Skip to content

chore(deps): Bump anchore/scan-action from 7.4.0 to 7.4.2 - #26

Merged
kevinpinscoe merged 1 commit into
mainfrom
dependabot/github_actions/anchore/scan-action-7.4.2
Sep 5, 2026
Merged

chore(deps): Bump anchore/scan-action from 7.4.0 to 7.4.2#26
kevinpinscoe merged 1 commit into
mainfrom
dependabot/github_actions/anchore/scan-action-7.4.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps anchore/scan-action from 7.4.0 to 7.4.2.

Release notes

Sourced from anchore/scan-action's releases.

v7.4.2

Additional Changes

(Full Changelog)

Commits
  • 27805bf chore(deps): update Grype to latest release (#755) (#756)
  • 8964e60 chore(deps): update Grype to latest release (#755)
  • 6875336 chore: bump fast-xml-parser from 5.5.8 to 5.7.3 (#654)
  • 65b5fb1 chore: bump esbuild from 0.28.0 to 0.28.2 (#753)
  • b905e0e chore(deps): update Grype to latest release (#713)
  • e49c028 fix: pin grype install.sh to the release tag being installed (#750)
  • db8f0b6 chore: bump globals from 17.9.0 to 17.11.0 (#754)
  • 35bf076 chore: bump eslint from 10.8.0 to 10.8.1 (#752)
  • bd77fb5 chore: bump anchore/workflows/.github/workflows/check-gate.yaml (#720)
  • d04f6c4 chore: bump lint-staged from 17.2.0 to 17.3.0 (#748)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 7.4.0 to 7.4.2.
- [Release notes](https://github.com/anchore/scan-action/releases)
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md)
- [Commits](anchore/scan-action@e116508...27805bf)
---
updated-dependencies:
- dependency-name: anchore/scan-action
dependency-version: 7.4.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 2, 2026
@kevinpinscoe
kevinpinscoe merged commit 3774be3 into mainSep 5, 2026
1 check passed
@dependabot
dependabotBot deleted the dependabot/github_actions/anchore/scan-action-7.4.2 branch September 5, 2026 23:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@kevinpinscoe