From f3cd4221ae669b1df111f302d3b2c9ae01eeaed1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 16:00:53 +0000 Subject: [PATCH 1/2] build(deps): bump SonarSource/sonarqube-scan-action Bumps the github-actions group with 1 update: [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action). Updates `SonarSource/sonarqube-scan-action` from 8.2.2 to 8.3.0 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/ba9859eae8dd6bd29e412f25ddbbef3d032000f4...d209202bc7d53ff1cc128f7f907dac145c9d6ae9) --- updated-dependencies: - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/main-validation.yml | 2 +- .github/workflows/pr-validation.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/main-validation.yml b/.github/workflows/main-validation.yml index 345d6b3..b38457f 100644 --- a/.github/workflows/main-validation.yml +++ b/.github/workflows/main-validation.yml @@ -304,6 +304,6 @@ jobs: fi - name: Run SonarQube scan - uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/pr-validation.yml b/.github/workflows/pr-validation.yml index c4da942..6d33fdb 100644 --- a/.github/workflows/pr-validation.yml +++ b/.github/workflows/pr-validation.yml @@ -256,7 +256,7 @@ jobs: fi - name: Run SonarQube scan - uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} retention-days: 14 From 225be021467821f88f8cf8c05edd810541582e9b Mon Sep 17 00:00:00 2001 From: Roman Khlebnov Date: Fri, 2 Oct 2026 18:49:10 +0200 Subject: [PATCH 2/2] test: align SonarQube action pin with 8.3.0 update --- cmd/cmdshape-ci/release_workflow_test.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cmd/cmdshape-ci/release_workflow_test.go b/cmd/cmdshape-ci/release_workflow_test.go index cbd033e..eb544a9 100644 --- a/cmd/cmdshape-ci/release_workflow_test.go +++ b/cmd/cmdshape-ci/release_workflow_test.go @@ -140,7 +140,7 @@ var _ = Describe("validation workflow dependencies", func() { Expect(workflow).NotTo(ContainSubstring("go install ")) Expect(workflow).NotTo(ContainSubstring("raw.githubusercontent.com/golangci")) Expect(workflow).To(ContainSubstring( - "uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8", + "uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8", )) Expect(workflow).NotTo(ContainSubstring("uses: SonarSource/sonarqube-scan-action@v8")) },