Tags: leplusorg/docker-latex
Tags
ci(deps): bump google/osv-scanner-action/.github/workflows/osv-scanne… …r-reusable.yml (#499) Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.3.0 to 2.3.1. - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@b77c075...375a0e8) --- updated-dependencies: - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: 2.3.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ci(trivy): disable vulnerability scan on PRs There is a risk with this approach to miss a new vulnerability being introduced by a PR. But in our case, it is much less likely than a random CVE popping up in existing dependencies at the wrong time, blocking a totally unrelated PR merge. And with our regular scheduled scan, we will catch all vulnerabilities spotted by Trivy soon enough (certainly way before I include the PR in a release).
ci(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#424) Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 5.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Bump debian from 12.10-slim to 12.11-slim in /latex (#356) Bumps debian from 12.10-slim to 12.11-slim. --- updated-dependencies: - dependency-name: debian dependency-version: 12.11-slim dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
PreviousNext