Skip to content
This repository was archived by the owner on Jul 10, 2026. It is now read-only.

chore(deps): bump anchore/sbom-action from 0.15.9 to 0.17.0 - #79

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anchore/sbom-action-0.17.0
Open

chore(deps): bump anchore/sbom-action from 0.15.9 to 0.17.0#79
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anchore/sbom-action-0.17.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJul 22, 2024

Copy link
Copy Markdown
Contributor

Bumps anchore/sbom-action from 0.15.9 to 0.17.0.

Release notes

Sourced from anchore/sbom-action's releases.

v0.17.0

Changes in v0.17.0

v0.16.1

Changes in v0.16.1

v0.16

Changes in v0.16.0

NOTE: if you are using this action within a matrix build and see failures attempting to upload artifacts with duplicate names, you will need to set the artifact-name to be unique based on the matrix properties (an example here). This is due to a change to use a newer GitHub API which no longer allows artifacts with duplicate names.

v0.15.11

Changes in v0.15.11

v0.15.10

Changes in v0.15.10

Commits
  • d94f46e chore(deps): update Syft to v1.9.0 (#479)
  • ee41e6a chore(deps): bump actions/checkout from 4.1.6 to 4.1.7 (#474)
  • 23e0b38 chore(deps): bump peter-evans/create-pull-request from 6.0.5 to 6.1.0 (#475)
  • f4035cd chore: serialize tests to prevent install race (#478)
  • f3253ca chore(deps): update Syft to v1.8.0 (#473)
  • 95b086a fix: workaround windows install script (#477)
  • 72370e1 fix: allow users to properly use the file input over the default path value (...
  • e28bab5 chore(deps): update Syft to v1.5.0 (#470)
  • 2283abe docs: notes for matrix and required permissions (#469)
  • 07e5b3a chore(deps): bump actions/checkout from 4.1.5 to 4.1.6 (#466)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.15.9 to 0.17.0.
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Commits](anchore/sbom-action@v0.15.9...v0.17.0)
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBot requested a review from a team as a code ownerJuly 22, 2024 03:15
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 22, 2024
@github-actions

Copy link
Copy Markdown
Contributor
PackageLine RateComplexityHealth
github.com/aws/codecatalyst-runner-cli/codecatalyst-runner/cmd68%0
github.com/aws/codecatalyst-runner-cli/codecatalyst-runner/pkg/actions76%0
github.com/aws/codecatalyst-runner-cli/codecatalyst-runner/pkg/workflows63%0
github.com/aws/codecatalyst-runner-cli/command-runner/internal/containers/docker15%0
github.com/aws/codecatalyst-runner-cli/command-runner/internal/fs31%0
github.com/aws/codecatalyst-runner-cli/command-runner/pkg/common72%0
github.com/aws/codecatalyst-runner-cli/command-runner/pkg/features51%0
github.com/aws/codecatalyst-runner-cli/command-runner/pkg/runner60%0
Summary50% (1675 / 3373)0

Minimum allowed line rate is 48%

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@codecatalyst-runner-cli-bot