Closed dependabot[bot] closed 3 months ago
Latest commit: |
fe80ac4
|
Status: | ✅ Deploy successful! |
Preview URL: | https://f53a21ba.safedep-vet.pages.dev |
Branch Preview URL: | https://dependabot-go-modules-github-90m2.safedep-vet.pages.dev |
This report is generated by vet
Go
] golang.org/x/exp@0.0.0-20240719175910-8a7402abbf56
Go
] github.com/google/osv-scanner@1.8.3
Go
] github.com/owenrumney/go-sarif/v2@2.3.3
Looks like github.com/google/osv-scanner is up-to-date now, so this is no longer needed.
Bumps github.com/google/osv-scanner from 1.8.2 to 1.8.3.
Release notes
Sourced from github.com/google/osv-scanner's releases.
Changelog
Sourced from github.com/google/osv-scanner's changelog.
Commits
18ab43f
Merge branch 'main' into release830002d
chore: update dependencygithub.com/docker/docker
(#1166)4c71abb
chore(deps-dev): bump rexml from 3.3.2 to 3.3.3 in /docs in the bundler group...a9eda5b
add maven changes587d9a9
Merge branch 'main' into releasef8eacda
feat(guided remediation): add non-interactive Maven remediation by override (...8aa4d7b
Label closed stale issues/PRs (#1165)8907a11
Fix snapshots (#1164)1f17ba2
Refactoring Maven manifest reading (#1159)0eed440
Do not attempt to remediate vulnerabilities in Maven artifacts that have defi...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show