From fdf0bffd4a56fa70285dc3217ac1b8b76de43c5a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 24 Sep 2026 04:53:56 +0000 Subject: [PATCH 1/2] build(deps): bump SonarSource/sonarqube-scan-action from 8.2.1 to 8.2.2 Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 8.2.1 to 8.2.2. - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/22918119ff8e1ca75a623e15c8296b6ea4fbe28f...ba9859eae8dd6bd29e412f25ddbbef3d032000f4) --- updated-dependencies: - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/main-validation.yml | 2 +- .github/workflows/pr-validation.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/main-validation.yml b/.github/workflows/main-validation.yml index 6f25522..345d6b3 100644 --- a/.github/workflows/main-validation.yml +++ b/.github/workflows/main-validation.yml @@ -304,6 +304,6 @@ jobs: fi - name: Run SonarQube scan - uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8 + uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/pr-validation.yml b/.github/workflows/pr-validation.yml index 2f9451b..c4da942 100644 --- a/.github/workflows/pr-validation.yml +++ b/.github/workflows/pr-validation.yml @@ -256,7 +256,7 @@ jobs: fi - name: Run SonarQube scan - uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8 + uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} retention-days: 14 From 11e85a98e825047c7614eac1ad27e8798cb04234 Mon Sep 17 00:00:00 2001 From: Roman Khlebnov Date: Fri, 2 Oct 2026 17:42:54 +0200 Subject: [PATCH 2/2] test: align SonarQube action pin with Dependabot update --- cmd/cmdshape-ci/release_workflow_test.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cmd/cmdshape-ci/release_workflow_test.go b/cmd/cmdshape-ci/release_workflow_test.go index 3d557a2..cbd033e 100644 --- a/cmd/cmdshape-ci/release_workflow_test.go +++ b/cmd/cmdshape-ci/release_workflow_test.go @@ -140,7 +140,7 @@ var _ = Describe("validation workflow dependencies", func() { Expect(workflow).NotTo(ContainSubstring("go install ")) Expect(workflow).NotTo(ContainSubstring("raw.githubusercontent.com/golangci")) Expect(workflow).To(ContainSubstring( - "uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8", + "uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8", )) Expect(workflow).NotTo(ContainSubstring("uses: SonarSource/sonarqube-scan-action@v8")) },