Skip to content

ci: bump anchore/sbom-action from 0.24.2 to 0.24.3 - #838

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anchore/sbom-action-0.24.3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/anchore/sbom-action-0.24.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps anchore/sbom-action from 0.24.2 to 0.24.3.

Release notes

Sourced from anchore/sbom-action's releases.

v0.24.3

Added Features

Bug Fixes

(Full Changelog)

Commits
  • 66cbf4b chore(deps): update Syft to latest release (#735)
  • 6b31fa7 chore(deps-dev): bump type-fest from 5.9.0 to 5.10.0 (#742)
  • 85bda36 chore(deps-dev): bump @​types/node from 26.5.1 to 26.6.1 (#741)
  • 7b97c1e chore(deps): bump github.com/anchore/go-make in /.make (#738)
  • 891b055 chore(deps): bump anchore/go-make/.github/actions/setup (#740)
  • f73cf48 chore(deps): bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#739)
  • 13576db chore(deps-dev): bump @​types/node from 26.4.1 to 26.5.1 (#737)
  • 924e83b chore(deps-dev): bump typescript-eslint from 8.69.0 to 8.70.0 (#736)
  • 274555f chore(deps-dev): bump type-fest from 5.8.0 to 5.9.0 (#732)
  • 48fb538 chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#734)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added ci Dependency update to a GitHub Actions workflow (Dependabot) dependencies Pull requests that update a dependency file labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from irparent as a code owner October 5, 2026 13:50
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ci Dependency update to a GitHub Actions workflow (Dependabot) labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
3c50bb8b199f57f987107a8c42aa21ad failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/anchore/sbom-action-0.24.3 branch 2 times, most recently from 1a44c18 to 4730b84 Compare October 5, 2026 22:20
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.24.2 to 0.24.3.
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@3ad7283...66cbf4b)

---
updated-dependencies:
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/anchore/sbom-action-0.24.3 branch from 4730b84 to c48a83e Compare October 5, 2026 22:30
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like anchore/sbom-action is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/anchore/sbom-action-0.24.3 branch October 5, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Dependency update to a GitHub Actions workflow (Dependabot) dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants