.md by [@​simar7](https://redirect.github.com/simar7) in [https://github.com/aquasecurity/trivy-action/pull/420](https://redirect.github.com/aquasecurity/trivy-action/pull/420) - feat: add token for `setup-trivy` by [@​DmitriyLewen](https://redirect.github.com/DmitriyLewen) in [https://github.com/aquasecurity/trivy-action/pull/421](https://redirect.github.com/aquasecurity/trivy-action/pull/421) - fix: bump `setup-trivy` and add new `contrib` directory path info by [@​DmitriyLewen](https://redirect.github.com/DmitriyLewen) in [https://github.com/aquasecurity/trivy-action/pull/424](https://redirect.github.com/aquasecurity/trivy-action/pull/424) - docs: remove ignore-unfixed from IaC scan example by [@​nikpivkin](https://redirect.github.com/nikpivkin) in [https://github.com/aquasecurity/trivy-action/pull/429](https://redirect.github.com/aquasecurity/trivy-action/pull/429) - chore(deps): Bump trivy to v0.57.1 by [@​simar7](https://redirect.github.com/simar7) in [https://github.com/aquasecurity/trivy-action/pull/434](https://redirect.github.com/aquasecurity/trivy-action/pull/434) ##### New Contributors - [@​rvesse](https://redirect.github.com/rvesse) made their first contribution in [https://github.com/aquasecurity/trivy-action/pull/414](https://redirect.github.com/aquasecurity/trivy-action/pull/414) - [@​Tiryoh](https://redirect.github.com/Tiryoh) made their first contribution in [https://github.com/aquasecurity/trivy-action/pull/413](https://redirect.github.com/aquasecurity/trivy-action/pull/413) **Full Changelog**: https://github.com/aquasecurity/trivy-action/compare/0.28.0...0.29.0

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot.

sourcery-ai[bot] commented 1 week ago

Reviewer's Guide by Sourcery

This PR updates the aquasecurity/trivy-action GitHub Action from version 0.28.0 to 0.29.0 in the workflow files. The update includes several improvements such as the ability to skip setup, fixes for the ORAS command, and a bump in the underlying Trivy version to v0.57.1.

No diagrams generated as the changes look simple and do not need a visual representation.

File-Level Changes

Change Details Files
Update Trivy action version in GitHub workflow files
  • Update aquasecurity/trivy-action from 0.28.0 to 0.29.0
  • Maintain existing configuration parameters for Trivy scanning
.github/workflows/main.yml
.github/workflows/release.yml

Possibly linked issues


Tips and commands #### Interacting with Sourcery - **Trigger a new review:** Comment `@sourcery-ai review` on the pull request. - **Continue discussions:** Reply directly to Sourcery's review comments. - **Generate a GitHub issue from a review comment:** Ask Sourcery to create an issue from a review comment by replying to it. - **Generate a pull request title:** Write `@sourcery-ai` anywhere in the pull request title to generate a title at any time. - **Generate a pull request summary:** Write `@sourcery-ai summary` anywhere in the pull request body to generate a PR summary at any time. You can also use this command to specify where the summary should be inserted. #### Customizing Your Experience Access your [dashboard](https://app.sourcery.ai) to: - Enable or disable review features such as the Sourcery-generated pull request summary, the reviewer's guide, and others. - Change the review language. - Add, remove or edit custom review instructions. - Adjust other review settings. #### Getting Help - [Contact our support team](mailto:support@sourcery.ai) for questions or feedback. - Visit our [documentation](https://docs.sourcery.ai) for detailed guides and information. - Keep in touch with the Sourcery team by following us on [X/Twitter](https://x.com/SourceryAI), [LinkedIn](https://www.linkedin.com/company/sourcery-ai/) or [GitHub](https://github.com/sourcery-ai).
sonarcloud[bot] commented 1 week ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud