aRustyDev / aRustyDev/pcf-mcp

deps: ci: bump anchore/scan-action from 3 to 7

Open
#35 0 comments 0 reactions 0 assignees View on GitHub
dependencies github-actions
Dominant language
Go
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

## Dependabot Update

Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 3 to 7.

Release notes

Sourced from anchore/scan-action's releases.



v7.0.0


New in scan-action v7.0.0



  • chore(deps): update Grype to v0.100.0 (#516)


v6.5.1


New in scan-action v6.5.1



  • Update Grype to v0.97.1 (#495)


v6.5.0


New in scan-action v6.5.0



v6.4.0


New in scan-action v6.4.0



  • Update Grype to v0.95.0 (#486)

  • chore(deps-dev): bump eslint from 9.30.0 to 9.30.1 (#485)

  • chore(deps-dev): bump lint-staged from 16.1.0 to 16.1.2 (#476)

  • chore(deps-dev): bump jest from 30.0.0 to 30.0.3 (#481)

  • chore(deps-dev): bump prettier from 3.5.3 to 3.6.2 (#483)

  • chore(deps-dev): bump eslint from 9.28.0 to 9.30.0 (#484)


v6.3.0


New in scan-action v6.3.0



  • Update Grype to v0.94.0 (#470)


v6.2.0


New in scan-action v6.2.0



  • feat: update Scan action to use grype db v6 (#462) [spiffcs]


v6.1.0


New in scan-action v6.1.0



v6.0.0


New in scan-action v6.0.0


Breaking Change



  • feat: add output-file option, default to random directory output in temp (#346) [kzantow]


The action no longer generates files in your working directory by default, instead you should use the action outputs: ${{ steps.<id>.outputs.sarif }} where the <id> needs to match the id you configured to reference the scan-action, e.g.:


</tr></table> 



... (truncated)

Commits


  • 3c9a191 chore(deps): update Grype to v0.104.2 (#557)

  • 0a9fbe8 chore(deps-dev): bump lint-staged from 16.2.6 to 16.2.7 (#547)

  • 5ac7f2a chore(deps-dev): bump prettier from 3.6.2 to 3.7.4 (#555)

  • 563e915 chore(deps): bump peter-evans/create-pull-request from 7.0.8 to 7.0.11 (#556)

  • 49c6d26 chore(deps): bump actions/checkout from 5.0.0 to 6.0.1 (#554)

  • 77906c3 chore(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#553)

  • ed82e81 chore(deps): bump glob from 10.4.5 to 10.5.0 (#546)

  • 40a61b5 chore(deps): update Grype to v0.104.1 (#550)

  • a958206 chore(deps-dev): bump eslint from 9.39.0 to 9.39.1 (#540)

  • ff5ff9e chore(deps-dev): bump js-yaml from 3.14.1 to 3.14.2 (#544)

  • Additional commits viewable in compare view


[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anchore/scan-action&package-manager=github_actions&previous-version=3&new-version=7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

## Pull Request

- PR: #34
- Author: @dependabot[bot]
- URL: https://github.com/aRustyDev/pcf-mcp/pull/34

---
This issue was automatically created to track the Dependabot update.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.