Skip to content

Commit 782e5b4

Browse files
authored
Merge branch 'master' into dependabot/go_modules/github.com/CycloneDX/cyclonedx-go-0.9.3
2 parents 80fd730 + 8c89728 commit 782e5b4

File tree

5 files changed

+41
-49
lines changed

5 files changed

+41
-49
lines changed
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Automatically merge (using squash) dependency update PRs, opened by Dependabot, under the following conditions:
2+
#
3+
# - PR was opened by dependabot[bot].
4+
# - Dependency update is a minor or patch update. This is determined based on Dependabot's metadata.
5+
# - Configured required checks pass.
6+
#
7+
# PRs are approved and merged by user codacybeta (https://github.com/orgs/codacy/people/codacybeta), using its
8+
# AUTO_MERGE_TOKEN.
9+
name: Auto-merge Dependabot dependency updates
10+
11+
on:
12+
pull_request:
13+
14+
jobs:
15+
auto-merge:
16+
name: Auto-merge Dependabot dependency updates
17+
runs-on: ubuntu-latest
18+
if: github.event.pull_request.user.login == 'dependabot[bot]'
19+
steps:
20+
- name: Checkout repository
21+
uses: actions/checkout@v4
22+
- name: Get Dependabot metadata
23+
id: metadata
24+
uses: dependabot/fetch-metadata@v2
25+
with:
26+
github-token: ${{ secrets.AUTO_MERGE_TOKEN }}
27+
- name: Approve PR and set it to auto-merge
28+
if: steps.metadata.outputs.update-type == 'version-update:semver-patch' || steps.metadata.outputs.update-type == 'version-update:semver-minor'
29+
run: |
30+
gh pr review --approve ${{ github.event.pull_request.number }}
31+
gh pr merge --squash --auto ${{ github.event.pull_request.number }}
32+
env:
33+
GH_TOKEN: ${{ secrets.AUTO_MERGE_TOKEN }}

.github/workflows/dependabot_auto_approve.yml

Lines changed: 0 additions & 23 deletions
This file was deleted.

.github/workflows/dependabot_auto_merge.yml

Lines changed: 0 additions & 24 deletions
This file was deleted.

docs/multiple-tests/pattern-vulnerability-high/results.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,7 @@
100100
<error
101101
source="vulnerability_high"
102102
line="14"
103-
message="Insecure dependency npm/[email protected] (CVE-2025-58754: axios: Axios DoS via lack of data size check) (update to 1.12.0)"
103+
message="Insecure dependency npm/[email protected] (CVE-2025-58754: axios: Axios DoS via lack of data size check) (update to 0.30.2)"
104104
severity="high"
105105
/>
106106
</file>
@@ -121,7 +121,7 @@
121121
<error
122122
source="vulnerability_high"
123123
line="5"
124-
message="Insecure dependency npm/[email protected] (CVE-2025-58754: axios: Axios DoS via lack of data size check) (update to 1.12.0)"
124+
message="Insecure dependency npm/[email protected] (CVE-2025-58754: axios: Axios DoS via lack of data size check) (update to 0.30.2)"
125125
severity="high"
126126
/>
127127
</file>

docs/multiple-tests/pattern-vulnerability-medium/results.xml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -122,6 +122,12 @@
122122
message="Insecure dependency golang/[email protected] (CVE-2025-4673: net/http: Sensitive headers not cleared on cross-origin redirect in net/http) (update to 1.23.10)"
123123
severity="warning"
124124
/>
125+
<error
126+
source="vulnerability_medium"
127+
line="3"
128+
message="Insecure dependency golang/[email protected] (CVE-2025-47906: os/exec: Unexpected paths returned from LookPath in os/exec) (update to 1.23.12)"
129+
severity="warning"
130+
/>
125131
</file>
126132

127133
<file name="gradle/gradle.lockfile">

0 commit comments

Comments
 (0)