Skip to content

chore(deps): bump anchore/scan-action from 3.6.4 to 7.4.0 - #19

Merged
emir-hasanbegovic merged 1 commit into
mainfrom
dependabot/github_actions/anchore/scan-action-7.4.0
Jul 14, 2026
Merged

chore(deps): bump anchore/scan-action from 3.6.4 to 7.4.0#19
emir-hasanbegovic merged 1 commit into
mainfrom
dependabot/github_actions/anchore/scan-action-7.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 16, 2026

Copy link
Copy Markdown
Contributor

Bumps anchore/scan-action from 3.6.4 to 7.4.0.

Release notes

Sourced from anchore/scan-action's releases.

v7.4.0

⬆️ Dependencies

v7.3.2

⬆️ Dependencies

v7.3.1

⬆️ Dependencies

v7.3.0

New in scan-action v7.3.0

⬆️ Dependencies

v7.2.3

New in scan-action v7.2.3

... (truncated)

Commits
  • e116508 chore: bump fast-xml-parser from 5.5.6 to 5.5.7 + setup-node (#631)
  • 382a23a chore(deps): update Grype to v0.110.0 (#618)
  • 2898213 chore: update to node 24 (#629)
  • 4e1eb5b chore: update to modules and bump all deps (required for new @​actions librari...
  • 8ed60d1 chore(deps): bump actions/setup-node from 6.2.0 to 6.3.0 (#617)
  • 5a271d2 chore(deps-dev): bump lint-staged from 16.3.1 to 16.3.2 (#619)
  • 6d37af2 chore(deps-dev): bump jest from 30.2.0 to 30.3.0 (#625)
  • 50a8160 chore(deps-dev): bump tar from 7.5.10 to 7.5.11 (#620)
  • daeb723 chore(deps): bump undici from 6.23.0 to 6.24.1 (#622)
  • 6471a7e chore(deps): bump fast-xml-parser from 5.3.6 to 5.5.6 (#626)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 3.6.4 to 7.4.0.
- [Release notes](https://github.com/anchore/scan-action/releases)
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md)
- [Commits](anchore/scan-action@3343887...e116508)

---
updated-dependencies:
- dependency-name: anchore/scan-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 16, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@emir-hasanbegovic
emir-hasanbegovic merged commit ca48f39 into main Jul 14, 2026
0 of 7 checks passed
@emir-hasanbegovic
emir-hasanbegovic deleted the dependabot/github_actions/anchore/scan-action-7.4.0 branch July 14, 2026 20:52
emir-hasanbegovic pushed a commit that referenced this pull request Jul 14, 2026
Dependabot PRs #19-#22 (and earlier #5-#9) bumped the pinned action
SHAs but the reviewer pin-map comment blocks still listed old tag/SHA
pairs. Sync 14 stale lines across 4 workflows to match the uses: lines
on main. github/codeql-action/upload-sarif stays documented at v3.27.0
because the uses: line itself is still on v3.27.0 (dependabot closed
its own #23 claiming codeql-action is no longer a dependency).

Comment-only. Every tag→SHA pair verified upstream with
gh api repos/<owner>/<repo>/git/ref/tags/<tag> (annotated tags dereferenced).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant