Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 7, 2023

This PR contains the following updates:

Package Type Update Change
actions/checkout action pinDigest -> 08eba0b

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link

github-actions bot commented Nov 7, 2023

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 08eba0b27e820071cde6df949e0beb9ba4906955 🟢 5.3
Details
CheckScoreReason
Maintained⚠️ 12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Security-Policy🟢 9security policy file detected
Branch-Protection⚠️ -1internal error: error during GetBranch(releases/v2): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST🟢 8SAST tool detected but not run on all commits
Vulnerabilities⚠️ 010 existing vulnerabilities detected

Scanned Files

  • .github/workflows/dependency-review.yaml

@renovate renovate bot force-pushed the renovate/pin-dependencies branch 2 times, most recently from 97e2a28 to 4d0b415 Compare November 14, 2023 05:40
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 4d0b415 to 3b3503a Compare November 30, 2023 08:29
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 3b3503a to c7af276 Compare January 5, 2024 05:59
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 2 times, most recently from d7f5e89 to fff0dfc Compare April 26, 2024 05:35
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from fff0dfc to a6923f4 Compare May 22, 2024 17:35
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from a6923f4 to f0de039 Compare June 15, 2024 02:40
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from f0de039 to 9a0dfcd Compare October 8, 2024 02:31
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 9a0dfcd to 6799861 Compare October 24, 2024 05:52
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 4 times, most recently from 7908344 to cdd5e80 Compare March 5, 2025 10:07
@renovate renovate bot changed the title Pin dependencies Pin actions/checkout action to 11bd719 Mar 5, 2025
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from cdd5e80 to 1038329 Compare March 5, 2025 13:51
@renovate renovate bot changed the title Pin actions/checkout action to 11bd719 Pin actions/checkout action to 08eba0b Aug 11, 2025
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 1038329 to e479d0e Compare August 11, 2025 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant