Skip to content

Bump entur/gha-security/.github/workflows/code-scan.yml from 2.13.0 to 2.15.0 in /.github/workflows#333

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/dot-github/workflows/entur/gha-security/dot-github/workflows/code-scan.yml-2.15.0
Open

Bump entur/gha-security/.github/workflows/code-scan.yml from 2.13.0 to 2.15.0 in /.github/workflows#333
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/dot-github/workflows/entur/gha-security/dot-github/workflows/code-scan.yml-2.15.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 14, 2026

Copy link
Copy Markdown
Contributor

Bumps entur/gha-security/.github/workflows/code-scan.yml from 2.13.0 to 2.15.0.

Release notes

Sourced from entur/gha-security/.github/workflows/code-scan.yml's releases.

v2.15.0

2.15.0 (2026-07-07)

Features

  • add codeql kotlin support warning (#233) (980d09b)
  • Improve alert output from Grype to include location (#232) (3ffb25f)
  • support dynamic build secrets (#228) (408a53b)

v2.14.0

2.14.0 (2026-06-19)

Features

  • add input include_docker_workdir to docker-scan (#223) (22a6e95)
  • improve pull request comment handling (#221) (e433894)
  • improve security hardening (#218) (71679a5)

Bug Fixes

  • check scala in semgrep_languages than codeql_languages (#224) (b201195)
  • reduce scope where github token is exposed under env (#216) (7b76d13)
  • truncate allowlist comment if longer than 280 characters. (#222) (d3c49ee)
Changelog

Sourced from entur/gha-security/.github/workflows/code-scan.yml's changelog.

2.15.0 (2026-07-07)

Features

  • add codeql kotlin support warning (#233) (980d09b)
  • Improve alert output from Grype to include location (#232) (3ffb25f)
  • support dynamic build secrets (#228) (408a53b)

2.14.0 (2026-06-19)

Features

  • add input include_docker_workdir to docker-scan (#223) (22a6e95)
  • improve pull request comment handling (#221) (e433894)
  • improve security hardening (#218) (71679a5)

Bug Fixes

  • check scala in semgrep_languages than codeql_languages (#224) (b201195)
  • reduce scope where github token is exposed under env (#216) (7b76d13)
  • truncate allowlist comment if longer than 280 characters. (#222) (d3c49ee)
Commits
  • df4f926 chore(main): release 2.15.0 (#229)
  • 02af389 hotfix: fix for release 2.15.0 (#236)
  • 460f360 chore: move get-repository-languages to composite action (#234)
  • 980d09b feat: add codeql kotlin support warning (#233)
  • 3ffb25f feat: Improve alert output from Grype to include location (#232)
  • 2bd3e51 chore(deps-dev): bump @​types/node (#231)
  • 408a53b feat: support dynamic build secrets (#228)
  • b60acdf chore(deps): bump undici from 6.24.1 to 6.27.0 in /scanner-action (#227)
  • 0d8f0cc chore(deps): bump slackapi/slack-github-action from 3.0.1 to 3.0.3 (#209)
  • df48e23 chore(deps-dev): bump the minor-and-patch group across 1 directory with 3 upd...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [entur/gha-security/.github/workflows/code-scan.yml](https://github.com/entur/gha-security) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/entur/gha-security/releases)
- [Changelog](https://github.com/entur/gha-security/blob/main/CHANGELOG.md)
- [Commits](entur/gha-security@v2.13.0...v2.15.0)

---
updated-dependencies:
- dependency-name: entur/gha-security/.github/workflows/code-scan.yml
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 14, 2026
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants