KristjanESPERANTO / MMM-PublicTransportHafas

This is a module for MagicMirrorΒ² to display public transport departures.
MIT License
17 stars 6 forks source link

Bump github/codeql-action from 2 to 3 #156

Closed dependabot[bot] closed 8 months ago

dependabot[bot] commented 8 months ago

Bumps github/codeql-action from 2 to 3.

Release notes

Sourced from github/codeql-action's releases.

CodeQL Bundle v2.15.5

Bundles CodeQL CLI v2.15.5

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.5:

CodeQL Bundle v2.15.4

Bundles CodeQL CLI v2.15.4

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.4:

CodeQL Bundle

Bundles CodeQL CLI v2.15.3

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.3:

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

Commits
  • e0c2b0a change version numbers inside processing function as well
  • 8e4a6c7 improve handling of changelog processing for backports
  • 511f073 Merge pull request #2033 from github/dependabot/npm_and_yarn/npm-0a98872b3d
  • ebf5a83 Merge pull request #2035 from github/mergeback/v3.22.11-to-main-b374143c
  • 7813bda Update checked-in dependencies
  • 2b2fb6b Update changelog and version after v3.22.11
  • b374143 Merge pull request #2034 from github/update-v3.22.11-64e61baea
  • 95591ba Merge branch 'main' into dependabot/npm_and_yarn/npm-0a98872b3d
  • e2b5cc7 Update changelog for v3.22.11
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
github-actions[bot] commented 8 months ago

πŸ¦™ MegaLinter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Elapsed time
βœ… ACTION actionlint 5 0 0.1s
βœ… COPYPASTE jscpd yes no 1.89s
❌ CSS stylelint 10 0 1 0.88s
❌ JSON eslint-plugin-jsonc 7 0 1 0.57s
βœ… JSON jsonlint 7 0 0.3s
βœ… JSON npm-package-json-lint yes no 0.61s
βœ… JSON prettier 7 0 0 0.7s
βœ… JSON v8r 7 0 8.39s
βœ… MARKDOWN markdownlint 4 0 0 1.48s
βœ… MARKDOWN markdown-link-check 4 0 3.89s
βœ… REPOSITORY checkov yes no 12.01s
βœ… REPOSITORY gitleaks yes no 1.21s
βœ… REPOSITORY git_diff yes no 0.04s
βœ… REPOSITORY grype yes no 11.73s
βœ… REPOSITORY secretlint yes no 0.82s
βœ… REPOSITORY trivy yes no 6.49s
βœ… REPOSITORY trivy-sbom yes no 6.56s
βœ… REPOSITORY trufflehog yes no 21.07s
βœ… SPELL lychee 19 0 1.46s
βœ… YAML prettier 8 0 0 0.73s
βœ… YAML v8r 8 0 6.35s
βœ… YAML yamllint 8 0 0.42s

See detailed report in MegaLinter reports

_MegaLinter is graciously provided by OX Security_