You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot will merge this PR once it's up-to-date and CI passes on it, as requested by @spencerschrock.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps github.com/google/osv-scanner from 1.8.2 to 1.8.3.
Release notes
Sourced from github.com/google/osv-scanner's releases.
Changelog
Sourced from github.com/google/osv-scanner's changelog.
Commits
18ab43f
Merge branch 'main' into release830002d
chore: update dependencygithub.com/docker/docker
(#1166)4c71abb
chore(deps-dev): bump rexml from 3.3.2 to 3.3.3 in /docs in the bundler group...a9eda5b
add maven changes587d9a9
Merge branch 'main' into releasef8eacda
feat(guided remediation): add non-interactive Maven remediation by override (...8aa4d7b
Label closed stale issues/PRs (#1165)8907a11
Fix snapshots (#1164)1f17ba2
Refactoring Maven manifest reading (#1159)0eed440
Do not attempt to remediate vulnerabilities in Maven artifacts that have defi...You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot will merge this PR once it's up-to-date and CI passes on it, as requested by @spencerschrock.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show