mtail
mtail copied to clipboard
build(deps): bump slsa-framework/slsa-verifier from 2.6.0 to 2.7.1
Bumps slsa-framework/slsa-verifier from 2.6.0 to 2.7.1.
Release notes
Sourced from slsa-framework/slsa-verifier's releases.
v2.7.1
What's Changed
- chore: Update docs for v2.7.0 by
@ramonpetgrave64in slsa-framework/slsa-verifier#829- docs(npm): "exmaple" spelling fix by
@scopin slsa-framework/slsa-verifier#832- chore: update test files for v2.1.0 by
@ramonpetgrave64in slsa-framework/slsa-verifier#836- feat: verify provenance for bcr modules produced by trusted reusable workflows by
@loosebazookain slsa-framework/slsa-verifier#840- chore(deps): update golang:1.23 docker digest to cc458d7 by
@renovate-botin slsa-framework/slsa-verifier#838- fix: less parallelism in tests by
@ramonpetgrave64in slsa-framework/slsa-verifier#851- chore(deps): bump
@octokit/request-errorfrom 5.0.1 to 5.1.1 in /actions/installer in the npm_and_yarn group across 1 directory by@dependabotin slsa-framework/slsa-verifier#833- chore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in the go_modules group by
@dependabotin slsa-framework/slsa-verifier#835- chore(deps): bump the go_modules group across 1 directory with 2 updates by
@dependabotin slsa-framework/slsa-verifier#853- fix(deps): update npm by
@renovate-botin slsa-framework/slsa-verifier#843- fix(deps): update golang.org/x/exp digest to dcc06ee by
@renovate-botin slsa-framework/slsa-verifier#839- fix: no parallel regression tests by
@ramonpetgrave64in slsa-framework/slsa-verifier#855- chore(deps): update golang:1.23 docker digest to dd5cc4b by
@renovate-botin slsa-framework/slsa-verifier#847- chore(deps): update gcr.io/distroless/base:nonroot docker digest to 0a0dc20 by
@renovate-botin slsa-framework/slsa-verifier#844- chore(deps): bump the npm_and_yarn group across 2 directories with 5 updates by
@dependabotin slsa-framework/slsa-verifier#854- feat: Bazel not experimental by
@ramonpetgrave64in slsa-framework/slsa-verifier#850- docs: add section for verify-github-attestation by
@loosebazookain slsa-framework/slsa-verifier#858New Contributors
@scopmade their first contribution in slsa-framework/slsa-verifier#832@loosebazookamade their first contribution in slsa-framework/slsa-verifier#840Full Changelog: https://github.com/slsa-framework/slsa-verifier/compare/v2.7.0...v2.7.1
v2.7.1-rc.2
What's Changed
- chore(deps): update golang:1.23 docker digest to cc458d7 by
@renovate-botin slsa-framework/slsa-verifier#838- fix: less parallelism in tests by
@ramonpetgrave64in slsa-framework/slsa-verifier#851- chore(deps): bump
@octokit/request-errorfrom 5.0.1 to 5.1.1 in /actions/installer in the npm_and_yarn group across 1 directory by@dependabotin slsa-framework/slsa-verifier#833- chore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in the go_modules group by
@dependabotin slsa-framework/slsa-verifier#835- chore(deps): bump the go_modules group across 1 directory with 2 updates by
@dependabotin slsa-framework/slsa-verifier#853- fix(deps): update npm by
@renovate-botin slsa-framework/slsa-verifier#843- fix(deps): update golang.org/x/exp digest to dcc06ee by
@renovate-botin slsa-framework/slsa-verifier#839- fix: no parallel regression tests by
@ramonpetgrave64in slsa-framework/slsa-verifier#855- chore(deps): update golang:1.23 docker digest to dd5cc4b by
@renovate-botin slsa-framework/slsa-verifier#847- chore(deps): update gcr.io/distroless/base:nonroot docker digest to 0a0dc20 by
@renovate-botin slsa-framework/slsa-verifier#844- chore(deps): bump the npm_and_yarn group across 2 directories with 5 updates by
@dependabotin slsa-framework/slsa-verifier#854- feat: Bazel not experimental by
@ramonpetgrave64in slsa-framework/slsa-verifier#850- docs: add section for verify-github-attestation by
@loosebazookain slsa-framework/slsa-verifier#858Full Changelog: https://github.com/slsa-framework/slsa-verifier/compare/v2.7.1-rc.1...v2.7.1-rc.2
v2.7.1-rc.1
What's Changed
- chore: Update docs for v2.7.0 by
@ramonpetgrave64in slsa-framework/slsa-verifier#829- docs(npm): "exmaple" spelling fix by
@scopin slsa-framework/slsa-verifier#832- chore: update test files for v2.1.0 by
@ramonpetgrave64in slsa-framework/slsa-verifier#836
... (truncated)
Commits
ea584f4docs: add section for verify-github-attestation (#858)2950204feat: Bazel not experimental (#850)08d54abchore(deps): bump the npm_and_yarn group across 2 directories with 5 updates ...09889f2chore(deps): update gcr.io/distroless/base:nonroot docker digest to 0a0dc20 (...7135755chore(deps): update golang:1.23 docker digest to dd5cc4b (#847)4f28a95fix: no parallel regression tests (#855)1595a06fix(deps): update golang.org/x/exp digest to dcc06ee (#839)e0b3ab7fix(deps): update npm (#843)b02ea50chore(deps): bump the go_modules group across 1 directory with 2 updates (#853)f6be75achore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in the go...- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
Unit Test Results
1 files 27 suites 9m 18s ⏱️ 672 tests 670 ✅ 2 💤 0 ❌ 1 989 runs 1 983 ✅ 6 💤 0 ❌
Results for commit 1dd74bc0.