Open dependabot[bot] opened 1 week ago
The following labels could not be found: Type: Security Patch
.
[!IMPORTANT]
Review skipped
Ignore keyword(s) in the title.
:no_entry: Ignored keywords (1)
* chore(deps):Please check the settings in the CodeRabbit UI or the
.coderabbit.yaml
file in this repository. To trigger a single review, invoke the@coderabbitai review
command.You can disable this status message by setting the
reviews.review_status
tofalse
in the CodeRabbit configuration file.
Name | Link |
---|---|
Latest commit | beae97f5e4f2ec1fbd2949150101e772858b0c76 |
Latest deploy log | https://app.netlify.com/sites/veascan/deploys/673c37cf6221ad0008c62f3d |
Deploy Preview | https://deploy-preview-360--veascan.netlify.app |
Preview on mobile | Toggle QR Code...Use your smartphone camera to open QR code link. |
To edit notification comments on pull requests, go to your Netlify site configuration.
Bumps step-security/harden-runner from 2.4.0 to 2.10.2.
Release notes
Sourced from step-security/harden-runner's releases.
... (truncated)
Commits
0080882
Merge pull request #476 from step-security/rc-164a3a88b
Update dist556aae6
Merge pull request #480 from h0x0er/jatin/cleanup6c39b84
chore: clean the code40401cf
Update for isdocker806ab1c
Update check for isdocker2846811
update distdf8a07c
Merge pull request #475 from h0x0er/fix-execSync30636fb
bug fixes91182cc
Merge pull request #463 from step-security/rc-14Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show
PR-Codex overview
This PR updates the version of the
step-security/harden-runner
action across multiple workflow files to improve security and functionality.Detailed summary
step-security/harden-runner
fromv2.4.0
tov2.10.2
in:.github/workflows/scorecards.yml
.github/workflows/deploy-bots.yml
.github/workflows/sonarcloud.yml
.github/workflows/codeql-analysis.yml
.github/workflows/contracts-testing.yml
.github/workflows/dependency-review.yml