bridgecrewio / yor

Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified resource which created it.
https://www.yor.io
Apache License 2.0
795 stars 121 forks source link

Bump tj-actions/verify-changed-files from 16.0.0 to 17.0.2 #461

Closed dependabot[bot] closed 6 months ago

dependabot[bot] commented 6 months ago

Bumps tj-actions/verify-changed-files from 16.0.0 to 17.0.2.

Release notes

Sourced from tj-actions/verify-changed-files's releases.

v17.0.2

What's Changed

Full Changelog: https://github.com/tj-actions/verify-changed-files/compare/v17...v17.0.2

v17.0.1

What's Changed

Full Changelog: https://github.com/tj-actions/verify-changed-files/compare/v17...v17.0.1

v17.0.0

🔥 🔥 BREAKING CHANGE 🔥 🔥

A new safe_output input is now available to prevent outputting unsafe filename characters (Enabled by default). This would escape characters in the filename that could be used for command injection.

[!NOTE] This can be disabled by setting the safe_output to false this comes with a recommendation to store all outputs generated in an environment variable first before using them.

Example

...
      - name: Verify Changed files
        uses: tj-actions/verify-changed-files@v16
        id: verify-changed-files
        with:
          safe_output: false # set to false because we are using an environment variable to store the output and avoid command injection.
  - name: List all changed tracked and untracked files
    env:
      FILES_CHANGED: ${{ steps.verify-changed-files.outputs.changed_files }}
    run: |
      echo "Changed files: $FILES_CHANGED

...

What's Changed

... (truncated)

Changelog

Sourced from tj-actions/verify-changed-files's changelog.

Changelog

17.0.2 - (2024-01-04)

📝 Other

  • PR #363: update tj-actions/glob action to v18 (0a07b6e) - (repo-ranger[bot])
  • PR #361: to v17.0.1 (56d4ba3) - (repo-ranger[bot])

⚙️ Miscellaneous Tasks

  • Update test (#362) (b742fc9) - (Tonye Jack)
  • deps: Update tj-actions/glob action to v18 (071c65e) - (renovate[bot])

⬆️ Upgrades

  • Upgraded from v17.0.0 -> v17.0.1 (43232db) - (jackton1)

17.0.1 - (2024-01-04)

🐛 Bug Fixes

  • Bug with adding separator to output (#360) (4321d85) - (Tonye Jack)

📝 Other

  • PR #359: update tj-actions/verify-changed-files action to v17 (2a93ea6) - (repo-ranger[bot])

⚙️ Miscellaneous Tasks

  • deps: Update tj-actions/verify-changed-files action to v17 (5cb319c) - (renovate[bot])

⬆️ Upgrades

  • Upgraded to v17 (#358)

Co-authored-by: jackton1 jackton1@users.noreply.github.com (0d4817f) - (tj-actions[bot])

17.0.0 - (2023-12-29)

📦 Bumps

  • Bump actions/checkout from 4.1.0 to 4.1.1 (#345)

Co-authored-by: dependabot[bot] (6d68896) - (dependabot[bot])

➕ Add

... (truncated)

Commits
  • b742fc9 chore: update test (#362)
  • 0a07b6e Merge pull request #363 from tj-actions/renovate/tj-actions-glob-18.x
  • 071c65e chore(deps): update tj-actions/glob action to v18
  • 56d4ba3 Merge pull request #361 from tj-actions/upgrade-to-v17.0.1
  • 43232db Upgraded from v17.0.0 -> v17.0.1
  • 4321d85 fix: bug with adding separator to output (#360)
  • 2a93ea6 Merge pull request #359 from tj-actions/renovate/tj-actions-verify-changed-fi...
  • 5cb319c chore(deps): update tj-actions/verify-changed-files action to v17
  • 0d4817f Upgraded to v17 (#358)
  • bc950d8 Update README.md
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 6 months ago

Superseded by #465.