Skip to content

build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 - #1132

Open
dependabot[bot] wants to merge 2 commits into
developfrom
dependabot/github_actions/develop/anchore/sbom-action-0.24.2
Open

build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2#1132
dependabot[bot] wants to merge 2 commits into
developfrom
dependabot/github_actions/develop/anchore/sbom-action-0.24.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps anchore/sbom-action from 0.24.0 to 0.24.2.

Release notes

Sourced from anchore/sbom-action's releases.

v0.24.2

Added Features

Additional Changes

(Full Changelog)

Commits
  • 3ad7283 ops: update write permissions for release (#723)
  • 31f5287 chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#724)
  • aa80c8c chore(deps): update Syft to latest release (#722)
  • 74b54e9 chore(deps): bump lodash from 4.17.23 to 4.18.1 (#623)
  • 6b92ff5 chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#721)
  • 4f8983b chore(deps-dev): bump typescript-eslint from 8.65.0 to 8.67.0 (#719)
  • 10f27f4 chore(deps-dev): bump eslint from 10.5.0 to 10.8.1 (#720)
  • 249403a chore(deps-dev): bump @​types/node from 26.1.0 to 26.2.0 (#718)
  • cbf8daa chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#693)
  • 6afc793 fix: pin syft install.sh to the release tag being installed (#716)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 2, 2026 04:06
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 2, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact head b214f940e8904594d9467e705199db0274cf5fb0 only advances the pinned anchore/sbom-action revision from v0.24.0 to v0.24.2 in the existing SBOM workflow locations; no product/runtime dependency or permission surface is added. The live protected-base movement since this PR was opened is one disjoint Tauri Cargo.lock uuid update, so there is no semantic overlap. Existing local CI/security/build/SBOM runs on this head were successful; the previously cancelled Strix job has been explicitly re-requested and current central OpenCode evidence remains non-passing until it actually completes. This approval is exact-head review evidence only and does not treat queued/cancelled checks as passing.

@seonghobae
seonghobae enabled auto-merge (squash) September 3, 2026 19:32
@opencode-agent
opencode-agent Bot disabled auto-merge September 4, 2026 02:41
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.24.0 to 0.24.2.
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@e22c389...3ad7283)

---
updated-dependencies:
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/anchore/sbom-action-0.24.2 branch from b214f94 to e7f59f1 Compare September 4, 2026 05:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant