Skip to content

ci: bump zircote/adrscope from e10f62e1e3469930f78180c5a18633c09932768b to 14b3dfb4f7a4adbf76af7ba9f13f0e122439b6d5#85

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/zircote/adrscope-14b3dfb4f7a4adbf76af7ba9f13f0e122439b6d5
Jun 15, 2026
Merged

ci: bump zircote/adrscope from e10f62e1e3469930f78180c5a18633c09932768b to 14b3dfb4f7a4adbf76af7ba9f13f0e122439b6d5#85
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/zircote/adrscope-14b3dfb4f7a4adbf76af7ba9f13f0e122439b6d5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps zircote/adrscope from e10f62e to 14b3dfb.

Changelog

Sourced from zircote/adrscope's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Added

  • [Docs]: Add comprehensive dependencies reference documentation

    • Complete catalog of all external dependencies with purposes
    • Version constraints and update policy
    • Supply chain security information
    • Dependency graph visualization
  • [Attested Delivery]: Release pipeline now attaches SLSA build provenance and a CycloneDX SBOM attestation to every platform binary, and fail-closed verifies every attestation before the GitHub Release is published

  • [Publish Workflow]: crates.io publishing via OIDC Trusted Publishing, with SLSA provenance attested against the exact .crate bytes the registry serves

  • [Homebrew Workflow]: Formula in zircote/homebrew-tap is regenerated automatically on release (source-built formula)

  • [CI]: pin-check job asserts every workflow uses: reference is pinned to a full 40-char commit SHA

  • [SECURITY.md]: Documents how to verify release artifact attestations

  • [LICENSE]: Add MIT license text

Changed

  • [Deps]: Update pulldown-cmark from 0.13.0 to 0.13.1 (patch release)
  • [Release Artifacts]: Binaries are now published as bare executables named adrscope-{version}-{platform} (e.g. adrscope-0.4.0-linux-amd64) instead of target-triple tar.gz/zip archives
  • [Action]: Downloads the new artifact naming and fail-closed verifies the binary's attestation before use; falls back to legacy archives for releases <= 0.3.0
  • [Crate Packaging]: Cargo.toml include allowlist keeps repo-internal files out of the published crate

28aebca (feat(release): adopt attested delivery pipeline)

[0.3.0] - 2026-01-15

Changed

  • [Action]: Move action.yml to repository root for GitHub Marketplace publishing
  • [Docs]: Add prominent GitHub Action section to README with examples
  • [Docs]: Add Marketplace badge and Homebrew installation instructions

... (truncated)

Commits
  • 14b3dfb fix(security): update rand to 0.9.3 (RUSTSEC-2026-0097)
  • c68f77a docs: pin CI badge to main branch
  • 6c87449 chore: untrack local caches and editor config
  • c468ccf Merge pull request #77 from zircote/dependabot/github_actions/taiki-e/install...
  • 10bd6e6 Merge pull request #76 from zircote/dependabot/github_actions/actions/checkou...
  • c359ace Merge pull request #74 from zircote/dependabot/github_actions/actions/cache-5...
  • 54385be ci: bump zircote/adrscope from 578e603 to e1...
  • daacbdc deps: bump pulldown-cmark from 0.13.3 to 0.13.4 (#68)
  • b3dd9e1 ci: bump codecov/codecov-action from 5.5.2 to 7.0.0 (#79)
  • 22496b9 deps: bump askama from 0.14.0 to 0.16.0 (#75)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [zircote/adrscope](https://github.com/zircote/adrscope) from e10f62e to 14b3dfb.
- [Release notes](https://github.com/zircote/adrscope/releases)
- [Changelog](https://github.com/zircote/adrscope/blob/main/CHANGELOG.md)
- [Commits](e10f62e...14b3dfb)

---
updated-dependencies:
- dependency-name: zircote/adrscope
  dependency-version: 14b3dfb
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: area/ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the type/chore Maintenance and housekeeping label Jun 15, 2026
@github-actions github-actions Bot enabled auto-merge (squash) June 15, 2026 00:24
@github-actions github-actions Bot merged commit 22ed52f into main Jun 15, 2026
20 checks passed
@dependabot dependabot Bot deleted the dependabot/github_actions/zircote/adrscope-14b3dfb4f7a4adbf76af7ba9f13f0e122439b6d5 branch June 15, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type/chore Maintenance and housekeeping

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants