deps: ci: bump anchore/scan-action from 3 to 7
- Dominant language
- Go
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Dependabot Update
Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 3 to 7.
Release notes
Sourced from anchore/scan-action's releases.
v7.0.0
New in scan-action v7.0.0
- chore(deps): update Grype to v0.100.0 (#516)
v6.5.1
New in scan-action v6.5.1
- Update Grype to v0.97.1 (#495)
v6.5.0
New in scan-action v6.5.0
- Update Grype to v0.96.1 (#493) [[anchore-actions-token-generator[bot]](https://github.com/[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator))]
- fix: output stderr for nonzero exit code (#491) [kzantow]
v6.4.0
New in scan-action v6.4.0
- Update Grype to v0.95.0 (#486)
- chore(deps-dev): bump eslint from 9.30.0 to 9.30.1 (#485)
- chore(deps-dev): bump lint-staged from 16.1.0 to 16.1.2 (#476)
- chore(deps-dev): bump jest from 30.0.0 to 30.0.3 (#481)
- chore(deps-dev): bump prettier from 3.5.3 to 3.6.2 (#483)
- chore(deps-dev): bump eslint from 9.28.0 to 9.30.0 (#484)
v6.3.0
New in scan-action v6.3.0
- Update Grype to v0.94.0 (#470)
v6.2.0
New in scan-action v6.2.0
v6.1.0
New in scan-action v6.1.0
- Feature (deps): update Grype to v0.87.0 (#430)
v6.0.0
New in scan-action v6.0.0
Breaking Change
The action no longer generates files in your working directory by default, instead you should use the action outputs:
${{ steps.<id>.outputs.sarif }}where the<id>needs to match theidyou configured to reference thescan-action, e.g.:</tr></table>
... (truncated)
Commits
3c9a191chore(deps): update Grype to v0.104.2 (#557)0a9fbe8chore(deps-dev): bump lint-staged from 16.2.6 to 16.2.7 (#547)5ac7f2achore(deps-dev): bump prettier from 3.6.2 to 3.7.4 (#555)563e915chore(deps): bump peter-evans/create-pull-request from 7.0.8 to 7.0.11 (#556)49c6d26chore(deps): bump actions/checkout from 5.0.0 to 6.0.1 (#554)77906c3chore(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#553)ed82e81chore(deps): bump glob from 10.4.5 to 10.5.0 (#546)40a61b5chore(deps): update Grype to v0.104.1 (#550)a958206chore(deps-dev): bump eslint from 9.39.0 to 9.39.1 (#540)ff5ff9echore(deps-dev): bump js-yaml from 3.14.1 to 3.14.2 (#544)- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
## Pull Request
- PR: #34
- Author: @dependabot[bot]
- URL: https://github.com/aRustyDev/pcf-mcp/pull/34
---
This issue was automatically created to track the Dependabot update.
Contributor guide
Assessment
This issue has not been assessed yet.