Uh oh!
There was an error while loading. Please reload this page.
chore(deps): bump the github-actions-dependencies group with 2 updates - #1070
Conversation
Bumps the github-actions-dependencies group with 2 updates: [actions/attest](https://github.com/actions/attest) and [docker/login-action](https://github.com/docker/login-action). Updates `actions/attest` from 4.2.0 to 4.2.1 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@v4.2.0...v4.2.1) Updates `docker/login-action` from 4.5.2 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4.5.2...v4.6.0) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-dependencies - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Claude finished @dependabot[bot]'s task in 51s —— View job Dependabot review — GitHub Actions bump ✅
Verdict: safe to merge. Both are patch/minor bumps with no breaking changes affecting this repo.
|
Uh oh!
There was an error while loading. Please reload this page.
Bumps the github-actions-dependencies group with 2 updates: actions/attest and docker/login-action.
Updates
actions/attestfrom 4.2.0 to 4.2.1Release notes
Sourced from actions/attest's releases.
Commits
508db95fix: strip OCI image tag when pushing attestation to registry (#464)dda48f2Bump the npm-development group across 1 directory with 6 updates (#461)7d789a3Bump the actions-minor group with 3 updates (#463)1f3ca2fAdd release-cutter canvas extension (#454)d215549Bump tar from 7.5.17 to 7.5.21 (#459)20c90edBump the npm-development group with 2 updates (#455)43c2c81Bump the actions-minor group with 4 updates (#456)f1d64fbBump actions/setup-node from 6.4.0 to 7.0.0 (#457)Updates
docker/login-actionfrom 4.5.2 to 4.6.0Release notes
Sourced from docker/login-action's releases.
Commits
dbcb813Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015[dependabot skip] chore: update generated contentb30b2f2build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...9087f1eMerge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830[dependabot skip] chore: update generated content2325523build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4aMerge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99baMerge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...e512bd5Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...a146c91Merge pull request #1059 from crazy-max/harden-buildx-scope-pathsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions