omec-project / sdcore-helm-charts

Helm charts used for SD-Core packaging
8 stars 8 forks source link

Bump burnett01/rsync-deployments from 7.0.0 to 7.0.1 #27

Closed dependabot[bot] closed 4 months ago

dependabot[bot] commented 4 months ago

Bumps burnett01/rsync-deployments from 7.0.0 to 7.0.1.

Release notes

Sourced from burnett01/rsync-deployments's releases.

7.0.1

The docker image of this action is now pinned to the specific SHA-256 hash of the version rather than just the version. This means for the latest drinternet/rsync:v1.4.4 the corresponding hash is drinternet/rsync@sha256:15b2949838074bd93c49421c22380396a0cd53a322439e799ac87afcadcfe234

Check for validation: https://hub.docker.com/layers/drinternet/rsync/v1.4.4/images/sha256-15b2949838074bd93c49421c22380396a0cd53a322439e799ac87afcadcfe234

With that, usage of this action is even more secure due to a consistent dependency chain of trust, since changes accompanied by a docker image hash are immutable.

Thanks to @​XComp

Commits
  • 796cf0d Merge pull request #61 from Burnett01/release/7.0.1
  • b2bc75a Merge pull request #60 from XComp/use-hash-instead-of-version-tag
  • 93c0d7a upd: mention version 7.0.1
  • 13aa4f9 update year to 2024
  • b166140 Use SHA instead of Docker version tag for base image to allow for consistent ...
  • e1c5b90 Merge pull request #59 from Burnett01/release/7.0.0
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
gab-arrobo commented 4 months ago

@dependabot merge