Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 22, 2025

Bumps anchore/scan-action from 6.4.0 to 6.5.0.

Release notes

Sourced from anchore/scan-action's releases.

v6.5.0

New in scan-action v6.5.0

Commits
  • df39580 chore(deps-dev): bump jest from 30.0.4 to 30.0.5 (#492)
  • e4ff89e chore(deps): update Grype to v0.96.1 (#493)
  • b8370fa fix: output stderr to log, more accurate nonzero exit code behavior (#491)
  • a0ef9a0 chore(deps-dev): bump jest from 30.0.3 to 30.0.4 (#487)
  • 0fc8134 chore(deps-dev): bump eslint from 9.30.1 to 9.31.0 (#488)
  • 0743469 chore(deps): update Grype to v0.96.0 (#489)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 6.4.0 to 6.5.0.
- [Release notes](https://github.com/anchore/scan-action/releases)
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md)
- [Commits](anchore/scan-action@16910ac...df39580)

---
updated-dependencies:
- dependency-name: anchore/scan-action
  dependency-version: 6.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Minor semver labels Jul 22, 2025
@github-actions
Copy link

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/chrono/GJChronology$LinkedDurationField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/node_modules/@jridgewell/gen-mapping/dist/gen-mapping.umd.js.map [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/json_encode encodes JSON JSON.stringify

Deleted: /tmp/prior-commit/scripts/start_registry_and_push_images.sh [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM discover/components/docker enumerates Docker containers docker ps
-MEDIUM fs/path/relative references and possibly executes relative path ./tests
-LOW fs/file/delete_forcibly Forcibly deletes files rm -f registry
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env

Deleted: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/trace-mapping.umd.js.map [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/json_decode Decodes JSON messages JSON.parse
-LOW data/encoding/json_encode encodes JSON JSON.stringify
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/chromium/chromium/blob/da4adbb3/third_party/blink/rend
https://github.com/mozilla/source-map/blob/8cb3ee57/lib/util.js

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/field/StrictDateTimeField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/tz/ZoneInfoCompiler.class [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW fs/directory/create creates directories mkdir

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/field/ImpreciseDateTimeField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/node_modules/@jridgewell/gen-mapping/dist/gen-mapping.mjs.map [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/json_encode encodes JSON JSON.stringify

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/field/ImpreciseDateTimeField$LinkedDurationField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/field/LenientDateTimeField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/node_modules/@jridgewell/sourcemap-codec/dist/sourcemap-codec.mjs.map [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM data/encoding/utf16 assembles strings from UTF-16 code units String.fromCharCode(buf[i])
-LOW os/fd/write writes to a file handle writer.write(semicolon)
writer.write(comma)

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/base/BaseLocal.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/chrono/GJChronology$ImpreciseCutoverField.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/any-map.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./trace-mapping
./types

Deleted: /tmp/prior-commit/node_modules/@jridgewell/sourcemap-codec/dist/sourcemap-codec.umd.js.map [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM data/encoding/utf16 assembles strings from UTF-16 code units String.fromCharCode(buf[i])
-LOW os/fd/write writes to a file handle writer.write(semicolon)
writer.write(comma)

Deleted: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/trace-mapping.mjs.map [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/json_decode Decodes JSON messages JSON.parse
-LOW data/encoding/json_encode encodes JSON JSON.stringify
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/chromium/chromium/blob/da4adbb3/third_party/blink/rend
https://github.com/mozilla/source-map/blob/8cb3ee57/lib/util.js

Deleted: /tmp/prior-commit/tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar ∴ /org/joda/time/base/BasePeriod$1.class [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/binary/opaque binary contains little text content

Deleted: /tmp/prior-commit/tests/fixtures/image-centos-match-coverage/var/lib/rpm/generate-fixture.sh [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/file/copy copy files using cp cp generate-rpmdb-fixture
-MEDIUM net/download download files download
-MEDIUM net/download/fetch Invokes curl curl -sSLO https://github.com/wagoodman/dive/releases/download/v0.9.2
-LOW c2/tool_transfer/arch references a specific architecture https://
amd64
-LOW c2/tool_transfer/os references a specific operating system https://
linux
-LOW fs/directory/create creates directories mkdir
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_lin
-LOW process/chdir changes working directory cd /scratch

Added: /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/src/scopes.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./strings
./vlq
+LOW os/fd/write writes to a file handle writer.write(semicolon)
writer.write(comma)

Added: /tmp/current-commit/node_modules/math-intrinsics/sign.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./sign

Added: /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/src/sourcemap-codec.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./strings
./scopes
./vlq
+LOW os/fd/write writes to a file handle writer.write(semicolon)
writer.write(comma)

Added: /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/src/strings.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM data/encoding/utf16 assembles strings from UTF-16 code units String.fromCharCode(buf[i])

Added: /tmp/current-commit/node_modules/@jest/reporters/build/CoverageWorker.mjs [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import exit
+LOW fs/file/read reads files fs.readFile

Added: /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/flatten-map.d.mts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./trace-mapping
./types
+LOW exec/imports/python imports python modules import type

Added: /tmp/current-commit/node_modules/math-intrinsics/mod.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./floor
./mod

Added: /tmp/current-commit/node_modules/jest-worker/build/threadChild.mjs [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
+LOW net/url/embedded contains embedded HTTPS URLs https://nodejs.org/api/util.html
+LOW os/env/get Retrieve environment variable values env.JEST_WORKER_ID

Added: /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/src/vlq.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./strings

Added: /tmp/current-commit/node_modules/es-errors/eval.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./eval

Added: /tmp/current-commit/node_modules/math-intrinsics/abs.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./abs

Added: /tmp/current-commit/node_modules/@jridgewell/trace-mapping/src/flatten-map.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./trace-mapping
./types

Added: /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/flatten-map.d.cts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./trace-mapping
./types
+LOW exec/imports/python imports python modules import type

Added: /tmp/current-commit/node_modules/math-intrinsics/pow.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./pow

Added: /tmp/current-commit/node_modules/@jridgewell/trace-mapping/src/by-source.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./binary-search

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/by-source.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/by-source.d.mts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/by-source.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/by-source.d.cts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/gen-mapping/dist/gen-mapping.mjs -> /tmp/current-commit/node_modules/@jridgewell/gen-mapping/src/gen-mapping.ts (similarity: 0.90) [🔵 LOW → 🟡 MEDIUM]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./set-array
./types

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/binary-search.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/binary-search.d.mts (similarity: 0.92) [🔵 → 🔵 LOW]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/binary-search.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/binary-search.d.cts (similarity: 0.92) [🔵 → 🔵 LOW]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/gen-mapping/dist/types/gen-mapping.d.ts -> /tmp/current-commit/node_modules/@jridgewell/gen-mapping/types/gen-mapping.d.cts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/gen-mapping/dist/types/gen-mapping.d.ts -> /tmp/current-commit/node_modules/@jridgewell/gen-mapping/types/gen-mapping.d.mts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/trace-mapping.mjs -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/src/trace-mapping.ts (similarity: 0.91) [🔵 LOW → 🟡 MEDIUM]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM fs/path/relative references and possibly executes relative path ./binary-search
./flatten-map
./by-source
./resolve
./types
./sort

3 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/json_decode Decodes JSON messages JSON.parse
-LOW exec/imports/python imports python modules import resolveUri
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/chromium/chromium/blob/da4adbb3/third_party/blink/rend
https://github.com/mozilla/source-map/blob/8cb3ee57/lib/util.js

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/trace-mapping.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/trace-mapping.d.mts (similarity: 0.92)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/sourcemap-codec/dist/types/vlq.d.ts -> /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/types/vlq.d.mts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/sourcemap-codec/dist/types/vlq.d.ts -> /tmp/current-commit/node_modules/@jridgewell/sourcemap-codec/types/vlq.d.cts (similarity: 0.91)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/sort.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/sort.d.cts (similarity: 0.91) [🔵 → 🔵 LOW]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/sort.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/sort.d.mts (similarity: 0.91) [🔵 → 🔵 LOW]

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

Moved: /tmp/prior-commit/node_modules/@jridgewell/trace-mapping/dist/types/trace-mapping.d.ts -> /tmp/current-commit/node_modules/@jridgewell/trace-mapping/types/trace-mapping.d.cts (similarity: 0.92)

1 new behavior

RISK KEY DESCRIPTION EVIDENCE
+LOW exec/imports/python imports python modules import type

@some-natalie some-natalie merged commit e804f5f into main Jul 22, 2025
6 checks passed
@some-natalie some-natalie deleted the dependabot/github_actions/anchore/scan-action-6.5.0 branch July 22, 2025 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Minor semver

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants