Skip to content

ci: bump zircote/adrscope from 578e603049caa7c6cf4be0182a2294f29aeea589 to e10f62e1e3469930f78180c5a18633c09932768b#78

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/zircote/adrscope-e10f62e1e3469930f78180c5a18633c09932768b
Jun 12, 2026
Merged

ci: bump zircote/adrscope from 578e603049caa7c6cf4be0182a2294f29aeea589 to e10f62e1e3469930f78180c5a18633c09932768b#78
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/zircote/adrscope-e10f62e1e3469930f78180c5a18633c09932768b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 12, 2026

Copy link
Copy Markdown
Contributor

Bumps zircote/adrscope from 578e603 to e10f62e.

Changelog

Sourced from zircote/adrscope's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Added

  • [Docs]: Add comprehensive dependencies reference documentation

    • Complete catalog of all external dependencies with purposes
    • Version constraints and update policy
    • Supply chain security information
    • Dependency graph visualization
  • [Attested Delivery]: Release pipeline now attaches SLSA build provenance and a CycloneDX SBOM attestation to every platform binary, and fail-closed verifies every attestation before the GitHub Release is published

  • [Publish Workflow]: crates.io publishing via OIDC Trusted Publishing, with SLSA provenance attested against the exact .crate bytes the registry serves

  • [Homebrew Workflow]: Formula in zircote/homebrew-tap is regenerated automatically on release (source-built formula)

  • [CI]: pin-check job asserts every workflow uses: reference is pinned to a full 40-char commit SHA

  • [SECURITY.md]: Documents how to verify release artifact attestations

  • [LICENSE]: Add MIT license text

Changed

  • [Deps]: Update pulldown-cmark from 0.13.0 to 0.13.1 (patch release)
  • [Release Artifacts]: Binaries are now published as bare executables named adrscope-{version}-{platform} (e.g. adrscope-0.4.0-linux-amd64) instead of target-triple tar.gz/zip archives
  • [Action]: Downloads the new artifact naming and fail-closed verifies the binary's attestation before use; falls back to legacy archives for releases <= 0.3.0
  • [Crate Packaging]: Cargo.toml include allowlist keeps repo-internal files out of the published crate

28aebca (feat(release): adopt attested delivery pipeline)

[0.3.0] - 2026-01-15

Changed

  • [Action]: Move action.yml to repository root for GitHub Marketplace publishing
  • [Docs]: Add prominent GitHub Action section to README with examples
  • [Docs]: Add Marketplace badge and Homebrew installation instructions

... (truncated)

Commits
  • e10f62e Merge pull request #73 from zircote/chore/dependabot-ignore-gh-aw
  • 24d9985 chore(ci): stop dependabot from bumping gh-aw refs in compiled lock files
  • f4116f9 deps: bump clap from 4.6.0 to 4.6.1 (#67)
  • 5e70ce7 deps: bump serde_json from 1.0.149 to 1.0.150 (#69)
  • e9e76d1 Merge pull request #72 from zircote/chore/gh-aw-upgrade-v0.79.6
  • fb8c855 fix(ci): SHA-pin checkout in generated copilot-setup-steps.yml
  • 25d25ec chore(ci): recompile workflows for gh-aw v0.79.6
  • a9053f1 Merge pull request #71 from zircote/feat/attested-delivery
  • 0ec869c ci: add CodeQL analysis workflow
  • 5b82ca9 fix(ci): address review — --locked publish determinism, tap token fallback, c...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [zircote/adrscope](https://github.com/zircote/adrscope) from 578e603 to e10f62e.
- [Release notes](https://github.com/zircote/adrscope/releases)
- [Changelog](https://github.com/zircote/adrscope/blob/main/CHANGELOG.md)
- [Commits](578e603...e10f62e)

---
updated-dependencies:
- dependency-name: zircote/adrscope
  dependency-version: e10f62e
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: area/ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the type/chore Maintenance and housekeeping label Jun 12, 2026
@github-actions github-actions Bot enabled auto-merge (squash) June 12, 2026 18:56
@github-actions github-actions Bot merged commit 54385be into main Jun 12, 2026
20 checks passed
@dependabot dependabot Bot deleted the dependabot/github_actions/zircote/adrscope-e10f62e1e3469930f78180c5a18633c09932768b branch June 12, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type/chore Maintenance and housekeeping

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants