Skip to content

ci: update OSV reusable workflow pin - #470

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/google/osv-scanner-action/dot-github/workflows/osv-scanner-reusable-pr.yml-f4cfcc01edc9c8b756a9b873b7a623ca674da51e
Closed

ci: update OSV reusable workflow pin#470
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/google/osv-scanner-action/dot-github/workflows/osv-scanner-reusable-pr.yml-f4cfcc01edc9c8b756a9b873b7a623ca674da51e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Supply-chain impact

Updates the repository's companion OSV dependency-scanning lane to the reviewed immutable upstream commit f4cfcc01edc9c8b756a9b873b7a623ca674da51e.

The upstream commit is a verified GitHub merge from August 7, 2026. Its reusable PR workflow resolves OSV Scanner v2.5.0 and refreshes its immutable artifact-upload and CodeQL SARIF-upload action pins.

Exact current-head scope

The branch was rebuilt as one commit directly on protected develop@b88e66e81e9701404d29a0f5de4f58573ceee14f.

Current head: 93d79d1dec3d7dabd97fb661763f4fb713ad7d3b.

Effective diff: exactly one line in .github/workflows/osvscanner.yml. No package, lockfile, Hono, product, or historical stacked-base change is included.

Ownership and verification

This workflow remains a companion manifest/SCA lane only. ContextualWisdomLab's central .github continues to own required review, security, failed-check explanation, scheduling, and merge governance.

The pin is a full immutable commit SHA and the inline annotation is corrected to v2.5.0. Exact-head Actions/security checks and independent review are required before merge; prior checks on the stacked head are not transferred.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 11, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 11, 2026 06:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 11, 2026
@seonghobae
seonghobae changed the base branch from develop to fix/hono-cves-2026-69207-71848-71850 August 11, 2026 13:32
@seonghobae
seonghobae changed the base branch from fix/hono-cves-2026-69207-71848-71850 to develop August 14, 2026 09:00

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@seonghobae
seonghobae force-pushed the dependabot/github_actions/develop/google/osv-scanner-action/dot-github/workflows/osv-scanner-reusable-pr.yml-f4cfcc01edc9c8b756a9b873b7a623ca674da51e branch from 7782f70 to 93d79d1 Compare August 14, 2026 09:09
@seonghobae seonghobae changed the title ci: bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to f4cfcc01edc9c8b756a9b873b7a623ca674da51e ci: update OSV reusable workflow pin Aug 14, 2026

Copy link
Copy Markdown
Contributor

Closing as superseded by clean protected-base PR #487.

#470 remained conflicted after its security-stack prerequisite was closed and still carried package.json/package-lock.json Hono drift unrelated to the OSV reusable-workflow update. #487 is rebuilt directly on current develop@b88e66e81e9701404d29a0f5de4f58573ceee14f with exactly one changed file and the same immutable v2.5.0 pin. Future validation and review should follow #487's exact head.

@seonghobae seonghobae closed this Aug 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/develop/google/osv-scanner-action/dot-github/workflows/osv-scanner-reusable-pr.yml-f4cfcc01edc9c8b756a9b873b7a623ca674da51e branch August 14, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant