echelon icon indicating copy to clipboard operation
echelon copied to clipboard

Bump crytic/slither-action from 0.1.1 to 0.2.0

Open dependabot[bot] opened this issue 2 years ago • 0 comments

Bumps crytic/slither-action from 0.1.1 to 0.2.0.

Release notes

Sourced from crytic/slither-action's releases.

v0.2.0

0.2.0 - 2022-09-09

This is a minor release for the Slither Action - the Github Action for Slither.

This release introduces two main features:

New fail-on option.

This option lets you configure the action step to only fail if findings of a certain severity are found. For example, fail-on: medium would only cause the action to fail if medium or high severity findings are detected. Refer to the corresponding section in the README for more details. This feature requires using Slither 0.9.0 or later for the best effect.

If you are using the action with the SARIF integration, note that you may now use fail-on: none instead of having to continue-on-error: true. This will result in an overall more robust setup, which will not mask build or other such failures. Refer to the updated examples in the README for the recommended way to use fail-on in this case.

Updated slither-version option.

This option has been extended, and it can now also accept Git references as well as PyPI release numbers. You can learn more about this change in the README document.

What's Changed

  • Foundry support - now foundry will be installed in the container if a target requires it to be built
  • Enhanced compatibility with manually built projects, and projects with special compilation arguments
  • Improved solc version detection for glob targets
  • pnpm support for dependency management
  • slither-version can now also accept git refs
  • New fail-on option, to specify when should the action fail. When combined with Slither 0.9.0, you can now choose to fail the action step if issues of a certain severity are found.

New Contributors

Thanks to the new contributors in this release!

Full Changelog: https://github.com/crytic/slither-action/compare/v0.1.1...v0.2.0

Commits
  • 230a81b Merge pull request #34 from crytic/dev-readme-020
  • fe4a2d3 Add note about dependabot updates
  • b710c70 Add note about SARIF and fail-on behavior on earlier Slither releases
  • 2b01696 Update action version on README
  • 35510b3 Merge pull request #29 from crytic/dev-new-exit-code-behavior
  • 18adb3e Merge branch 'dev' into dev-new-exit-code-behavior
  • 670c387 Merge pull request #32 from crytic/dev-github-versions
  • 481d27b Merge pull request #26 from aurora-is-near/main
  • 8809f52 Merge pull request #27 from 0xCLARITY/add-pnpm-support
  • 6ac1f52 Expand slither-version documentation in README
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

dependabot[bot] avatar Oct 06 '22 10:10 dependabot[bot]