Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump docker/scout-action from 1.15.1 to 1.16.1 #352

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 16, 2024

Bumps docker/scout-action from 1.15.1 to 1.16.1.

Release notes

Sourced from docker/scout-action's releases.

v1.16.1

What's Changed

  • Fix in-toto subject digest for the docker scout attestation add command by @​cdupuis

v1.16.0

What's Changed

  • Add secret scanning to sbom command by @​cdupuis
  • Keep original pattern to find nested matches too by @​cdupuis
  • Make licenses unqiue by @​cdupuis
  • Print platform in markdown output by @​cdupuis
  • Normalize licenses using spdx license list by @​cdupuis
  • Updates to make spdx output spec compliant by @​cdupuis
  • Check dir exists before creating temp file by @​chrispatrick
  • Update Go, crypto module and alpine by @​cdupuis
  • Add support for attestations for images from Tanzu Application Catalog by @​cdupuis
  • Fix behaviour with multi images in attest cmd by @​cdupuis
Commits
  • b23590d Merge 95bd05b11d612059dab025c80072e80894133594 into d3343f4e1411fc42690966f3a...
  • 95bd05b [BOT] Publish v1.16.1 release
  • d3343f4 Update CODEOWNERS
  • 4d5cab6 Merge 2bfc559301a561e2462f0eba7d35917644f0e71e into 6ac950eb733f8b2811f25c05d...
  • 2bfc559 [BOT] Publish v1.16.0 release
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [docker/scout-action](https://github.com/docker/scout-action) from 1.15.1 to 1.16.1.
- [Release notes](https://github.com/docker/scout-action/releases)
- [Commits](docker/scout-action@v1.15.1...v1.16.1)

---
updated-dependencies:
- dependency-name: docker/scout-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant