spdx / ntia-conformance-checker

Check SPDX SBOM for NTIA minimum elements
Apache License 2.0
55 stars 20 forks source link

Bump tj-actions/bandit from 5.1 to 5.5 #209

Closed dependabot[bot] closed 4 weeks ago

dependabot[bot] commented 1 month ago

Bumps tj-actions/bandit from 5.1 to 5.5.

Release notes

Sourced from tj-actions/bandit's releases.

v5.5

What's Changed

New Contributors

Full Changelog: https://github.com/tj-actions/bandit/compare/v5...v5.5

v5.4

What's Changed

... (truncated)

Changelog

Sourced from tj-actions/bandit's changelog.

Changelog

5.5 - (2023-09-07)

📦 Bumps

  • Bump python from 3.11.3-slim-buster to 3.11.4-slim-buster

Bumps python from 3.11.3-slim-buster to 3.11.4-slim-buster.


updated-dependencies:

  • dependency-name: python dependency-type: direct:production update-type: version-update:semver-patch ...

Signed-off-by: dependabot[bot] support@github.com (e30a211) - (dependabot[bot])

  • Bump tj-actions/branch-names from 6 to 7

Bumps tj-actions/branch-names from 6 to 7.


updated-dependencies:

  • dependency-name: tj-actions/branch-names dependency-type: direct:production update-type: version-update:semver-major ...

Signed-off-by: dependabot[bot] support@github.com (7f26cd0) - (dependabot[bot])

➖ Remove

  • Deleted .github/ISSUE_TEMPLATE/feature_request.yaml (e29b49b) - (Tonye Jack)
  • Deleted .github/ISSUE_TEMPLATE/bug_report.yaml (f239d8e) - (Tonye Jack)
  • Deleted .github/FUNDING.yml (2e9484f) - (Tonye Jack)
  • Deleted .github/workflows/auto-merge.yml (fda37aa) - (Tonye Jack)

🔄 Update

  • Updated README.md (74c938f) - (repo-ranger[bot])
  • Updated .github/FUNDING.yml (75e2ea0) - (Tonye Jack)
  • Updated .github/FUNDING.yml (6ee6365) - (Tonye Jack)
  • Updated renovate.json (497bb85) - (Tonye Jack)
  • Updated README.md (0e5ccbc) - (jackton1)

... (truncated)

Commits
  • 0aed5b3 chore(deps): update reviewdog/action-shellcheck action to v1.19
  • 57138c0 Merge pull request #221 from tj-actions/renovate/actions-checkout-4.x
  • 4d66f1d chore(deps): update actions/checkout action to v4
  • e29b49b Deleted .github/ISSUE_TEMPLATE/feature_request.yaml
  • f239d8e Deleted .github/ISSUE_TEMPLATE/bug_report.yaml
  • 2e9484f Deleted .github/FUNDING.yml
  • b042b3f chore(deps): update docker/setup-buildx-action action to v2.10.0
  • fdd2b11 Merge pull request #219 from tj-actions/renovate/tj-actions-release-tagger-4.x
  • a9d7d83 chore(deps): update tj-actions/release-tagger action to v4
  • bef8732 chore(deps): update actions/checkout action to v3.6.0
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
jspeed-meyers commented 1 month ago

@dependabot rebase