Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the actions group with 3 updates in the / directory: sigstore/cosign-installer, anchore/sbom-action and actions/attest-build-provenance.
Updates
sigstore/cosign-installer
from 3.5.0 to 3.6.0Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
4959ce0
update readme for new release (#170)45ffe83
bump default version to v2.4.0 release (#168)7e1d9c1
pin public key used for verification (#169)cc23fe1
Bump actions/setup-go from 5.0.1 to 5.0.2 (#167)b235ed9
Bump actions/checkout from 4.1.6 to 4.1.7 (#166)b49ef6b
Bump actions/checkout from 4.1.5 to 4.1.6 (#165)7a59e5a
Bump actions/checkout from 4.1.4 to 4.1.5 (#164)8d927bd
Bump actions/setup-go from 5.0.0 to 5.0.1 (#163)8c9caa0
Bump actions/checkout from 4.1.3 to 4.1.4 (#162)19351d0
Bump actions/checkout from 4.1.2 to 4.1.3 (#161)Updates
anchore/sbom-action
from 0.17.0 to 0.17.2Release notes
Sourced from anchore/sbom-action's releases.
Commits
61119d4
chore(deps): update Syft to v1.11.1 (#485)ab9d16d
chore(deps): update Syft to v1.11.0 (#483)fe5e7c3
doc: Updates for the Slack to Discourse migration (#484)f2d02cb
chore: Create issue template (#481)ca15f99
docs: CODE_OF_CONDUCT.md (#480)Updates
actions/attest-build-provenance
from 1.4.0 to 1.4.2Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
6149ea5
bump actions/attest from 1.4.0 to 1.4.1 (#209)3eb3242
Bump super-linter/super-linter from 6 to 7 (#205)399bb17
Bump@types/node
from 22.2.0 to 22.4.0 in the npm-development group (#203)9f60666
Bump the npm-development group with 2 updates (#199)310b0a4
update predicate action to 1.1.2 (#197)d58ddf9
dynamic construction of oidc issuer (#195)f9d4126
Bump@typescript-eslint/parser
from 7.17.0 to 7.18.0 (#188)588eda3
Bump the npm-development group with 3 updates (#187)48f71d5
disable typescript-standard super linter (#191)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show