Skip to content

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Nov 7, 2025

Release 1.4.5. If CI tests have not run, mark as 'ready for review' or close this PR and re-open it.

For proper management of git history, merge this PR, do not squash or rebase.

Bumps [jazzsequence/action-validate-plugin-version](https://github.com/jazzsequence/action-validate-plugin-version) from 1 to 2.
- [Release notes](https://github.com/jazzsequence/action-validate-plugin-version/releases)
- [Commits](jazzsequence/action-validate-plugin-version@v1...v2)

---
updated-dependencies:
- dependency-name: jazzsequence/action-validate-plugin-version
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot bot and others added 2 commits November 20, 2025 14:33
Bumps [webfactory/ssh-agent](https://github.com/webfactory/ssh-agent) from 0.7.0 to 0.9.1.
- [Release notes](https://github.com/webfactory/ssh-agent/releases)
- [Changelog](https://github.com/webfactory/ssh-agent/blob/master/CHANGELOG.md)
- [Commits](webfactory/ssh-agent@v0.7.0...v0.9.1)

---
updated-dependencies:
- dependency-name: webfactory/ssh-agent
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
run: echo "GIT_SSH_COMMAND=ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null" >> $GITHUB_ENV

- name: Install SSH key
uses: webfactory/ssh-agent@v0.9.1

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium test

Unpinned 3rd party Action 'Behat CI' step
Uses Step
uses 'webfactory/ssh-agent' with ref 'v0.9.1', not a pinned commit hash
{ composer config -g github-oauth.github.com "$GITHUB_TOKEN"; } &>/dev/null

- name: Validate fixture version
uses: jazzsequence/action-validate-plugin-version@v2

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium test

Unpinned 3rd party Action 'Behat CI' step
Uses Step
uses 'jazzsequence/action-validate-plugin-version' with ref 'v2', not a pinned commit hash
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants