Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 27, 2025

Bumps open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml from 0.1.65 to 0.1.67.

Commits
  • 592eafb Added Trivy compliance Docker image scan to Trivy action (#434)
  • d74da04 [gha] Bump open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard....
  • 66012bd [gha] Bump actions/setup-python from 6.0.0 to 6.1.0 in /.github/actions/boots...
  • 65fb572 [gha] Bump open-edge-platform/orch-ci from 0.1.65 to 0.1.66 (#430)
  • 4dec2a4 [gha] Bump github/codeql-action from 4.31.4 to 4.31.5 (#429)
  • ad2bfff Version bump to -dev (#428)
  • 79c4381 Fix permission issue (#427)
  • f3f7fb4 [gha] Bump actions/checkout from 5.0.1 to 6.0.0 in /discover-changed-subfolde...
  • fd9b3cb [gha] Bump actions/checkout from 5.0.1 to 6.0.0 in /verify-branch-name (#426)
  • 406e82c [gha] Bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#423)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…orecard.yml

Bumps [open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml](https://github.com/open-edge-platform/orch-ci) from 0.1.65 to 0.1.67.
- [Commits](open-edge-platform/orch-ci@490a865...592eafb)

---
updated-dependencies:
- dependency-name: open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml
  dependency-version: 0.1.67
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/open-edge-platform/orch-ci/dot-github/workflows/post-merge-scorecard.yml-0.1.67 branch from d58a3d5 to 73c544a Compare November 28, 2025 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant