Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0#62
Conversation
Bumps [sigs.k8s.io/release-utils](https://github.com/kubernetes-sigs/release-utils) from 0.8.5 to 0.9.0. - [Release notes](https://github.com/kubernetes-sigs/release-utils/releases) - [Commits](kubernetes-sigs/release-utils@v0.8.5...v0.9.0) --- updated-dependencies: - dependency-name: sigs.k8s.io/release-utils dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Minder Vulnerability Report ✅Minder analyzed this PR and found it does not add any new vulnerable dependencies.
|
ghost
left a comment
There was a problem hiding this comment.
Dependency Information
Minder analyzed the dependencies introduced in this pull request and detected that some dependencies do not meet your security profile.
📦 Dependency: sigs.k8s.io/release-utils
Trusty Score: 0
ghost
left a comment
There was a problem hiding this comment.
Dependency Information
Minder analyzed the dependencies introduced in this pull request and detected that some dependencies do not meet your security profile.
📦 Dependency: sigs.k8s.io/release-utils
Trusty Score: 0
Scoring details
| Component | Score |
|---|---|
| Package activity | 5.7 |
| Repository activity | 3.5 |
| User activity | 7.9 |
| Provenance | verified_provenance_match |
Proof of Origin (Provenance)
This package can be linked back to its source code using a historical provenance map.
We were able to correlate a significant number of git tags and tagged releases in this package’s source code to versions of the published package. This mapping creates a strong link from the package back to its source code repository, verifying proof of origin.
| Published package versions | 22 |
| Number of git tags or releases | 22 |
| Versions matched to tags or releases | 19 |
Bumps sigs.k8s.io/release-utils from 0.8.5 to 0.9.0.
Release notes
Sourced from sigs.k8s.io/release-utils's releases.
Commits
de6082dMerge pull request #120 from kubernetes-sigs/dependabot/github_actions/action...df1146bbuild(deps): bump the actions group with 3 updatese775794Merge pull request #119 from cpanato/updatescaf1a42fix lintd9a90e0cosign/golangci-lint/ko/zeitgeist version updatesce3ddedenable dependabot update for gh actions30ae3ebMerge pull request #118 from kubernetes-sigs/dependabot/go_modules/all-1193ad...ca98d1fbuild(deps): bump github.com/uwu-tools/magex in the all group869db02Merge pull request #117 from kubernetes-sigs/dependabot/go_modules/all-5a611e...b05d2c0build(deps): bump github.com/maxbrunsfeld/counterfeiter/v6Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)