ci: update OSV reusable workflow pin - #470
Conversation
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
7782f70 to
93d79d1
Compare
|
Closing as superseded by clean protected-base PR #487. #470 remained conflicted after its security-stack prerequisite was closed and still carried |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Supply-chain impact
Updates the repository's companion OSV dependency-scanning lane to the reviewed immutable upstream commit
f4cfcc01edc9c8b756a9b873b7a623ca674da51e.The upstream commit is a verified GitHub merge from August 7, 2026. Its reusable PR workflow resolves OSV Scanner v2.5.0 and refreshes its immutable artifact-upload and CodeQL SARIF-upload action pins.
Exact current-head scope
The branch was rebuilt as one commit directly on protected
develop@b88e66e81e9701404d29a0f5de4f58573ceee14f.Current head:
93d79d1dec3d7dabd97fb661763f4fb713ad7d3b.Effective diff: exactly one line in
.github/workflows/osvscanner.yml. No package, lockfile, Hono, product, or historical stacked-base change is included.Ownership and verification
This workflow remains a companion manifest/SCA lane only. ContextualWisdomLab's central
.githubcontinues to own required review, security, failed-check explanation, scheduling, and merge governance.The pin is a full immutable commit SHA and the inline annotation is corrected to v2.5.0. Exact-head Actions/security checks and independent review are required before merge; prior checks on the stacked head are not transferred.