Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(ci)(deps): Bump rustsec/audit-check from 0.1.0 to 1.4.1 #123

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 10, 2023

Bumps rustsec/audit-check from 0.1.0 to 1.4.1.

Release notes

Sourced from rustsec/audit-check's releases.

v1.4.1

  • Further corrected reporting on unsound and notice informationals

v1.4.0

  • Informational unsound and notice advisories are now relayed correctly #9

Thanks @​FabianLars for reporting 🥳

v1.3.2

  • Bumped to node16 and fixed outdated dependencies

In case someone reads CHANGELOG this is a v1 release mirror.

v1

This is directly-compatible fork-version from actions-rs/audit-check.

This will not be updated beyond to reflect v1.3.2 so please use the point versions on and after v1.4.0

Changelog

Sourced from rustsec/audit-check's changelog.

[1.4.1] - 2023-04-04

Fixed

  • Corrected reporting on unsound and notice informationals

[1.4.0] - 2023-04-04

Fixed

  • Reflect change to enable warning on unsound and notice informationals

[1.3.2] - 2023-03-13

Changed

  • Update various dependencies to fix some known vulnerabilities.

[1.3.1] - 2020-05-10

Fixed

  • GitHub Actions does not support sequences as input

[1.3.0] - 2022-05-09

Added

  • Add support for ignores (#1)

[1.2.0] - 2020-05-07

Fixed

  • Compatibility with latest cargo-audit == 0.12 JSON output (#115)
  • Do not fail check if no critical vulnerabilities were found when executed for a fork repository (closes #104)

[1.1.0]

Fixed

  • Invalid input properly terminates Action execution (#1)
  • Compatibility with new cargo-audit JSON output (#70)

[1.0.0] - 2019-10-09

Added

  • First public version
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [rustsec/audit-check](https://github.com/rustsec/audit-check) from 0.1.0 to 1.4.1.
- [Release notes](https://github.com/rustsec/audit-check/releases)
- [Changelog](https://github.com/rustsec/audit-check/blob/main/CHANGELOG.md)
- [Commits](rustsec/audit-check@v0.1.0...v1.4.1)

---
updated-dependencies:
- dependency-name: rustsec/audit-check
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner April 10, 2023 23:00
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions labels Apr 10, 2023
@codecov
Copy link

codecov bot commented Apr 10, 2023

Codecov Report

Merging #123 (54d3c98) into main (7ecf856) will decrease coverage by 1.10%.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #123      +/-   ##
==========================================
- Coverage   42.40%   41.31%   -1.10%     
==========================================
  Files          28       28              
  Lines        1462     1462              
  Branches      369      388      +19     
==========================================
- Hits          620      604      -16     
  Misses        630      630              
- Partials      212      228      +16     

see 5 files with indirect coverage changes

@zeeshanlakhani zeeshanlakhani merged commit c34c92f into main Apr 13, 2023
@zeeshanlakhani zeeshanlakhani deleted the dependabot/github_actions/main/rustsec/audit-check-1.4.1 branch April 13, 2023 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant