{"id":76010,"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","ecosystem":"actions","repository_url":null,"issues_count":245,"created_at":"2025-11-09T22:01:02.621Z","updated_at":"2025-11-09T22:01:02.621Z","purl":"pkg:githubactions/google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","unique_repositories_count":199,"unique_repositories_count_past_30_days":48,"recent_issues":[{"uuid":"5669607201","node_id":"PR_kwDONFihn88AAAABGLytTg","number":421,"state":"open","title":"build(deps): bump the all group with 4 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T21:43:16.000Z","updated_at":"2026-10-01T21:43:42.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all","update_count":4,"packages":[{"name":"pnpm/setup","old_version":"2.0.2","new_version":"3.0.0","repository_url":"https://github.com/pnpm/setup"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"zizmorcore/zizmor-action","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/zizmorcore/zizmor-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the all group with 4 updates: [pnpm/setup](https://github.com/pnpm/setup), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).\n\nUpdates `pnpm/setup` from 2.0.2 to 3.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pnpm/setup/releases\"\u003epnpm/setup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix!: include runid in cache key, restore freshest lockfile match by \u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat!: automatically detect Node.js version files by \u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add private registry authentication recipes by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/61\"\u003epnpm/setup#61\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid deprecated shell spawning for pnpm commands by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/52\"\u003epnpm/setup#52\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: require-lockfile no longer accepts a lockfile pnpm will not use by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/60\"\u003epnpm/setup#60\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: restore cache before installing runtime by \u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: install multiple runtimes from devEngines.runtime by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: cache pnpm's lockfile verification results by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/30\"\u003epnpm/setup#30\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e by \u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: update dependencies with pnpm/update instead of Dependabot by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/41\"\u003epnpm/setup#41\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update dependencies by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003e\u003ccode\u003efbda4c8\u003c/code\u003e\u003c/a\u003e docs(README): update version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c868a7d055a8423cab9de075713ce4ce9bf9205d\"\u003e\u003ccode\u003ec868a7d\u003c/code\u003e\u003c/a\u003e fix: require-lockfile no longer accepts a lockfile pnpm will not use (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/60\"\u003e#60\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/463911b67ec9290f1350907aa2b257be0aca1687\"\u003e\u003ccode\u003e463911b\u003c/code\u003e\u003c/a\u003e fix: avoid deprecated shell spawning for pnpm commands (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/52\"\u003e#52\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/659828629c47ab99e8bdf4cc9aec88a8aab310a6\"\u003e\u003ccode\u003e6598286\u003c/code\u003e\u003c/a\u003e docs: add private registry authentication recipes (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/61\"\u003e#61\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c5b2e249903756c468007fa3f013203377937b5b\"\u003e\u003ccode\u003ec5b2e24\u003c/code\u003e\u003c/a\u003e feat!: automatically detect Node.js version files (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/f37addefd310ed0d00a4de48e30bb7e1c4414491\"\u003e\u003ccode\u003ef37adde\u003c/code\u003e\u003c/a\u003e fix!: include runid in cache key, restore freshest lockfile match (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/43\"\u003e#43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/703c52620218391530e48b9e8870d5c0082e1b9b\"\u003e\u003ccode\u003e703c526\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/e02cd34ce0366c68c5fccdd0f0fd4fa1f9d3459c\"\u003e\u003ccode\u003ee02cd34\u003c/code\u003e\u003c/a\u003e ci: update dependencies with pnpm/update instead of Dependabot (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/41\"\u003e#41\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/0080eca8ccdd50c579e4d2242cc958f8e8b3040e\"\u003e\u003ccode\u003e0080eca\u003c/code\u003e\u003c/a\u003e feat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/23\"\u003e#23\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/3327d57c1fba3d6ed3bef37285efc7a45c25f6cd\"\u003e\u003ccode\u003e3327d57\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/zizmorcore/zizmor-action/releases\"\u003ezizmorcore/zizmor-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sponsors/woodruffw/\"\u003eSponsorship is appreciated!\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003ezizmor 1.30.1 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1301%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1301)\"\u003ezizmorcore/zizmor-action#1301\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.6.3\u003c/h2\u003e\n\u003cp\u003ezizmor 1.30.0 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1300%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1300)\"\u003ezizmorcore/zizmor-action#1300\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003e\u003ccode\u003ecc914d7\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/bae72b71bc270806f906e8e2a1f5985a26effaa2\"\u003e\u003ccode\u003ebae72b7\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/27604f9eef072d6456e69fc10ee36629710fa6f6\"\u003e\u003ccode\u003e27604f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/164\"\u003e#164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/c41d66537b2d733801baec1e31ffc22aa2051a8f\"\u003e\u003ccode\u003ec41d665\u003c/code\u003e\u003c/a\u003e README: bump pins (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/163\"\u003e#163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/70fb788f84895a7701f5643d103d587e460b5c99\"\u003e\u003ccode\u003e70fb788\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/162\"\u003e#162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/7999d8c8ac51dbd3bd44e6e35e7cd015b5dcdc82\"\u003e\u003ccode\u003e7999d8c\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/2ae1ce9c6b7248fdfc5a4f47f3527240521f79b9\"\u003e\u003ccode\u003e2ae1ce9\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/951a5eef1c3d7669c20934ceca759fdf8dbd153e\"\u003e\u003ccode\u003e951a5ee\u003c/code\u003e\u003c/a\u003e Skip prerelease versions in sync-zizmor-versions workflow (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/158\"\u003e#158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/79f019101434ac77d41ed24f93c6bdc8676bd355\"\u003e\u003ccode\u003e79f0191\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/156\"\u003e#156\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/26a3ae6758a68e521bfe592f503410eb61b699bb\"\u003e\u003ccode\u003e26a3ae6\u003c/code\u003e\u003c/a\u003e sync-zizmor-versions: retry up to 5 times (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/155\"\u003e#155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/zizmorcore/zizmor-action/compare/3dc1ecc9bcb9e94e9b2c709687979e1298497054...cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/gahojin/date-fns-japan/pull/421","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gahojin%2Fdate-fns-japan/issues/421","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/421/packages"},{"uuid":"5660097317","node_id":"PR_kwDOUXF5V88AAAABGEGWlA","number":20,"state":"open","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from c7c7bcb0773cc4678a674ada03a66cc5c4325476 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T09:36:15.000Z","updated_at":"2026-10-01T09:36:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"c7c7bcb0773cc4678a674ada03a66cc5c4325476","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from c7c7bcb0773cc4678a674ada03a66cc5c4325476 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003e\u003ccode\u003e8ac9e5c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/143\"\u003e#143\u003c/a\u003e from renovate-bot/renovate/workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/3b06fbb744e4192b7d47b4f2584715a21ef88b92\"\u003e\u003ccode\u003e3b06fbb\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.38.0\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/c7c7bcb0773cc4678a674ada03a66cc5c4325476...8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/nakedape2000/bandcamp-wishlist-tidal/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nakedape2000%2Fbandcamp-wishlist-tidal/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"},{"uuid":"5657452536","node_id":"PR_kwDOOiDYAc8AAAABGB_5qg","number":291,"state":"open","title":"build(deps): bump the all group with 4 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T05:28:51.000Z","updated_at":"2026-10-01T05:29:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all","update_count":4,"packages":[{"name":"pnpm/setup","old_version":"2.0.2","new_version":"3.0.0","repository_url":"https://github.com/pnpm/setup"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"zizmorcore/zizmor-action","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/zizmorcore/zizmor-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the all group with 4 updates: [pnpm/setup](https://github.com/pnpm/setup), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).\n\nUpdates `pnpm/setup` from 2.0.2 to 3.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pnpm/setup/releases\"\u003epnpm/setup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix!: include runid in cache key, restore freshest lockfile match by \u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat!: automatically detect Node.js version files by \u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add private registry authentication recipes by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/61\"\u003epnpm/setup#61\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid deprecated shell spawning for pnpm commands by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/52\"\u003epnpm/setup#52\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: require-lockfile no longer accepts a lockfile pnpm will not use by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/60\"\u003epnpm/setup#60\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: restore cache before installing runtime by \u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: install multiple runtimes from devEngines.runtime by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: cache pnpm's lockfile verification results by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/30\"\u003epnpm/setup#30\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e by \u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: update dependencies with pnpm/update instead of Dependabot by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/41\"\u003epnpm/setup#41\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update dependencies by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003e\u003ccode\u003efbda4c8\u003c/code\u003e\u003c/a\u003e docs(README): update version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c868a7d055a8423cab9de075713ce4ce9bf9205d\"\u003e\u003ccode\u003ec868a7d\u003c/code\u003e\u003c/a\u003e fix: require-lockfile no longer accepts a lockfile pnpm will not use (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/60\"\u003e#60\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/463911b67ec9290f1350907aa2b257be0aca1687\"\u003e\u003ccode\u003e463911b\u003c/code\u003e\u003c/a\u003e fix: avoid deprecated shell spawning for pnpm commands (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/52\"\u003e#52\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/659828629c47ab99e8bdf4cc9aec88a8aab310a6\"\u003e\u003ccode\u003e6598286\u003c/code\u003e\u003c/a\u003e docs: add private registry authentication recipes (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/61\"\u003e#61\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c5b2e249903756c468007fa3f013203377937b5b\"\u003e\u003ccode\u003ec5b2e24\u003c/code\u003e\u003c/a\u003e feat!: automatically detect Node.js version files (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/f37addefd310ed0d00a4de48e30bb7e1c4414491\"\u003e\u003ccode\u003ef37adde\u003c/code\u003e\u003c/a\u003e fix!: include runid in cache key, restore freshest lockfile match (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/43\"\u003e#43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/703c52620218391530e48b9e8870d5c0082e1b9b\"\u003e\u003ccode\u003e703c526\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/e02cd34ce0366c68c5fccdd0f0fd4fa1f9d3459c\"\u003e\u003ccode\u003ee02cd34\u003c/code\u003e\u003c/a\u003e ci: update dependencies with pnpm/update instead of Dependabot (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/41\"\u003e#41\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/0080eca8ccdd50c579e4d2242cc958f8e8b3040e\"\u003e\u003ccode\u003e0080eca\u003c/code\u003e\u003c/a\u003e feat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/23\"\u003e#23\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/3327d57c1fba3d6ed3bef37285efc7a45c25f6cd\"\u003e\u003ccode\u003e3327d57\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pnpm/setup/compare/84cb39b217b10273981911c288cd62326dc7c6d2...fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/zizmorcore/zizmor-action/releases\"\u003ezizmorcore/zizmor-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sponsors/woodruffw/\"\u003eSponsorship is appreciated!\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003ezizmor 1.30.1 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1301%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1301)\"\u003ezizmorcore/zizmor-action#1301\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.6.3\u003c/h2\u003e\n\u003cp\u003ezizmor 1.30.0 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1300%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1300)\"\u003ezizmorcore/zizmor-action#1300\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003e\u003ccode\u003ecc914d7\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/bae72b71bc270806f906e8e2a1f5985a26effaa2\"\u003e\u003ccode\u003ebae72b7\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/27604f9eef072d6456e69fc10ee36629710fa6f6\"\u003e\u003ccode\u003e27604f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/164\"\u003e#164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/c41d66537b2d733801baec1e31ffc22aa2051a8f\"\u003e\u003ccode\u003ec41d665\u003c/code\u003e\u003c/a\u003e README: bump pins (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/163\"\u003e#163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/70fb788f84895a7701f5643d103d587e460b5c99\"\u003e\u003ccode\u003e70fb788\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/162\"\u003e#162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/7999d8c8ac51dbd3bd44e6e35e7cd015b5dcdc82\"\u003e\u003ccode\u003e7999d8c\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/2ae1ce9c6b7248fdfc5a4f47f3527240521f79b9\"\u003e\u003ccode\u003e2ae1ce9\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/951a5eef1c3d7669c20934ceca759fdf8dbd153e\"\u003e\u003ccode\u003e951a5ee\u003c/code\u003e\u003c/a\u003e Skip prerelease versions in sync-zizmor-versions workflow (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/158\"\u003e#158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/79f019101434ac77d41ed24f93c6bdc8676bd355\"\u003e\u003ccode\u003e79f0191\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/156\"\u003e#156\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/26a3ae6758a68e521bfe592f503410eb61b699bb\"\u003e\u003ccode\u003e26a3ae6\u003c/code\u003e\u003c/a\u003e sync-zizmor-versions: retry up to 5 times (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/155\"\u003e#155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/zizmorcore/zizmor-action/compare/3dc1ecc9bcb9e94e9b2c709687979e1298497054...cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/gahojin/rolldown-gas-plugin/pull/291","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gahojin%2Frolldown-gas-plugin/issues/291","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/291/packages"},{"uuid":"5621481920","node_id":"PR_kwDOToe92s8AAAABFlM-kA","number":809,"state":"open","title":"[CI] 의존성 업데이트 Bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T21:27:58.000Z","updated_at":"2026-10-01T02:32:36.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[CI] 의존성 업데이트 Bump","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"3a7550f43ba5b58905a821ce3a0ed24c4858b3f4","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003e\u003ccode\u003e8ac9e5c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/143\"\u003e#143\u003c/a\u003e from renovate-bot/renovate/workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/3b06fbb744e4192b7d47b4f2584715a21ef88b92\"\u003e\u003ccode\u003e3b06fbb\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/3a7550f43ba5b58905a821ce3a0ed24c4858b3f4...8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/AquilaXk/easysubway-data/pull/809","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AquilaXk%2Feasysubway-data/issues/809","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/809/packages"},{"uuid":"5619716275","node_id":"PR_kwDOUtpkjs8AAAABFjx-JA","number":7,"state":"closed","title":"chore(actions)(deps): bump the actions-minor-patch group with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-28T19:11:05.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-28T19:00:46.000Z","updated_at":"2026-09-28T19:11:50.000Z","time_to_close":619,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/acmeist/hermes-agent/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/acmeist%2Fhermes-agent/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"},{"uuid":"5618450313","node_id":"PR_kwDOSRjOYs8AAAABFiwytA","number":23,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T17:14:07.000Z","updated_at":"2026-09-28T17:21:42.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/highclaws-com/hermes-agent-fork/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/highclaws-com%2Fhermes-agent-fork/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"},{"uuid":"5602284810","node_id":"PR_kwDOUuReW88AAAABFV-fYw","number":1,"state":"closed","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-29T18:27:11.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-27T11:33:48.000Z","updated_at":"2026-09-29T18:27:21.000Z","time_to_close":197603,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/selendang666/selendang666-jb/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/selendang666%2Fselendang666-jb/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5599552015","node_id":"PR_kwDOUtpkjs8AAAABFT_iKw","number":1,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-27T03:54:52.000Z","updated_at":"2026-09-27T03:59:38.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/acmeist/hermes-agent/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/acmeist%2Fhermes-agent/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5590631270","node_id":"PR_kwDOKtY1DM8AAAABFNPJNA","number":349,"state":"closed","title":"ci: bump the github-actions group across 1 directory with 6 updates","user":"dependabot[bot]","labels":["dependencies",":zap: ci/cd","triage","released"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-29T06:15:16.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-26T02:16:57.000Z","updated_at":"2026-10-03T14:09:41.000Z","time_to_close":273499,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci: bump","group_name":"github-actions","update_count":6,"packages":[{"name":"github/codeql-action/init","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/autobuild","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/upload-sarif","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n\n\nUpdates `github/codeql-action/init` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/autobuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/autobuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/janbiasi/rollup-plugin-sbom/pull/349","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/janbiasi%2Frollup-plugin-sbom/issues/349","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/349/packages"},{"uuid":"5572980577","node_id":"PR_kwDORK5qGc8AAAABE_RcvA","number":3231,"state":"closed","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0 in the github-actions group across 1 directory","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-02T00:46:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-24T18:46:28.000Z","updated_at":"2026-10-02T00:46:18.000Z","time_to_close":626380,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":"the github-actions group across 1 directory","ecosystem":"actions"},"body":"Bumps the github-actions group with 1 update in the / directory: [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/jerry200176-png/AllTrue_System/pull/3231","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jerry200176-png%2FAllTrue_System/issues/3231","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3231/packages"},{"uuid":"5570080421","node_id":"PR_kwDOUodimc8AAAABE889RQ","number":2,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:43:43.000Z","updated_at":"2026-09-24T14:47:16.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/cryozenai/cryozen-agent/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/cryozenai%2Fcryozen-agent/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5543146968","node_id":"PR_kwDOUl8rkc8AAAABEnxZng","number":1,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 4 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T17:47:39.000Z","updated_at":"2026-09-22T17:47:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":4,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 4 updates: [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action), [docker/build-push-action](https://github.com/docker/build-push-action), [docker/login-action](https://github.com/docker/login-action) and [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/igniteenow/robo-engineer/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/igniteenow%2Frobo-engineer/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5535742164","node_id":"PR_kwDOSaQaxc8AAAABEhzCyA","number":1713,"state":"open","title":"chore(ci): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.3.8 to 2.6.0","user":"dependabot[bot]","labels":["size/XS"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T05:44:28.000Z","updated_at":"2026-09-22T05:44:38.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(ci)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.3.8 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.3.8\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Mininglamp-OSS/octo-web/pull/1713","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Mininglamp-OSS%2Focto-web/issues/1713","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1713/packages"},{"uuid":"5533203504","node_id":"PR_kwDORJ_K788AAAABEfzWdQ","number":8,"state":"open","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T22:35:47.000Z","updated_at":"2026-09-21T22:35:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.5.1 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.5.1\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Tuteliq/flutter/pull/8","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Tuteliq%2Fflutter/issues/8","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/8/packages"},{"uuid":"5533064564","node_id":"PR_kwDOT6Rtr88AAAABEfsL4Q","number":7,"state":"open","title":"Bump the github-actions group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T22:17:54.000Z","updated_at":"2026-09-21T22:18:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"github-actions","update_count":10,"packages":[{"name":"actions/checkout","old_version":"4","new_version":"7","repository_url":"https://github.com/actions/checkout"},{"name":"docker/login-action","old_version":"3","new_version":"4","repository_url":"https://github.com/docker/login-action"},{"name":"docker/setup-buildx-action","old_version":"3","new_version":"4","repository_url":"https://github.com/docker/setup-buildx-action"},{"name":"docker/build-push-action","old_version":"6","new_version":"7","repository_url":"https://github.com/docker/build-push-action"},{"name":"actions/dependency-review-action","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/actions/dependency-review-action"},{"name":"actions/upload-artifact","old_version":"4","new_version":"7","repository_url":"https://github.com/actions/upload-artifact"},{"name":"actions/download-artifact","old_version":"4","new_version":"8","repository_url":"https://github.com/actions/download-artifact"},{"name":"oven-sh/setup-bun","old_version":"1","new_version":"2","repository_url":"https://github.com/oven-sh/setup-bun"},{"name":"actions/cache","old_version":"4","new_version":"6","repository_url":"https://github.com/actions/cache"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"3adb4b14a2b0623876d18d863a498b785fb3752d","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |\n| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |\n| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `6` | `7` |\n| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.9.0` | `5.0.0` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` |\n| [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `8` |\n| [oven-sh/setup-bun](https://github.com/oven-sh/setup-bun) | `1` | `2` |\n| [actions/cache](https://github.com/actions/cache) | `4` | `6` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `3adb4b14a2b0623876d18d863a498b785fb3752d` | `8ac9e5ce44cc7178e0e04229a91bdcc003166e57` |\n\n\nUpdates `actions/checkout` from 4 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/checkout/releases\"\u003eactions/checkout's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eblock checking out fork pr for pull_request_target and workflow_run by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and \u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003egetting ready for checkout v7 release by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2464\"\u003eactions/checkout#2464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate error wording by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2467\"\u003eactions/checkout#2467\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.3...v7.0.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[BREAKING]\u003c/strong\u003e backport \u003ccode\u003eallow-unsafe-pr-checkout\u003c/code\u003e to v6 by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2500\"\u003eactions/checkout#2500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebackport fixes to releases-v6 by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2527\"\u003eactions/checkout#2527\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/\"\u003ehttps://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/\u003c/a\u003e for more details about this breaking change\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.3...v6.1.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate changelog by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2357\"\u003eactions/checkout#2357\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate changelog for v6.0.3 by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2446\"\u003eactions/checkout#2446\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6...v6.0.3\"\u003ehttps://github.com/actions/checkout/compare/v6...v6.0.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by \u003ca href=\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2355\"\u003eactions/checkout#2355\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.1...v6.0.2\"\u003ehttps://github.com/actions/checkout/compare/v6.0.1...v6.0.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all references from v5 and v4 to v6 by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2314\"\u003eactions/checkout#2314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify v6 README by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2328\"\u003eactions/checkout#2328\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003e\u003ccode\u003e3d3c42e\u003c/code\u003e\u003c/a\u003e prep v7.0.1 release (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2531\"\u003e#2531\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07\"\u003e\u003ccode\u003e2880268\u003c/code\u003e\u003c/a\u003e escape values passed to --unset (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2530\"\u003e#2530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1\"\u003e\u003ccode\u003e12cd223\u003c/code\u003e\u003c/a\u003e trim only ascii whitespace for branch (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2521\"\u003e#2521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541\"\u003e\u003ccode\u003e62661c4\u003c/code\u003e\u003c/a\u003e skip running unsafe pr check if input is default (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2518\"\u003e#2518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f\"\u003e\u003ccode\u003ee8d4307\u003c/code\u003e\u003c/a\u003e Bump the minor-actions-dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2499\"\u003e#2499\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87\"\u003e\u003ccode\u003e631c942\u003c/code\u003e\u003c/a\u003e eslint 9 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2474\"\u003e#2474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e\"\u003e\u003ccode\u003e4f1f4ae\u003c/code\u003e\u003c/a\u003e Bump actions/upload-artifact from 4 to 7 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2476\"\u003e#2476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92\"\u003e\u003ccode\u003eba09753\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6 to 7 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2488\"\u003e#2488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22\"\u003e\u003ccode\u003eb9e0990\u003c/code\u003e\u003c/a\u003e Bump docker/login-action from 3.3.0 to 4.2.0 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2479\"\u003e#2479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2\"\u003e\u003ccode\u003ee8cb398\u003c/code\u003e\u003c/a\u003e Bump docker/build-push-action from 6.5.0 to 7.2.0 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2478\"\u003e#2478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/checkout/compare/v4...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 3 to 4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/929\"\u003edocker/login-action#929\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/927\"\u003edocker/login-action#927\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/919\"\u003edocker/login-action#919\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e from 3.890.0 to 3.1000.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/909\"\u003edocker/login-action#909\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/920\"\u003edocker/login-action#920\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e from 3.890.0 to 3.1000.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/909\"\u003edocker/login-action#909\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/920\"\u003edocker/login-action#920\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.63.0 to 0.77.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/910\"\u003edocker/login-action#910\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/928\"\u003edocker/login-action#928\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​isaacs/brace-expansion\u003c/code\u003e from 5.0.0 to 5.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/921\"\u003edocker/login-action#921\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/901\"\u003edocker/login-action#901\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.7.0...v4.0.0\"\u003ehttps://github.com/docker/login-action/compare/v3.7.0...v4.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003escope\u003c/code\u003e input to set scopes for the authentication token by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/912\"\u003edocker/login-action#912\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for AWS European Sovereign Cloud ECR by \u003ca href=\"https://github.com/dphi\"\u003e\u003ccode\u003e@​dphi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/914\"\u003edocker/login-action#914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure passwords are redacted with \u003ccode\u003eregistry-auth\u003c/code\u003e input by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/911\"\u003edocker/login-action#911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/915\"\u003edocker/login-action#915\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.6.0...v3.7.0\"\u003ehttps://github.com/docker/login-action/compare/v3.6.0...v3.7.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eregistry-auth\u003c/code\u003e input for raw authentication to registries by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/887\"\u003edocker/login-action#887\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.890.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/882\"\u003edocker/login-action#882\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/890\"\u003edocker/login-action#890\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.890.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/882\"\u003edocker/login-action#882\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/890\"\u003edocker/login-action#890\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.63.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/883\"\u003edocker/login-action#883\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/880\"\u003edocker/login-action#880\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/879\"\u003edocker/login-action#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.3 to 0.2.4 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/881\"\u003edocker/login-action#881\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.5.0...v3.6.0\"\u003ehttps://github.com/docker/login-action/compare/v3.5.0...v3.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport dual-stack endpoints for AWS ECR by \u003ca href=\"https://github.com/Spacefish\"\u003e\u003ccode\u003e@​Spacefish\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/874\"\u003edocker/login-action#874\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/876\"\u003edocker/login-action#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.859.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/860\"\u003edocker/login-action#860\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/878\"\u003edocker/login-action#878\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.859.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/860\"\u003edocker/login-action#860\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/878\"\u003edocker/login-action#878\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.57.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/870\"\u003edocker/login-action#870\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/875\"\u003edocker/login-action#875\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.4.0...v3.5.0\"\u003ehttps://github.com/docker/login-action/compare/v3.4.0...v3.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.10.1 to 1.11.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/791\"\u003edocker/login-action#791\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.766.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/789\"\u003edocker/login-action#789\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/856\"\u003edocker/login-action#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.758.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/789\"\u003edocker/login-action#789\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/856\"\u003edocker/login-action#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.35.0 to 0.57.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/801\"\u003edocker/login-action#801\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/806\"\u003edocker/login-action#806\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/858\"\u003edocker/login-action#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump cross-spawn from 7.0.3 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/814\"\u003edocker/login-action#814\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump https-proxy-agent from 7.0.5 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/823\"\u003edocker/login-action#823\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump path-to-regexp from 6.2.2 to 6.3.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/777\"\u003edocker/login-action#777\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.3.0...v3.4.0\"\u003ehttps://github.com/docker/login-action/compare/v3.3.0...v3.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/v3...v4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/setup-buildx-action` from 3 to 4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/483\"\u003edocker/setup-buildx-action#483\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated inputs/outputs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/464\"\u003edocker/setup-buildx-action#464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/481\"\u003edocker/setup-buildx-action#481\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/475\"\u003edocker/setup-buildx-action#475\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.63.0 to 0.79.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/482\"\u003edocker/setup-buildx-action#482\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/485\"\u003edocker/setup-buildx-action#485\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/452\"\u003edocker/setup-buildx-action#452\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/472\"\u003edocker/setup-buildx-action#472\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump minimatch from 3.1.2 to 3.1.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/480\"\u003edocker/setup-buildx-action#480\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.12.0...v4.0.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.12.0...v4.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.12.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003einstall\u003c/code\u003e input by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/455\"\u003edocker/setup-buildx-action#455\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.63.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/434\"\u003edocker/setup-buildx-action#434\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/436\"\u003edocker/setup-buildx-action#436\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/432\"\u003edocker/setup-buildx-action#432\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/435\"\u003edocker/setup-buildx-action#435\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.11.1...v3.12.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.11.1...v3.12.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.11.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003ekeep-state\u003c/code\u003e not being respected by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/429\"\u003edocker/setup-buildx-action#429\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.11.0...v3.11.1\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.11.0...v3.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eKeep BuildKit state support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/427\"\u003edocker/setup-buildx-action#427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove aliases created when installing by default by \u003ca href=\"https://github.com/hashhar\"\u003e\u003ccode\u003e@​hashhar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/139\"\u003edocker/setup-buildx-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.56.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/422\"\u003edocker/setup-buildx-action#422\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/425\"\u003edocker/setup-buildx-action#425\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.10.0...v3.11.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.10.0...v3.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.54.0 to 0.56.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/408\"\u003edocker/setup-buildx-action#408\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.9.0...v3.10.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.9.0...v3.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.48.0 to 0.54.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/402\"\u003edocker/setup-buildx-action#402\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/404\"\u003edocker/setup-buildx-action#404\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.8.0...v3.9.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.8.0...v3.9.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMake cloud prefix optional to download buildx if driver is cloud by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/390\"\u003edocker/setup-buildx-action#390\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.10.1 to 1.11.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/370\"\u003edocker/setup-buildx-action#370\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.39.0 to 0.48.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/389\"\u003edocker/setup-buildx-action#389\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump cross-spawn from 7.0.3 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/382\"\u003edocker/setup-buildx-action#382\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.7.1...v3.8.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.7.1...v3.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003e\u003ccode\u003ef87e599\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/624\"\u003e#624\u003c/a\u003e from crazy-max/skip-pull-with-endpoint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022\"\u003e\u003ccode\u003ee700274\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07\"\u003e\u003ccode\u003e3061c91\u003c/code\u003e\u003c/a\u003e skip BuildKit image pre-pulls for explicit endpoints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003\"\u003e\u003ccode\u003e594f3bf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/609\"\u003e#609\u003c/a\u003e from crazy-max/pull-buildkit-image-before-create\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25\"\u003e\u003ccode\u003ebd6e702\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032\"\u003e\u003ccode\u003e6268c9d\u003c/code\u003e\u003c/a\u003e pull BuildKit image before builder creation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11\"\u003e\u003ccode\u003ee823525\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/621\"\u003e#621\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d\"\u003e\u003ccode\u003e533ed8e\u003c/code\u003e\u003c/a\u003e build(deps): bump the codeql-actions group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99\"\u003e\u003ccode\u003ebedaf13\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/620\"\u003e#620\u003c/a\u003e from crazy-max/shared-error-helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2\"\u003e\u003ccode\u003ed5079fb\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3...v4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 6 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1470\"\u003edocker/build-push-action#1470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated \u003ccode\u003eDOCKER_BUILD_NO_SUMMARY\u003c/code\u003e and \u003ccode\u003eDOCKER_BUILD_EXPORT_RETENTION_DAYS\u003c/code\u003e envs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1473\"\u003edocker/build-push-action#1473\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove legacy export-build tool support for build summary by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1474\"\u003edocker/build-push-action#1474\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1466\"\u003edocker/build-push-action#1466\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1454\"\u003edocker/build-push-action#1454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.79.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1453\"\u003edocker/build-push-action#1453\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1472\"\u003edocker/build-push-action#1472\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1479\"\u003edocker/build-push-action#1479\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump minimatch from 3.1.2 to 3.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1463\"\u003edocker/build-push-action#1463\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.2...v7.0.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.2...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve port in \u003ccode\u003eGIT_AUTH_TOKEN\u003c/code\u003e host by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1458\"\u003edocker/build-push-action#1458\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.1...v6.19.2\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.1...v6.19.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDerive \u003ccode\u003eGIT_AUTH_TOKEN\u003c/code\u003e host from GitHub server URL by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1456\"\u003edocker/build-push-action#1456\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.0...v6.19.1\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.0...v6.19.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eScope default git auth token to \u003ccode\u003egithub.com\u003c/code\u003e by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1451\"\u003edocker/build-push-action#1451\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1396\"\u003edocker/build-push-action#1396\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1391\"\u003edocker/build-push-action#1391\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.1 to 3.14.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1429\"\u003edocker/build-push-action#1429\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1446\"\u003edocker/build-push-action#1446\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.3 to 0.2.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1398\"\u003edocker/build-push-action#1398\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1397\"\u003edocker/build-push-action#1397\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.18.0...v6.19.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.18.0...v6.19.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.18.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.61.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1381\"\u003edocker/build-push-action#1381\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\n\u003ca href=\"https://docs.docker.com/build/ci/github-actions/build-summary/\"\u003eBuild summary\u003c/a\u003e is now supported with \u003ca href=\"https://docs.docker.com/build-cloud/\"\u003eDocker Build Cloud\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.17.0...v6.18.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.17.0...v6.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.17.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.59.0 to 0.61.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1364\"\u003edocker/build-push-action#1364\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nBuild record is now exported using the \u003ca href=\"https://docs.docker.com/reference/cli/docker/buildx/history/export/\"\u003e\u003ccode\u003ebuildx history export\u003c/code\u003e\u003c/a\u003e command instead of the legacy export-build tool.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.16.0...v6.17.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.16.0...v6.17.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.16.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle no default attestations env var by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1343\"\u003edocker/build-push-action#1343\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/v6...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/dependency-review-action` from 4.9.0 to 5.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/dependency-review-action/releases\"\u003eactions/dependency-review-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.0\u003c/h2\u003e\n\u003cp\u003eThis is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003ev2.327.1\u003c/a\u003e to run.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd .github/copilot-instructions.md for Copilot coding agent by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1067\"\u003eactions/dependency-review-action#1067\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js runtime from 20 to 24 by \u003ca href=\"https://github.com/scottschreckengaust\"\u003e\u003ccode\u003e@​scottschreckengaust\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1084\"\u003eactions/dependency-review-action#1084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump spdx-license-ids from 3.0.20 to 3.0.23 by \u003ca href=\"https://github.com/mongolyy\"\u003e\u003ccode\u003e@​mongolyy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1091\"\u003eactions/dependency-review-action#1091\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: bump actions/checkout from v4 to v6 in workflow examples by \u003ca href=\"https://github.com/Marukome0743\"\u003e\u003ccode\u003e@​Marukome0743\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1077\"\u003eactions/dependency-review-action#1077\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: patched version display for advisories with non-strict semver ranges (e.g. Maven beta versions) by \u003ca href=\"https://github.com/tspascoal\"\u003e\u003ccode\u003e@​tspascoal\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1076\"\u003eactions/dependency-review-action#1076\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve security findings by \u003ca href=\"https://github.com/AshelyTC\"\u003e\u003ccode\u003e@​AshelyTC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1094\"\u003eactions/dependency-review-action#1094\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ev5.0.0 release branch by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1098\"\u003eactions/dependency-review-action#1098\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scottschreckengaust\"\u003e\u003ccode\u003e@​scottschreckengaust\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1084\"\u003eactions/dependency-review-action#1084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongolyy\"\u003e\u003ccode\u003e@​mongolyy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1091\"\u003eactions/dependency-review-action#1091\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Marukome0743\"\u003e\u003ccode\u003e@​Marukome0743\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1077\"\u003eactions/dependency-review-action#1077\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0\"\u003ehttps://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a1d282b36b6f3519aa1f3fc636f609c47dddb294\"\u003e\u003ccode\u003ea1d282b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1098\"\u003e#1098\u003c/a\u003e from actions/ahpook/v5-release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/eb6c199c5a85c7387f1f0b02b3ba5c6364740695\"\u003e\u003ccode\u003eeb6c199\u003c/code\u003e\u003c/a\u003e update examples to show \u003ca href=\"https://github.com/v5\"\u003e\u003ccode\u003e@​v5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/3943c2c5beaaaf1806eb3758273c203dabcbf89c\"\u003e\u003ccode\u003e3943c2c\u003c/code\u003e\u003c/a\u003e v5.0.0 release branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/454943c880b147adbfe7de0cdd3ece1c00882033\"\u003e\u003ccode\u003e454943c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1094\"\u003e#1094\u003c/a\u003e from actions/ashelytc/security-findings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/6d92a1228e9e9db334f02c09f84fe9217d2b4463\"\u003e\u003ccode\u003e6d92a12\u003c/code\u003e\u003c/a\u003e revert \u003ccode\u003e@​typescript-eslint/parser\u003c/code\u003e update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a8e5a7e93695b41abf6d1083cd220bee39a720f0\"\u003e\u003ccode\u003ea8e5a7e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1076\"\u003e#1076\u003c/a\u003e from tspascoal/fix-version-matching-for-non-string-s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/b6b7079031ef4ed61656c221988f1f3bcbf35101\"\u003e\u003ccode\u003eb6b7079\u003c/code\u003e\u003c/a\u003e update \u003ccode\u003e@​typescript-eslint/parser\u003c/code\u003e to 8.40.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/821a21dd691f162c4c5c2e9754a344accde9a208\"\u003e\u003ccode\u003e821a21d\u003c/code\u003e\u003c/a\u003e update more dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/05aaaae45cf4c420de012addf2a72e3435ddaa63\"\u003e\u003ccode\u003e05aaaae\u003c/code\u003e\u003c/a\u003e run npm audit fix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/55d3e754501fc13c84b95637ce51f135012d41ea\"\u003e\u003ccode\u003e55d3e75\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1077\"\u003e#1077\u003c/a\u003e from Marukome0743/docs/checkout\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/dependency-review-action/compare/2031cfc080254a8a887f58cffee85186f0e49e48...a1d282b36b6f3519aa1f3fc636f609c47dddb294\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 4 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003ev7 What's new\u003c/h2\u003e\n\u003ch3\u003eDirect Uploads\u003c/h3\u003e\n\u003cp\u003eAdds support for uploading single files directly (unzipped). Callers can set the new \u003ccode\u003earchive\u003c/code\u003e parameter to \u003ccode\u003efalse\u003c/code\u003e to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The \u003ccode\u003ename\u003c/code\u003e parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.\u003c/p\u003e\n\u003ch3\u003eESM\u003c/h3\u003e\n\u003cp\u003eTo support new versions of the \u003ccode\u003e@actions/*\u003c/code\u003e packages, we've upgraded the package to ESM.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd proxy integration test by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade the module to ESM and bump dependencies by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/762\"\u003eactions/upload-artifact#762\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport direct file uploads by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/764\"\u003eactions/upload-artifact#764\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- made their first contribution in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/upload-artifact/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003ev6 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/upload-artifact@v6 now runs on Node.js 24 (\u003ccode\u003eruns.using: node24\u003c/code\u003e) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eNode.js 24\u003c/h3\u003e\n\u003cp\u003eThis release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpload Artifact Node 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/719\"\u003eactions/upload-artifact#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update \u003ccode\u003e@​actions/artifact\u003c/code\u003e for Node.js 24 punycode deprecation by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/744\"\u003eactions/upload-artifact#744\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare release v6.0.0 for Node.js 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/745\"\u003eactions/upload-artifact#745\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0\"\u003ehttps://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBREAKING CHANGE:\u003c/strong\u003e this update supports Node \u003ccode\u003ev24.x\u003c/code\u003e. This is not a breaking change per-se but we're treating it as such.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate README.md by \u003ca href=\"https://github.com/GhadimiR\"\u003e\u003ccode\u003e@​GhadimiR\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/681\"\u003eactions/upload-artifact#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca href=\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/712\"\u003eactions/upload-artifact#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: spell out the first use of GHES by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/727\"\u003eactions/upload-artifact#727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate GHES guidance to include reference to Node 20 version by \u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/725\"\u003eactions/upload-artifact#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/artifact\u003c/code\u003e to \u003ccode\u003ev4.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ePrepare \u003ccode\u003ev5.0.0\u003c/code\u003e by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/734\"\u003eactions/upload-artifact#734\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f\"\u003e\u003ccode\u003ebbbca2d\u003c/code\u003e\u003c/a\u003e Support direct file uploads (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/764\"\u003e#764\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/589182c5a4cec8920b8c1bce3e2fab1c97a02296\"\u003e\u003ccode\u003e589182c\u003c/code\u003e\u003c/a\u003e Upgrade the module to ESM and bump dependencies (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/762\"\u003e#762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/47309c993abb98030a35d55ef7ff34b7fa1074b5\"\u003e\u003ccode\u003e47309c9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/754\"\u003e#754\u003c/a\u003e from actions/Link-/add-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/02a8460834e70dab0ce194c64360c59dc1475ef0\"\u003e\u003ccode\u003e02a8460\u003c/code\u003e\u003c/a\u003e Add proxy integration test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/b7c566a772e6b6bfb58ed0dc250532a479d7789f\"\u003e\u003ccode\u003eb7c566a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/745\"\u003e#745\u003c/a\u003e from actions/upload-artifact-v6-release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e516bc8500aaf3d07d591fcd4ae6ab5f9c391d5b\"\u003e\u003ccode\u003ee516bc8\u003c/code\u003e\u003c/a\u003e docs: correct description of Node.js 24 support in README\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/upload-artifact/compare/v4...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/download-artifact` from 4 to 8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/download-artifact/releases\"\u003eactions/download-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.0.0\u003c/h2\u003e\n\u003ch2\u003ev8 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nHash mismatches will now error by default. Users can override this behavior with a setting change (see below).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eDirect downloads\u003c/h3\u003e\n\u003cp\u003eTo support direct uploads in \u003ccode\u003eactions/upload-artifact\u003c/code\u003e, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the \u003ccode\u003eContent-Type\u003c/code\u003e header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new \u003ccode\u003eskip-decompress\u003c/code\u003e parameter to \u003ccode\u003etrue\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eEnforced checks (breaking)\u003c/h3\u003e\n\u003cp\u003eA previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the \u003ccode\u003edigest-mismatch\u003c/code\u003e parameter. To be secure by default, we are now defaulting the behavior to \u003ccode\u003eerror\u003c/code\u003e which will fail the workflow run.\u003c/p\u003e\n\u003ch3\u003eESM\u003c/h3\u003e\n\u003cp\u003eTo support new versions of the @actions/* packages, we've upgraded the package to ESM.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDon't attempt to un-zip non-zipped downloads by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/460\"\u003eactions/download-artifact#460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a setting to specify what to do on hash mismatch and default it to \u003ccode\u003eerror\u003c/code\u003e by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/461\"\u003eactions/download-artifact#461\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/download-artifact/compare/v7...v8.0.0\"\u003ehttps://github.com/actions/download-artifact/compare/v7...v8.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003ev7 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/download-artifact@v7 now runs on Node.js 24 (\u003ccode\u003eruns.using: node24\u003c/code\u003e) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eNode.js 24\u003c/h3\u003e\n\u003cp\u003eThis release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate GHES guidance to include reference to Node 20 version by \u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/440\"\u003eactions/download-artifact#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDownload Artifact Node24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/415\"\u003eactions/download-artifact#415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update \u003ccode\u003e@​actions/artifact\u003c/code\u003e to fix Node.js 24 punycode deprecation by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/451\"\u003eactions/download-artifact#451\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare release v7.0.0 for Node.js 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/452\"\u003eactions/download-artifact#452\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/440\"\u003eactions/download-artifact#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/415\"\u003eactions/download-artifact#415\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0\"\u003ehttps://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c\"\u003e\u003ccode\u003e3e5f45b\u003c/code\u003e\u003c/a\u003e Add regression tests for CJK characters (\u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/471\"\u003e#471\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/e6d03f67377d4412c7aa56a8e2e4988e6ec479dd\"\u003e\u003ccode\u003ee6d03f6\u003c/code\u003e\u003c/a\u003e Add a regression test for artifact name + content-type mismatches (\u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/472\"\u003e#472\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3\"\u003e\u003ccode\u003e70fc10c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/461\"\u003e#461\u003c/a\u003e from actions/danwkennedy/digest-mismatch-behavior\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/f258da9a506b755b84a09a531814700b86ccfc62\"\u003e\u003ccode\u003ef258da9\u003c/code\u003e\u003c/a\u003e Add change docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/ccc058e5fbb0bb2352213eaec3491e117cbc4a5c\"\u003e\u003ccode\u003eccc058e\u003c/code\u003e\u003c/a\u003e Fix linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/bd7976ba57ecea96e6f3df575eb922d11a12a9fd\"\u003e\u003ccode\u003ebd7976b\u003c/code\u003e\u003c/a\u003e Add a setting to specify what to do on hash mismatch and default it to \u003ccode\u003eerror\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/ac21fcf45e0aaee541c0f7030558bdad38d77d6c\"\u003e\u003ccode\u003eac21fcf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/460\"\u003e#460\u003c/a\u003e from actions/danwkennedy/download-no-unzip\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/15999bff51058bc7c19b50ebbba518eaef7c26c0\"\u003e\u003ccode\u003e15999bf\u003c/code\u003e\u003c/a\u003e Add note about package bumps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/974686ed5098c7f9c9289ec946b9058e496a2561\"\u003e\u003ccode\u003e974686e\u003c/code\u003e\u003c/a\u003e Bump the version to \u003ccode\u003ev8\u003c/code\u003e and add release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/fbe48b1d2756394be4cd4358ed3bc1343b330e75\"\u003e\u003ccode\u003efbe48b1\u003c/code\u003e\u003c/a\u003e Update test names to make it clearer what they do\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/download-artifact/compare/v4...v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `oven-sh/setup-bun` from 1 to 2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oven-sh/setup-bun/releases\"\u003eoven-sh/setup-bun's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eoven-sh/setup-bun\u003c/code\u003e is the github action for setting up Bun.\u003c/p\u003e\n\u003cp\u003eThis release introduces support for the \u003ccode\u003ebun-version-file\u003c/code\u003e option, fixes \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/79\"\u003eoven-sh/setup-bun#79\u003c/a\u003e, and adds bun paths \u0026amp; urls to the output (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/81\"\u003eoven-sh/setup-bun#81\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor more information, see \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/pull/76\"\u003eoven-sh/setup-bun#76\u003c/a\u003e by \u003ca href=\"https://github.com/adeherysh\"\u003e\u003ccode\u003e@​adeherysh\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/pull/80\"\u003eoven-sh/setup-bun#80\u003c/a\u003e by \u003ca href=\"https://github.com/xHyroM\"\u003e\u003ccode\u003e@​xHyroM\u003c/code\u003e\u003c/a\u003e :tada:\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/oven-sh/setup-bun/compare/v1...v2\"\u003ehttps://github.com/oven-sh/setup-bun/compare/v1...v2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eoven-sh/setup-bun\u003c/code\u003e is the github action for setting up Bun.\u003c/p\u003e\n\u003cp\u003eThis release introduces support for the \u003ccode\u003ebun-download-url\u003c/code\u003e input, which lets you override the URL used to download the .zip file for Bun.\u003c/p\u003e\n\u003cp\u003eHere's an example:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- name: Setup Bun\r\n  uses: oven-sh/setup-bun@v1.2.2\r\n  with:\r\n    bun-version: latest\r\n    bun-download-url: \u0026quot;https://github.com/oven-sh/bun/releases/latest/download/bun-${{runner.os == 'macOS' \u0026amp;\u0026amp; 'darwin' || runner.os}}-${{ runner.arch == 'X64' \u0026amp;\u0026amp; 'x64' || 'arm64' }}.zip\u0026quot;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003ev1.2.1\u003c/h2\u003e\n\u003ch1\u003esetup-bun \u003ccode\u003ev1.2.1\u003c/code\u003e\u003c/h1\u003e\n\u003cp\u003eDownload, install, and setup \u003ca href=\"https://bun.sh\"\u003eBun\u003c/a\u003e in GitHub Actions.\u003c/p\u003e\n\u003ch2\u003eUsage\u003c/h2\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- uses: oven-sh/setup-bun@v1\r\n  with:\r\n    bun-version: latest\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch3\u003eUsing a custom NPM registry\u003c/h3\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- uses: oven-sh/setup-bun@v1\r\n  with:\r\n    registry-url: \u0026quot;https://npm.pkg.github.com/\u0026quot;\r\n    scope: \u0026quot;@foo\u0026quot;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eIf you need to authenticate with a private registry, you can set the \u003ccode\u003eBUN_AUTH_TOKEN\u003c/code\u003e environment variable.\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- name: Install Dependencies\r\n  env:\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/0c5077e51419868618aeaa5fe8019c62421857d6\"\u003e\u003ccode\u003e0c5077e\u003c/code\u003e\u003c/a\u003e release: v2.2.0 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/177\"\u003e#177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/1255e43b02f74b77bb39330ef756405951c3303a\"\u003e\u003ccode\u003e1255e43\u003c/code\u003e\u003c/a\u003e ci: update actions for the \u003ccode\u003eRelease new action version\u003c/code\u003e workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/175\"\u003e#175\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/61861d1f6a3acf561f12343ea89e2c71ff4af529\"\u003e\u003ccode\u003e61861d1\u003c/code\u003e\u003c/a\u003e ci: update actions for the \u003ccode\u003eautofix.ci\u003c/code\u003e workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/174\"\u003e#174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/6f5bd063f58cadd19ae42cca8bb41b191e9949bd\"\u003e\u003ccode\u003e6f5bd06\u003c/code\u003e\u003c/a\u003e ci: use \u003ccode\u003eactions/checkout@v6.0.2\u003c/code\u003e in the test workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/173\"\u003e#173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/e3914758a49697077f7bcd190d36582a61667aad\"\u003e\u003ccode\u003ee391475\u003c/code\u003e\u003c/a\u003e build: update action runtime to Node.js 24 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/176\"\u003e#176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/ecf28ddc73e819eb6fa29df6b34ef8921c743461\"\u003e\u003ccode\u003eecf28dd\u003c/code\u003e\u003c/a\u003e release: v2.1.3 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/95edc153a3f71202eb7d8f0ee7b43c6b8b16763f\"\u003e\u003ccode\u003e95edc15\u003c/code\u003e\u003c/a\u003e fix: validate cached binary version matches requested version (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/146\"\u003e#146\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/4c32875876eebbbb9bc34b8ee07ba2d7bb4b3462\"\u003e\u003ccode\u003e4c32875\u003c/code\u003e\u003c/a\u003e feat: add AVX2 support detection for x64 Linux systems (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/167\"\u003e#167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/0ff83bfc51e05dd2251088164ec6a5e8533b476b\"\u003e\u003ccode\u003e0ff83bf\u003c/code\u003e\u003c/a\u003e fix: use native Windows ARM64 binary for Bun \u0026gt;= 1.3.10 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/ab8cb4e8f89912a29b87e4abc4554f2301648a5c\"\u003e\u003ccode\u003eab8cb4e\u003c/code\u003e\u003c/a\u003e feat: add bun- prefix to cache keys (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/oven-sh/setup-bun/compare/v1...v2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 4 to 6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate packages, migrate to ESM by \u003ca href=\"https://github.com/Samirat\"\u003e\u003ccode\u003e@​Samirat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1760\"\u003eactions/cache#1760\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v6.0.0\"\u003ehttps://github.com/actions/cache/compare/v5...v6.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/cache\u003c/code\u003e to v5.1.0 - handle read-only cache access by \u003ca href=\"https://github.com/jasongin\"\u003e\u003ccode\u003e@​jasongin\u003c/cod...\n\n_Description has been truncated_","html_url":"https://github.com/simhadris17/SimhaStack/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/simhadris17%2FSimhaStack/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"},{"uuid":"5532743281","node_id":"PR_kwDOTayYl88AAAABEfbqag","number":18,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T21:38:59.000Z","updated_at":"2026-09-21T21:39:36.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.3.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.3.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.5.1","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"pypa/gh-action-pypi-publish","old_version":"1.14.1","new_version":"1.14.2","repository_url":"https://github.com/pypa/gh-action-pypi-publish"},{"name":"sigstore/gh-action-sigstore-python","old_version":"3.4.0","new_version":"3.5.0","repository_url":"https://github.com/sigstore/gh-action-sigstore-python"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.3.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.5.1` | `4.6.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n| [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.1` | `1.14.2` |\n| [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) | `3.4.0` | `3.5.0` |\n\n\nUpdates `hadolint/hadolint-action` from 3.3.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/75bb911ebea0ab9b6188cbaba353bb3de62287e7\"\u003e\u003ccode\u003e75bb911\u003c/code\u003e\u003c/a\u003e fixup! Update hadolint.sh\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/631cc83a1d7add7571da26544581e8bb9db9c62a\"\u003e\u003ccode\u003e631cc83\u003c/code\u003e\u003c/a\u003e Update repository reference in problem-matcher.json\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/2332a7b74a6de0dda2e2221d575162eba76ba5e5...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.3.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.5.1 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/abd2ef45e78c5afb21d64d4ca52ee8550d9572c7...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/releases\"\u003epypa/gh-action-pypi-publish's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.14.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🛠️ Urgh… Another release!? Again? Explain yourself!\u003c/h2\u003e\n\u003cp\u003eLooking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!tip]\nSo what \u003cem\u003emost\u003c/em\u003e people will find useful is \u003ca href=\"https://github.com/takluyver\"\u003e\u003ccode\u003e@​takluyver\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/takluyver\"\u003e💰\u003c/a\u003e's update of Twine to v7 that we use internally (\u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003e🧐 Tell me why..\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eTL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like \u003ca href=\"https://redirect.github.com/aio-libs/aiohttp/pull/13226\"\u003eaio-libs/aiohttp#13226\u003c/a\u003e around July 23.\nOn this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.\u003c/p\u003e\n\u003cp\u003eI had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.\u003c/p\u003e\n\u003cp\u003eOver the course of investigation, \u003ca href=\"https://github.com/facutuesca\"\u003e\u003ccode\u003e@​facutuesca\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/facutuesca\"\u003e💰\u003c/a\u003e found and fixed a related underlying cache invalidation bug in \u003ca href=\"https://redirect.github.com/sigstore/sigstore-python/pull/1838\"\u003esigstore/sigstore-python#1838\u003c/a\u003e, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.\u003c/p\u003e\n\u003cp\u003eMike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: \u003ca href=\"https://publishing-five-minute-timeout.tiiny.site\"\u003ehttps://publishing-five-minute-timeout.tiiny.site\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🫶 New Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415\"\u003e#415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/takluyver\"\u003e\u003ccode\u003e@​takluyver\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e🪞 Full Diff\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2\"\u003ehttps://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e🧔‍♂️ Release Manager:\u003c/strong\u003e \u003ca href=\"https://github.com/sponsors/webknjaz\"\u003e\u003ccode\u003e@​webknjaz\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://stand-with-ukraine.pp.ua\"\u003e🇺🇦\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e🙏 Special Thanks\u003c/strong\u003e to \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/davidbrochart\"\u003e💰\u003c/a\u003e and \u003ca href=\"https://github.com/Dreamsorcerer\"\u003e\u003ccode\u003e@​Dreamsorcerer\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/Dreamsorcerer\"\u003e💰\u003c/a\u003e for turning my attention (in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415\"\u003e#415\u003c/a\u003e and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. \u003ca href=\"https://github.com/bdraco\"\u003e\u003ccode\u003e@​bdraco\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/bdraco\"\u003e💰\u003c/a\u003e came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. \u003ca href=\"https://github.com/miketheman\"\u003e\u003ccode\u003e@​miketheman\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/miketheman\"\u003e💰\u003c/a\u003e confirmed the Warehouse-side details. Also, \u003ca href=\"https://github.com/jku\"\u003e\u003ccode\u003e@​jku\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/jku\"\u003e💰\u003c/a\u003e and \u003ca href=\"https://github.com/woodruffw\"\u003e\u003ccode\u003e@​woodruffw\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/woodruffw\"\u003e💰\u003c/a\u003e helped work through, review and release the Sigstore ecosystem upstream libs.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e💬 Discuss\u003c/strong\u003e \u003ca href=\"https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j\"\u003eon Bluesky 🦋\u003c/a\u003e, \u003ca href=\"https://mastodon.social/@webknjaz/117005132816750073\"\u003eon Mastodon 🐘\u003c/a\u003e and [on GitHub][release discussion].\u003c/p\u003e\n\u003cp\u003e[![GH Sponsors badge]][GH Sponsors URL]\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/dc37677b2e1c63e2034f94d8a5b11f265b73ba33\"\u003e\u003ccode\u003edc37677\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/417\"\u003e#417\u003c/a\u003e from trail-of-forks/ft/bump-deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/8b2f23418f024937cf97f77534a597947105e772\"\u003e\u003ccode\u003e8b2f234\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypi-attestations\u003c/code\u003e and \u003ccode\u003esigstore\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/78b72dbfed6e025eb89577c059edc936f8a2df14\"\u003e\u003ccode\u003e78b72db\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e from takluyver/twine-v7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/92f4d2a159875dd135a7e56b7b3262f502b23a13\"\u003e\u003ccode\u003e92f4d2a\u003c/code\u003e\u003c/a\u003e Update twine to v7\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/compare/ba38be9e461d3875417946c167d0b5f3d385a247...dc37677b2e1c63e2034f94d8a5b11f265b73ba33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sigstore/gh-action-sigstore-python` from 3.4.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/releases\"\u003esigstore/gh-action-sigstore-python's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe action now uses \u003ca href=\"https://github.com/sigstore/sigstore-python\"\u003esigstore\u003c/a\u003e 4.5.0\u003c/li\u003e\n\u003cli\u003eBump other dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/compare/v3.4.0...v3.5.0\"\u003ehttps://github.com/sigstore/gh-action-sigstore-python/compare/v3.4.0...v3.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/790bc6befb9d733738f18d8f895854b453640ec9\"\u003e\u003ccode\u003e790bc6b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/upload-sarif in the actions group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/445\"\u003e#445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/513a14942a452294df6cf0387762f4872d190109\"\u003e\u003ccode\u003e513a149\u003c/code\u003e\u003c/a\u003e build(deps): bump platformdirs in the python-dependencies group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/446\"\u003e#446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/74e004047800e50833c6fe90f17003f764a112fa\"\u003e\u003ccode\u003e74e0040\u003c/code\u003e\u003c/a\u003e Bump sigstore from 4.4 to 4.5 (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/444\"\u003e#444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/52538fdda336882a056c40b6364f8b39cf117401\"\u003e\u003ccode\u003e52538fd\u003c/code\u003e\u003c/a\u003e build(deps): bump the actions group across 1 directory with 4 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/439\"\u003e#439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/cbab91d8551b56009e61847b6403dea3baaf5509\"\u003e\u003ccode\u003ecbab91d\u003c/code\u003e\u003c/a\u003e build(deps): bump the python-dependencies group across 1 directory with 9 upd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/1d3524cb549bc0806f8ed27cdf6b6434d37a42a1\"\u003e\u003ccode\u003e1d3524c\u003c/code\u003e\u003c/a\u003e build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 in the acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/a1744845fbc68281e15c62b04220920b9f3c0766\"\u003e\u003ccode\u003ea174484\u003c/code\u003e\u003c/a\u003e build(deps): bump sigstore from 4.3.0 to 4.4.0 in the python-dependencies gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/0b384a68485d27aa4751533ff55c1d3ac2eb46af\"\u003e\u003ccode\u003e0b384a6\u003c/code\u003e\u003c/a\u003e build(deps): bump the actions group with 2 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/429\"\u003e#429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/f11d8f862eca1b34affd24b3403ae612f0980527\"\u003e\u003ccode\u003ef11d8f8\u003c/code\u003e\u003c/a\u003e build(deps): bump typing-extensions in the python-dependencies group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/430\"\u003e#430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/258577b06d5c2d98682589ca8b6e432ec9bfe070\"\u003e\u003ccode\u003e258577b\u003c/code\u003e\u003c/a\u003e build(deps): bump the python-dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/compare/5b79a39c381910c090341a2c9b0bf022c8b387e1...790bc6befb9d733738f18d8f895854b453640ec9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/creezio/hermes-agent-creezio/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/creezio%2Fhermes-agent-creezio/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"},{"uuid":"5532400452","node_id":"PR_kwDOUiFKBs8AAAABEfJ--g","number":6,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T20:59:32.000Z","updated_at":"2026-09-22T05:03:55.825Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Chensihakniroth/anakot-agent-v1/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Chensihakniroth%2Fanakot-agent-v1/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"5531737691","node_id":"PR_kwDOTn5yY88AAAABEenkRw","number":90,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T19:51:20.000Z","updated_at":"2026-09-21T19:51:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"github/codeql-action/init","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"docker/setup-buildx-action","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/docker/setup-buildx-action"},{"name":"docker/build-push-action","old_version":"7.3.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n\nUpdates `github/codeql-action/init` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/setup-buildx-action` from 4.3.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip BuildKit image pre-pulls for explicit endpoints by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/624\"\u003edocker/setup-buildx-action#624\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse official Buildx releases for cloud driver by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/606\"\u003edocker/setup-buildx-action#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePull BuildKit image before builder creation by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/609\"\u003edocker/setup-buildx-action#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse shared error helpers for Buildx and Docker commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/620\"\u003edocker/setup-buildx-action#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.95.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/610\"\u003edocker/setup-buildx-action#610\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/618\"\u003edocker/setup-buildx-action#618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/619\"\u003edocker/setup-buildx-action#619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/614\"\u003edocker/setup-buildx-action#614\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.3.0 to 5.4.2 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/608\"\u003edocker/setup-buildx-action#608\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/617\"\u003edocker/setup-buildx-action#617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/611\"\u003edocker/setup-buildx-action#611\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003e\u003ccode\u003ef87e599\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/624\"\u003e#624\u003c/a\u003e from crazy-max/skip-pull-with-endpoint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022\"\u003e\u003ccode\u003ee700274\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07\"\u003e\u003ccode\u003e3061c91\u003c/code\u003e\u003c/a\u003e skip BuildKit image pre-pulls for explicit endpoints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003\"\u003e\u003ccode\u003e594f3bf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/609\"\u003e#609\u003c/a\u003e from crazy-max/pull-buildkit-image-before-create\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25\"\u003e\u003ccode\u003ebd6e702\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032\"\u003e\u003ccode\u003e6268c9d\u003c/code\u003e\u003c/a\u003e pull BuildKit image before builder creation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11\"\u003e\u003ccode\u003ee823525\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/621\"\u003e#621\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d\"\u003e\u003ccode\u003e533ed8e\u003c/code\u003e\u003c/a\u003e build(deps): bump the codeql-actions group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99\"\u003e\u003ccode\u003ebedaf13\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/620\"\u003e#620\u003c/a\u003e from crazy-max/shared-error-helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2\"\u003e\u003ccode\u003ed5079fb\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.3.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/mintoriakamoto/Hercules/pull/90","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mintoriakamoto%2FHercules/issues/90","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/90/packages"},{"uuid":"5527747551","node_id":"PR_kwDOTVqsYM8AAAABEbZOEg","number":113,"state":"open","title":"chore(deps): bump the github-actions group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T13:37:58.000Z","updated_at":"2026-09-21T20:27:44.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"github-actions","update_count":3,"packages":[{"name":"github/codeql-action/init","old_version":"4.37.9","new_version":"4.38.0","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.37.9","new_version":"4.38.0","repository_url":"https://github.com/github/codeql-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `github/codeql-action/init` from 4.37.9 to 4.38.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003e\u003ccode\u003eb96794f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4131\"\u003e#4131\u003c/a\u003e from github/update-v4.38.0-7e08580a9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef\"\u003e\u003ccode\u003e02d5093\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6\"\u003e\u003ccode\u003e7e08580\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4130\"\u003e#4130\u003c/a\u003e from github/henrymercer/workflow-runner-sizing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698\"\u003e\u003ccode\u003ebfcc52b\u003c/code\u003e\u003c/a\u003e Run slow macOS checks on larger runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4\"\u003e\u003ccode\u003e8c251e7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4129\"\u003e#4129\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1\"\u003e\u003ccode\u003e0b7ca40\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505\"\u003e\u003ccode\u003e40484b3\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df\"\u003e\u003ccode\u003e977e6ce\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4124\"\u003e#4124\u003c/a\u003e from github/henrymercer/toolcache-bundle-cleanup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc\"\u003e\u003ccode\u003e40a6b38\u003c/code\u003e\u003c/a\u003e Address toolcache cleanup review feedback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252\"\u003e\u003ccode\u003edeece8f\u003c/code\u003e\u003c/a\u003e Apply suggestion from \u003ca href=\"https://github.com/henrymercer\"\u003e\u003ccode\u003e@​henrymercer\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.37.9 to 4.38.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003e\u003ccode\u003eb96794f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4131\"\u003e#4131\u003c/a\u003e from github/update-v4.38.0-7e08580a9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef\"\u003e\u003ccode\u003e02d5093\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6\"\u003e\u003ccode\u003e7e08580\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4130\"\u003e#4130\u003c/a\u003e from github/henrymercer/workflow-runner-sizing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698\"\u003e\u003ccode\u003ebfcc52b\u003c/code\u003e\u003c/a\u003e Run slow macOS checks on larger runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4\"\u003e\u003ccode\u003e8c251e7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4129\"\u003e#4129\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1\"\u003e\u003ccode\u003e0b7ca40\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505\"\u003e\u003ccode\u003e40484b3\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df\"\u003e\u003ccode\u003e977e6ce\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4124\"\u003e#4124\u003c/a\u003e from github/henrymercer/toolcache-bundle-cleanup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc\"\u003e\u003ccode\u003e40a6b38\u003c/code\u003e\u003c/a\u003e Address toolcache cleanup review feedback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252\"\u003e\u003ccode\u003edeece8f\u003c/code\u003e\u003c/a\u003e Apply suggestion from \u003ca href=\"https://github.com/henrymercer\"\u003e\u003ccode\u003e@​henrymercer\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/windwardline/pathfinder/pull/113","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/windwardline%2Fpathfinder/issues/113","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/113/packages"},{"uuid":"5524164261","node_id":"PR_kwDOGBFizs8AAAABEYhKtA","number":172,"state":"closed","title":"ci(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-21T07:44:13.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T07:44:00.000Z","updated_at":"2026-09-21T07:44:20.000Z","time_to_close":13,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.5.1 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.5.1\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/thomasleplus/thomasleplus/pull/172","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/thomasleplus%2Fthomasleplus/issues/172","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/172/packages"}],"issue_packages":[{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-10-01T21:43:16.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5669607201","node_id":"PR_kwDONFihn88AAAABGLytTg","number":421,"state":"open","title":"build(deps): bump the all group with 4 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T21:43:16.000Z","updated_at":"2026-10-01T21:43:42.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all","update_count":4,"packages":[{"name":"pnpm/setup","old_version":"2.0.2","new_version":"3.0.0","repository_url":"https://github.com/pnpm/setup"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"zizmorcore/zizmor-action","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/zizmorcore/zizmor-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the all group with 4 updates: [pnpm/setup](https://github.com/pnpm/setup), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).\n\nUpdates `pnpm/setup` from 2.0.2 to 3.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pnpm/setup/releases\"\u003epnpm/setup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix!: include runid in cache key, restore freshest lockfile match by \u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat!: automatically detect Node.js version files by \u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add private registry authentication recipes by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/61\"\u003epnpm/setup#61\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid deprecated shell spawning for pnpm commands by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/52\"\u003epnpm/setup#52\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: require-lockfile no longer accepts a lockfile pnpm will not use by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/60\"\u003epnpm/setup#60\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: restore cache before installing runtime by \u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: install multiple runtimes from devEngines.runtime by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: cache pnpm's lockfile verification results by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/30\"\u003epnpm/setup#30\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e by \u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: update dependencies with pnpm/update instead of Dependabot by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/41\"\u003epnpm/setup#41\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update dependencies by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003e\u003ccode\u003efbda4c8\u003c/code\u003e\u003c/a\u003e docs(README): update version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c868a7d055a8423cab9de075713ce4ce9bf9205d\"\u003e\u003ccode\u003ec868a7d\u003c/code\u003e\u003c/a\u003e fix: require-lockfile no longer accepts a lockfile pnpm will not use (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/60\"\u003e#60\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/463911b67ec9290f1350907aa2b257be0aca1687\"\u003e\u003ccode\u003e463911b\u003c/code\u003e\u003c/a\u003e fix: avoid deprecated shell spawning for pnpm commands (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/52\"\u003e#52\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/659828629c47ab99e8bdf4cc9aec88a8aab310a6\"\u003e\u003ccode\u003e6598286\u003c/code\u003e\u003c/a\u003e docs: add private registry authentication recipes (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/61\"\u003e#61\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c5b2e249903756c468007fa3f013203377937b5b\"\u003e\u003ccode\u003ec5b2e24\u003c/code\u003e\u003c/a\u003e feat!: automatically detect Node.js version files (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/f37addefd310ed0d00a4de48e30bb7e1c4414491\"\u003e\u003ccode\u003ef37adde\u003c/code\u003e\u003c/a\u003e fix!: include runid in cache key, restore freshest lockfile match (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/43\"\u003e#43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/703c52620218391530e48b9e8870d5c0082e1b9b\"\u003e\u003ccode\u003e703c526\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/e02cd34ce0366c68c5fccdd0f0fd4fa1f9d3459c\"\u003e\u003ccode\u003ee02cd34\u003c/code\u003e\u003c/a\u003e ci: update dependencies with pnpm/update instead of Dependabot (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/41\"\u003e#41\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/0080eca8ccdd50c579e4d2242cc958f8e8b3040e\"\u003e\u003ccode\u003e0080eca\u003c/code\u003e\u003c/a\u003e feat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/23\"\u003e#23\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/3327d57c1fba3d6ed3bef37285efc7a45c25f6cd\"\u003e\u003ccode\u003e3327d57\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/zizmorcore/zizmor-action/releases\"\u003ezizmorcore/zizmor-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sponsors/woodruffw/\"\u003eSponsorship is appreciated!\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003ezizmor 1.30.1 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1301%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1301)\"\u003ezizmorcore/zizmor-action#1301\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.6.3\u003c/h2\u003e\n\u003cp\u003ezizmor 1.30.0 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1300%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1300)\"\u003ezizmorcore/zizmor-action#1300\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003e\u003ccode\u003ecc914d7\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/bae72b71bc270806f906e8e2a1f5985a26effaa2\"\u003e\u003ccode\u003ebae72b7\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/27604f9eef072d6456e69fc10ee36629710fa6f6\"\u003e\u003ccode\u003e27604f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/164\"\u003e#164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/c41d66537b2d733801baec1e31ffc22aa2051a8f\"\u003e\u003ccode\u003ec41d665\u003c/code\u003e\u003c/a\u003e README: bump pins (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/163\"\u003e#163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/70fb788f84895a7701f5643d103d587e460b5c99\"\u003e\u003ccode\u003e70fb788\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/162\"\u003e#162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/7999d8c8ac51dbd3bd44e6e35e7cd015b5dcdc82\"\u003e\u003ccode\u003e7999d8c\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/2ae1ce9c6b7248fdfc5a4f47f3527240521f79b9\"\u003e\u003ccode\u003e2ae1ce9\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/951a5eef1c3d7669c20934ceca759fdf8dbd153e\"\u003e\u003ccode\u003e951a5ee\u003c/code\u003e\u003c/a\u003e Skip prerelease versions in sync-zizmor-versions workflow (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/158\"\u003e#158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/79f019101434ac77d41ed24f93c6bdc8676bd355\"\u003e\u003ccode\u003e79f0191\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/156\"\u003e#156\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/26a3ae6758a68e521bfe592f503410eb61b699bb\"\u003e\u003ccode\u003e26a3ae6\u003c/code\u003e\u003c/a\u003e sync-zizmor-versions: retry up to 5 times (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/155\"\u003e#155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/zizmorcore/zizmor-action/compare/3dc1ecc9bcb9e94e9b2c709687979e1298497054...cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/gahojin/date-fns-japan/pull/421","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gahojin%2Fdate-fns-japan/issues/421","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/421/packages"}},{"old_version":"c7c7bcb0773cc4678a674ada03a66cc5c4325476","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","update_type":null,"path":null,"pr_created_at":"2026-10-01T09:36:15.000Z","version_change":"c7c7bcb0773cc4678a674ada03a66cc5c4325476 → 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","issue":{"uuid":"5660097317","node_id":"PR_kwDOUXF5V88AAAABGEGWlA","number":20,"state":"open","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from c7c7bcb0773cc4678a674ada03a66cc5c4325476 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T09:36:15.000Z","updated_at":"2026-10-01T09:36:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"c7c7bcb0773cc4678a674ada03a66cc5c4325476","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from c7c7bcb0773cc4678a674ada03a66cc5c4325476 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003e\u003ccode\u003e8ac9e5c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/143\"\u003e#143\u003c/a\u003e from renovate-bot/renovate/workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/3b06fbb744e4192b7d47b4f2584715a21ef88b92\"\u003e\u003ccode\u003e3b06fbb\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.38.0\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/c7c7bcb0773cc4678a674ada03a66cc5c4325476...8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/nakedape2000/bandcamp-wishlist-tidal/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nakedape2000%2Fbandcamp-wishlist-tidal/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-10-01T05:28:51.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5657452536","node_id":"PR_kwDOOiDYAc8AAAABGB_5qg","number":291,"state":"open","title":"build(deps): bump the all group with 4 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-10-01T05:28:51.000Z","updated_at":"2026-10-01T05:29:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all","update_count":4,"packages":[{"name":"pnpm/setup","old_version":"2.0.2","new_version":"3.0.0","repository_url":"https://github.com/pnpm/setup"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"zizmorcore/zizmor-action","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/zizmorcore/zizmor-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the all group with 4 updates: [pnpm/setup](https://github.com/pnpm/setup), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).\n\nUpdates `pnpm/setup` from 2.0.2 to 3.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pnpm/setup/releases\"\u003epnpm/setup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix!: include runid in cache key, restore freshest lockfile match by \u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat!: automatically detect Node.js version files by \u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add private registry authentication recipes by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/61\"\u003epnpm/setup#61\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid deprecated shell spawning for pnpm commands by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/52\"\u003epnpm/setup#52\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: require-lockfile no longer accepts a lockfile pnpm will not use by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/60\"\u003epnpm/setup#60\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/poulet42\"\u003e\u003ccode\u003e@​poulet42\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/43\"\u003epnpm/setup#43\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Neonsy\"\u003e\u003ccode\u003e@​Neonsy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/49\"\u003epnpm/setup#49\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.1.0...v3.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: restore cache before installing runtime by \u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: install multiple runtimes from devEngines.runtime by \u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: cache pnpm's lockfile verification results by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/30\"\u003epnpm/setup#30\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e by \u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input by \u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: update dependencies with pnpm/update instead of Dependabot by \u003ca href=\"https://github.com/zkochan\"\u003e\u003ccode\u003e@​zkochan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/41\"\u003epnpm/setup#41\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: update dependencies by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Stanzilla\"\u003e\u003ccode\u003e@​Stanzilla\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/39\"\u003epnpm/setup#39\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BlankParticle\"\u003e\u003ccode\u003e@​BlankParticle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/32\"\u003epnpm/setup#32\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/haines\"\u003e\u003ccode\u003e@​haines\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/27\"\u003epnpm/setup#27\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebdanielsson\"\u003e\u003ccode\u003e@​sebdanielsson\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/23\"\u003epnpm/setup#23\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/pnpm/setup/pull/42\"\u003epnpm/setup#42\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\"\u003ehttps://github.com/pnpm/setup/compare/v2.0.2...v2.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003e\u003ccode\u003efbda4c8\u003c/code\u003e\u003c/a\u003e docs(README): update version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c868a7d055a8423cab9de075713ce4ce9bf9205d\"\u003e\u003ccode\u003ec868a7d\u003c/code\u003e\u003c/a\u003e fix: require-lockfile no longer accepts a lockfile pnpm will not use (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/60\"\u003e#60\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/463911b67ec9290f1350907aa2b257be0aca1687\"\u003e\u003ccode\u003e463911b\u003c/code\u003e\u003c/a\u003e fix: avoid deprecated shell spawning for pnpm commands (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/52\"\u003e#52\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/659828629c47ab99e8bdf4cc9aec88a8aab310a6\"\u003e\u003ccode\u003e6598286\u003c/code\u003e\u003c/a\u003e docs: add private registry authentication recipes (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/61\"\u003e#61\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/c5b2e249903756c468007fa3f013203377937b5b\"\u003e\u003ccode\u003ec5b2e24\u003c/code\u003e\u003c/a\u003e feat!: automatically detect Node.js version files (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/f37addefd310ed0d00a4de48e30bb7e1c4414491\"\u003e\u003ccode\u003ef37adde\u003c/code\u003e\u003c/a\u003e fix!: include runid in cache key, restore freshest lockfile match (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/43\"\u003e#43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/703c52620218391530e48b9e8870d5c0082e1b9b\"\u003e\u003ccode\u003e703c526\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/e02cd34ce0366c68c5fccdd0f0fd4fa1f9d3459c\"\u003e\u003ccode\u003ee02cd34\u003c/code\u003e\u003c/a\u003e ci: update dependencies with pnpm/update instead of Dependabot (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/41\"\u003e#41\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/0080eca8ccdd50c579e4d2242cc958f8e8b3040e\"\u003e\u003ccode\u003e0080eca\u003c/code\u003e\u003c/a\u003e feat: add a \u003ccode\u003erequire-lockfile\u003c/code\u003e input (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/23\"\u003e#23\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pnpm/setup/commit/3327d57c1fba3d6ed3bef37285efc7a45c25f6cd\"\u003e\u003ccode\u003e3327d57\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eworking-directory\u003c/code\u003e, deprecating \u003ccode\u003epackage-json-file\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pnpm/setup/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pnpm/setup/compare/84cb39b217b10273981911c288cd62326dc7c6d2...fbda4c85fc2e1e08721cd8763afea8f48d60f024\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/zizmorcore/zizmor-action/releases\"\u003ezizmorcore/zizmor-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sponsors/woodruffw/\"\u003eSponsorship is appreciated!\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003ezizmor 1.30.1 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1301%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1301)\"\u003ezizmorcore/zizmor-action#1301\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.6.3\u003c/h2\u003e\n\u003cp\u003ezizmor 1.30.0 is now the default version.\u003c/p\u003e\n\u003cp\u003eRelease notes: \u003ca href=\"https://docs.zizmor.sh/release-notes/%5B#1300%5D(https://redirect.github.com/zizmorcore/zizmor-action/issues/1300)\"\u003ezizmorcore/zizmor-action#1300\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003e\u003ccode\u003ecc914d7\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/bae72b71bc270806f906e8e2a1f5985a26effaa2\"\u003e\u003ccode\u003ebae72b7\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/27604f9eef072d6456e69fc10ee36629710fa6f6\"\u003e\u003ccode\u003e27604f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/164\"\u003e#164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/c41d66537b2d733801baec1e31ffc22aa2051a8f\"\u003e\u003ccode\u003ec41d665\u003c/code\u003e\u003c/a\u003e README: bump pins (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/163\"\u003e#163\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/70fb788f84895a7701f5643d103d587e460b5c99\"\u003e\u003ccode\u003e70fb788\u003c/code\u003e\u003c/a\u003e Sync zizmor versions (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/162\"\u003e#162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/7999d8c8ac51dbd3bd44e6e35e7cd015b5dcdc82\"\u003e\u003ccode\u003e7999d8c\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/2ae1ce9c6b7248fdfc5a4f47f3527240521f79b9\"\u003e\u003ccode\u003e2ae1ce9\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/951a5eef1c3d7669c20934ceca759fdf8dbd153e\"\u003e\u003ccode\u003e951a5ee\u003c/code\u003e\u003c/a\u003e Skip prerelease versions in sync-zizmor-versions workflow (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/158\"\u003e#158\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/79f019101434ac77d41ed24f93c6bdc8676bd355\"\u003e\u003ccode\u003e79f0191\u003c/code\u003e\u003c/a\u003e chore(deps): bump github/codeql-action/upload-sarif (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/156\"\u003e#156\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zizmorcore/zizmor-action/commit/26a3ae6758a68e521bfe592f503410eb61b699bb\"\u003e\u003ccode\u003e26a3ae6\u003c/code\u003e\u003c/a\u003e sync-zizmor-versions: retry up to 5 times (\u003ca href=\"https://redirect.github.com/zizmorcore/zizmor-action/issues/155\"\u003e#155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/zizmorcore/zizmor-action/compare/3dc1ecc9bcb9e94e9b2c709687979e1298497054...cc914d7f3750a2d13d75c7f184a1060aa0e9d482\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/gahojin/rolldown-gas-plugin/pull/291","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gahojin%2Frolldown-gas-plugin/issues/291","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/291/packages"}},{"old_version":"3a7550f43ba5b58905a821ce3a0ed24c4858b3f4","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","update_type":null,"path":null,"pr_created_at":"2026-09-28T21:27:58.000Z","version_change":"3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 → 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","issue":{"uuid":"5621481920","node_id":"PR_kwDOToe92s8AAAABFlM-kA","number":809,"state":"open","title":"[CI] 의존성 업데이트 Bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T21:27:58.000Z","updated_at":"2026-10-01T02:32:36.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[CI] 의존성 업데이트 Bump","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"3a7550f43ba5b58905a821ce3a0ed24c4858b3f4","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 8ac9e5ce44cc7178e0e04229a91bdcc003166e57.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003e\u003ccode\u003e8ac9e5c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/143\"\u003e#143\u003c/a\u003e from renovate-bot/renovate/workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/3b06fbb744e4192b7d47b4f2584715a21ef88b92\"\u003e\u003ccode\u003e3b06fbb\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/3a7550f43ba5b58905a821ce3a0ed24c4858b3f4...8ac9e5ce44cc7178e0e04229a91bdcc003166e57\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/AquilaXk/easysubway-data/pull/809","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AquilaXk%2Feasysubway-data/issues/809","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/809/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-28T19:00:46.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5619716275","node_id":"PR_kwDOUtpkjs8AAAABFjx-JA","number":7,"state":"closed","title":"chore(actions)(deps): bump the actions-minor-patch group with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-28T19:11:05.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-28T19:00:46.000Z","updated_at":"2026-09-28T19:11:50.000Z","time_to_close":619,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/acmeist/hermes-agent/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/acmeist%2Fhermes-agent/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-28T17:14:07.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5618450313","node_id":"PR_kwDOSRjOYs8AAAABFiwytA","number":23,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T17:14:07.000Z","updated_at":"2026-09-28T17:21:42.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/highclaws-com/hermes-agent-fork/pull/23","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/highclaws-com%2Fhermes-agent-fork/issues/23","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/23/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-27T11:33:48.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5602284810","node_id":"PR_kwDOUuReW88AAAABFV-fYw","number":1,"state":"closed","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-29T18:27:11.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-27T11:33:48.000Z","updated_at":"2026-09-29T18:27:21.000Z","time_to_close":197603,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/selendang666/selendang666-jb/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/selendang666%2Fselendang666-jb/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-27T03:54:52.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5599552015","node_id":"PR_kwDOUtpkjs8AAAABFT_iKw","number":1,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-27T03:54:52.000Z","updated_at":"2026-09-27T03:59:38.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"azure/login","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/azure/login"},{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `azure/login` from 3.0.1 to 3.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/azure/login/releases\"\u003eazure/login's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd the ability to prevent the masking of clientId by \u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAutomate release tagging via deploy key + self-pin bump by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/638\"\u003eAzure/login#638\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document immutable release model and correct branch reference by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/640\"\u003eAzure/login#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: reduce scheduled test frequency and clarify workflow names by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/639\"\u003eAzure/login#639\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.2 to 3.15.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/643\"\u003eAzure/login#643\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump browserslist from 4.21.4 to 4.28.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/Azure/login/pull/637\"\u003eAzure/login#637\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd max-context-population input to override Azure PowerShell MaxCont… by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/642\"\u003eAzure/login#642\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/636\"\u003eAzure/login#636\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/the-coding-cuzzy\"\u003e\u003ccode\u003e@​the-coding-cuzzy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/Azure/login/pull/634\"\u003eAzure/login#634\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.2...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.2...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eAzure Login Action v3.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity \u0026amp; hardening\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRefactor PowerShell login to a static \u003ccode\u003eparam()\u003c/code\u003e-bound script\u003c/strong\u003e — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/607\"\u003eAzure/login#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePin third-party GitHub Actions to commit SHAs\u003c/strong\u003e — supply-chain hardening for the CI/release workflows by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/615\"\u003eAzure/login#615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdd admin-gated Release workflow\u003c/strong\u003e — reproducible, approval-gated release + rollback pipeline by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/610\"\u003eAzure/login#610\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTelemetry\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmit the real action ref in telemetry via \u003ccode\u003eGITHUB_ACTION_REF\u003c/code\u003e\u003c/strong\u003e — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/614\"\u003eAzure/login#614\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCap \u003ccode\u003e@actions/exec\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e below the ESM-only 3.x majors (keeps the CommonJS \u003ccode\u003encc\u003c/code\u003e build working) by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/628\"\u003eAzure/login#628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden Dependabot config for the CommonJS \u003ccode\u003encc\u003c/code\u003e build by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/622\"\u003eAzure/login#622\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group across 1 directory with 7 updates by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/621\"\u003eAzure/login#621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003euuid\u003c/code\u003e and \u003ccode\u003e@actions/core\u003c/code\u003e by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/589\"\u003eAzure/login#589\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003ebrace-expansion\u003c/code\u003e from 1.1.12 to 1.1.18 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/616\"\u003eAzure/login#616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003epicomatch\u003c/code\u003e from 2.3.1 to 2.3.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/582\"\u003eAzure/login#582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMaintenance \u0026amp; docs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCleanup \u003ccode\u003epackage.json\u003c/code\u003e and Dependabot config by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/608\"\u003eAzure/login#608\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWorkflows/CI hygiene by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/609\"\u003eAzure/login#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocs uplift by \u003ca href=\"https://github.com/MaddyMicrosoft\"\u003e\u003ccode\u003e@​MaddyMicrosoft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/620\"\u003eAzure/login#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd version support policy and security update guidance by \u003ca href=\"https://github.com/Alex-AZPS\"\u003e\u003ccode\u003e@​Alex-AZPS\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Azure/login/pull/604\"\u003eAzure/login#604\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Azure/login/compare/v3.0.1...v3.1.0\"\u003ehttps://github.com/Azure/login/compare/v3.0.1...v3.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003e\u003ccode\u003ea641126\u003c/code\u003e\u003c/a\u003e prepare release v3.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/3c5b5ce5ad792113eb9ae7c228a7f10434d2abd8\"\u003e\u003ccode\u003e3c5b5ce\u003c/code\u003e\u003c/a\u003e Add max-context-population input to override Azure PowerShell MaxCont… (\u003ca href=\"https://redirect.github.com/azure/login/issues/642\"\u003e#642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/fcd03407c33dcc2d7daa4be58fbc6cc97f863e47\"\u003e\u003ccode\u003efcd0340\u003c/code\u003e\u003c/a\u003e Bump browserslist from 4.21.4 to 4.28.8 (\u003ca href=\"https://redirect.github.com/azure/login/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5a8018ff19213e23577f851630e72e2d967da18e\"\u003e\u003ccode\u003e5a8018f\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.2 to 3.15.2 (\u003ca href=\"https://redirect.github.com/azure/login/issues/643\"\u003e#643\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/a23dddf88dfa76057d85fe74e0fd43cf63e47d93\"\u003e\u003ccode\u003ea23dddf\u003c/code\u003e\u003c/a\u003e ci: reduce scheduled test frequency and clarify workflow names (\u003ca href=\"https://redirect.github.com/azure/login/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/4c016e02d235fa9be92c94e670c7a9bc9a95ce6e\"\u003e\u003ccode\u003e4c016e0\u003c/code\u003e\u003c/a\u003e docs: document immutable release model and correct branch reference (\u003ca href=\"https://redirect.github.com/azure/login/issues/640\"\u003e#640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/63f3c387ff4b3f913e65326383bb8cc883a8562a\"\u003e\u003ccode\u003e63f3c38\u003c/code\u003e\u003c/a\u003e Automate release tagging via deploy key + self-pin bump (\u003ca href=\"https://redirect.github.com/azure/login/issues/638\"\u003e#638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/92a0b67e043fe0ecbf078b452645f1ef87319ad3\"\u003e\u003ccode\u003e92a0b67\u003c/code\u003e\u003c/a\u003e Add the ability to prevent the masking of clientId (\u003ca href=\"https://redirect.github.com/azure/login/issues/634\"\u003e#634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/5cb857d5d1b63c00fa4b689bbf6c742ef3d6e610\"\u003e\u003ccode\u003e5cb857d\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/azure/login/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Azure/login/commit/d90bae5347f733e8026acdee0e5e0f3b5ae6fca6\"\u003e\u003ccode\u003ed90bae5\u003c/code\u003e\u003c/a\u003e Cap \u003ccode\u003e@​actions/exec\u003c/code\u003e and \u003ccode\u003e@​actions/core\u003c/code\u003e below the ESM-only 3.x majors (\u003ca href=\"https://redirect.github.com/azure/login/issues/628\"\u003e#628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/azure/login/compare/f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca...a641126d1b8aa4d1fa005f4f92df94a3a4c4c906\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/acmeist/hermes-agent/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/acmeist%2Fhermes-agent/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-26T02:16:57.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5590631270","node_id":"PR_kwDOKtY1DM8AAAABFNPJNA","number":349,"state":"closed","title":"ci: bump the github-actions group across 1 directory with 6 updates","user":"dependabot[bot]","labels":["dependencies",":zap: ci/cd","triage","released"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-29T06:15:16.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-26T02:16:57.000Z","updated_at":"2026-10-03T14:09:41.000Z","time_to_close":273499,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci: bump","group_name":"github-actions","update_count":6,"packages":[{"name":"github/codeql-action/init","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/autobuild","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/upload-sarif","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n\n\nUpdates `github/codeql-action/init` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/autobuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/autobuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.2 - 24 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1\"\u003e2.27.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4160\"\u003e#4160\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/janbiasi/rollup-plugin-sbom/pull/349","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/janbiasi%2Frollup-plugin-sbom/issues/349","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/349/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":"the github-actions group across 1 directory","pr_created_at":"2026-09-24T18:46:28.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5572980577","node_id":"PR_kwDORK5qGc8AAAABE_RcvA","number":3231,"state":"closed","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0 in the github-actions group across 1 directory","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-10-02T00:46:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-24T18:46:28.000Z","updated_at":"2026-10-02T00:46:18.000Z","time_to_close":626380,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":"the github-actions group across 1 directory","ecosystem":"actions"},"body":"Bumps the github-actions group with 1 update in the / directory: [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/jerry200176-png/AllTrue_System/pull/3231","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jerry200176-png%2FAllTrue_System/issues/3231","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3231/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-24T14:43:43.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5570080421","node_id":"PR_kwDOUodimc8AAAABE889RQ","number":2,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:43:43.000Z","updated_at":"2026-09-24T14:47:16.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/cryozenai/cryozen-agent/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/cryozenai%2Fcryozen-agent/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-22T17:47:39.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5543146968","node_id":"PR_kwDOUl8rkc8AAAABEnxZng","number":1,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 4 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T17:47:39.000Z","updated_at":"2026-09-22T17:47:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":4,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 4 updates: [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action), [docker/build-push-action](https://github.com/docker/build-push-action), [docker/login-action](https://github.com/docker/login-action) and [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/igniteenow/robo-engineer/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/igniteenow%2Frobo-engineer/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-22T05:44:28.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5535742164","node_id":"PR_kwDOSaQaxc8AAAABEhzCyA","number":1713,"state":"open","title":"chore(ci): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.3.8 to 2.6.0","user":"dependabot[bot]","labels":["size/XS"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T05:44:28.000Z","updated_at":"2026-09-22T05:44:38.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(ci)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.3.8 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.3.8\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Mininglamp-OSS/octo-web/pull/1713","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Mininglamp-OSS%2Focto-web/issues/1713","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1713/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T22:35:47.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5533203504","node_id":"PR_kwDORJ_K788AAAABEfzWdQ","number":8,"state":"open","title":"chore(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T22:35:47.000Z","updated_at":"2026-09-21T22:35:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.5.1 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.5.1\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Tuteliq/flutter/pull/8","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Tuteliq%2Fflutter/issues/8","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/8/packages"}},{"old_version":"3adb4b14a2b0623876d18d863a498b785fb3752d","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","update_type":null,"path":null,"pr_created_at":"2026-09-21T22:17:54.000Z","version_change":"3adb4b14a2b0623876d18d863a498b785fb3752d → 8ac9e5ce44cc7178e0e04229a91bdcc003166e57","issue":{"uuid":"5533064564","node_id":"PR_kwDOT6Rtr88AAAABEfsL4Q","number":7,"state":"open","title":"Bump the github-actions group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T22:17:54.000Z","updated_at":"2026-09-21T22:18:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"github-actions","update_count":10,"packages":[{"name":"actions/checkout","old_version":"4","new_version":"7","repository_url":"https://github.com/actions/checkout"},{"name":"docker/login-action","old_version":"3","new_version":"4","repository_url":"https://github.com/docker/login-action"},{"name":"docker/setup-buildx-action","old_version":"3","new_version":"4","repository_url":"https://github.com/docker/setup-buildx-action"},{"name":"docker/build-push-action","old_version":"6","new_version":"7","repository_url":"https://github.com/docker/build-push-action"},{"name":"actions/dependency-review-action","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/actions/dependency-review-action"},{"name":"actions/upload-artifact","old_version":"4","new_version":"7","repository_url":"https://github.com/actions/upload-artifact"},{"name":"actions/download-artifact","old_version":"4","new_version":"8","repository_url":"https://github.com/actions/download-artifact"},{"name":"oven-sh/setup-bun","old_version":"1","new_version":"2","repository_url":"https://github.com/oven-sh/setup-bun"},{"name":"actions/cache","old_version":"4","new_version":"6","repository_url":"https://github.com/actions/cache"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"3adb4b14a2b0623876d18d863a498b785fb3752d","new_version":"8ac9e5ce44cc7178e0e04229a91bdcc003166e57","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |\n| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |\n| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `6` | `7` |\n| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.9.0` | `5.0.0` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` |\n| [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `8` |\n| [oven-sh/setup-bun](https://github.com/oven-sh/setup-bun) | `1` | `2` |\n| [actions/cache](https://github.com/actions/cache) | `4` | `6` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `3adb4b14a2b0623876d18d863a498b785fb3752d` | `8ac9e5ce44cc7178e0e04229a91bdcc003166e57` |\n\n\nUpdates `actions/checkout` from 4 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/checkout/releases\"\u003eactions/checkout's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eblock checking out fork pr for pull_request_target and workflow_run by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and \u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003egetting ready for checkout v7 release by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2464\"\u003eactions/checkout#2464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate error wording by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2467\"\u003eactions/checkout#2467\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.3...v7.0.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[BREAKING]\u003c/strong\u003e backport \u003ccode\u003eallow-unsafe-pr-checkout\u003c/code\u003e to v6 by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2500\"\u003eactions/checkout#2500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebackport fixes to releases-v6 by \u003ca href=\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2527\"\u003eactions/checkout#2527\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/\"\u003ehttps://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/\u003c/a\u003e for more details about this breaking change\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.3...v6.1.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate changelog by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2357\"\u003eactions/checkout#2357\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate changelog for v6.0.3 by \u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2446\"\u003eactions/checkout#2446\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6...v6.0.3\"\u003ehttps://github.com/actions/checkout/compare/v6...v6.0.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by \u003ca href=\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2355\"\u003eactions/checkout#2355\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/checkout/compare/v6.0.1...v6.0.2\"\u003ehttps://github.com/actions/checkout/compare/v6.0.1...v6.0.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all references from v5 and v4 to v6 by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2314\"\u003eactions/checkout#2314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify v6 README by \u003ca href=\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/checkout/pull/2328\"\u003eactions/checkout#2328\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003e\u003ccode\u003e3d3c42e\u003c/code\u003e\u003c/a\u003e prep v7.0.1 release (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2531\"\u003e#2531\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07\"\u003e\u003ccode\u003e2880268\u003c/code\u003e\u003c/a\u003e escape values passed to --unset (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2530\"\u003e#2530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1\"\u003e\u003ccode\u003e12cd223\u003c/code\u003e\u003c/a\u003e trim only ascii whitespace for branch (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2521\"\u003e#2521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541\"\u003e\u003ccode\u003e62661c4\u003c/code\u003e\u003c/a\u003e skip running unsafe pr check if input is default (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2518\"\u003e#2518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f\"\u003e\u003ccode\u003ee8d4307\u003c/code\u003e\u003c/a\u003e Bump the minor-actions-dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2499\"\u003e#2499\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87\"\u003e\u003ccode\u003e631c942\u003c/code\u003e\u003c/a\u003e eslint 9 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2474\"\u003e#2474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e\"\u003e\u003ccode\u003e4f1f4ae\u003c/code\u003e\u003c/a\u003e Bump actions/upload-artifact from 4 to 7 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2476\"\u003e#2476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92\"\u003e\u003ccode\u003eba09753\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6 to 7 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2488\"\u003e#2488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22\"\u003e\u003ccode\u003eb9e0990\u003c/code\u003e\u003c/a\u003e Bump docker/login-action from 3.3.0 to 4.2.0 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2479\"\u003e#2479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2\"\u003e\u003ccode\u003ee8cb398\u003c/code\u003e\u003c/a\u003e Bump docker/build-push-action from 6.5.0 to 7.2.0 (\u003ca href=\"https://redirect.github.com/actions/checkout/issues/2478\"\u003e#2478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/checkout/compare/v4...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 3 to 4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/929\"\u003edocker/login-action#929\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/927\"\u003edocker/login-action#927\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/919\"\u003edocker/login-action#919\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e from 3.890.0 to 3.1000.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/909\"\u003edocker/login-action#909\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/920\"\u003edocker/login-action#920\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e from 3.890.0 to 3.1000.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/909\"\u003edocker/login-action#909\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/920\"\u003edocker/login-action#920\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.63.0 to 0.77.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/910\"\u003edocker/login-action#910\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/928\"\u003edocker/login-action#928\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​isaacs/brace-expansion\u003c/code\u003e from 5.0.0 to 5.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/921\"\u003edocker/login-action#921\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/901\"\u003edocker/login-action#901\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.7.0...v4.0.0\"\u003ehttps://github.com/docker/login-action/compare/v3.7.0...v4.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003escope\u003c/code\u003e input to set scopes for the authentication token by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/912\"\u003edocker/login-action#912\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for AWS European Sovereign Cloud ECR by \u003ca href=\"https://github.com/dphi\"\u003e\u003ccode\u003e@​dphi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/914\"\u003edocker/login-action#914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure passwords are redacted with \u003ccode\u003eregistry-auth\u003c/code\u003e input by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/911\"\u003edocker/login-action#911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/915\"\u003edocker/login-action#915\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.6.0...v3.7.0\"\u003ehttps://github.com/docker/login-action/compare/v3.6.0...v3.7.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eregistry-auth\u003c/code\u003e input for raw authentication to registries by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/887\"\u003edocker/login-action#887\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.890.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/882\"\u003edocker/login-action#882\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/890\"\u003edocker/login-action#890\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.890.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/882\"\u003edocker/login-action#882\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/890\"\u003edocker/login-action#890\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.63.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/883\"\u003edocker/login-action#883\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/880\"\u003edocker/login-action#880\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/879\"\u003edocker/login-action#879\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.3 to 0.2.4 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/881\"\u003edocker/login-action#881\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.5.0...v3.6.0\"\u003ehttps://github.com/docker/login-action/compare/v3.5.0...v3.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport dual-stack endpoints for AWS ECR by \u003ca href=\"https://github.com/Spacefish\"\u003e\u003ccode\u003e@​Spacefish\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/874\"\u003edocker/login-action#874\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/876\"\u003edocker/login-action#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.859.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/860\"\u003edocker/login-action#860\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/878\"\u003edocker/login-action#878\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.859.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/860\"\u003edocker/login-action#860\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/878\"\u003edocker/login-action#878\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.57.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/870\"\u003edocker/login-action#870\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/875\"\u003edocker/login-action#875\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.4.0...v3.5.0\"\u003ehttps://github.com/docker/login-action/compare/v3.4.0...v3.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.10.1 to 1.11.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/791\"\u003edocker/login-action#791\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e to 3.766.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/789\"\u003edocker/login-action#789\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/856\"\u003edocker/login-action#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.758.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/789\"\u003edocker/login-action#789\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/856\"\u003edocker/login-action#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.35.0 to 0.57.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/801\"\u003edocker/login-action#801\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/806\"\u003edocker/login-action#806\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/858\"\u003edocker/login-action#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump cross-spawn from 7.0.3 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/814\"\u003edocker/login-action#814\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump https-proxy-agent from 7.0.5 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/823\"\u003edocker/login-action#823\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump path-to-regexp from 6.2.2 to 6.3.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/777\"\u003edocker/login-action#777\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v3.3.0...v3.4.0\"\u003ehttps://github.com/docker/login-action/compare/v3.3.0...v3.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/v3...v4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/setup-buildx-action` from 3 to 4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/483\"\u003edocker/setup-buildx-action#483\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated inputs/outputs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/464\"\u003edocker/setup-buildx-action#464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/481\"\u003edocker/setup-buildx-action#481\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/475\"\u003edocker/setup-buildx-action#475\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.63.0 to 0.79.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/482\"\u003edocker/setup-buildx-action#482\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/485\"\u003edocker/setup-buildx-action#485\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/452\"\u003edocker/setup-buildx-action#452\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/472\"\u003edocker/setup-buildx-action#472\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump minimatch from 3.1.2 to 3.1.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/480\"\u003edocker/setup-buildx-action#480\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.12.0...v4.0.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.12.0...v4.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.12.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003einstall\u003c/code\u003e input by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/455\"\u003edocker/setup-buildx-action#455\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.63.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/434\"\u003edocker/setup-buildx-action#434\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/436\"\u003edocker/setup-buildx-action#436\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/432\"\u003edocker/setup-buildx-action#432\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/435\"\u003edocker/setup-buildx-action#435\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.11.1...v3.12.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.11.1...v3.12.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.11.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003ekeep-state\u003c/code\u003e not being respected by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/429\"\u003edocker/setup-buildx-action#429\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.11.0...v3.11.1\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.11.0...v3.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eKeep BuildKit state support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/427\"\u003edocker/setup-buildx-action#427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove aliases created when installing by default by \u003ca href=\"https://github.com/hashhar\"\u003e\u003ccode\u003e@​hashhar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/139\"\u003edocker/setup-buildx-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.56.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/422\"\u003edocker/setup-buildx-action#422\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/425\"\u003edocker/setup-buildx-action#425\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.10.0...v3.11.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.10.0...v3.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.54.0 to 0.56.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/408\"\u003edocker/setup-buildx-action#408\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.9.0...v3.10.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.9.0...v3.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.48.0 to 0.54.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/402\"\u003edocker/setup-buildx-action#402\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/404\"\u003edocker/setup-buildx-action#404\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.8.0...v3.9.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.8.0...v3.9.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMake cloud prefix optional to download buildx if driver is cloud by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/390\"\u003edocker/setup-buildx-action#390\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.10.1 to 1.11.1 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/370\"\u003edocker/setup-buildx-action#370\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.39.0 to 0.48.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/389\"\u003edocker/setup-buildx-action#389\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump cross-spawn from 7.0.3 to 7.0.6 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/382\"\u003edocker/setup-buildx-action#382\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3.7.1...v3.8.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v3.7.1...v3.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003e\u003ccode\u003ef87e599\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/624\"\u003e#624\u003c/a\u003e from crazy-max/skip-pull-with-endpoint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022\"\u003e\u003ccode\u003ee700274\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07\"\u003e\u003ccode\u003e3061c91\u003c/code\u003e\u003c/a\u003e skip BuildKit image pre-pulls for explicit endpoints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003\"\u003e\u003ccode\u003e594f3bf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/609\"\u003e#609\u003c/a\u003e from crazy-max/pull-buildkit-image-before-create\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25\"\u003e\u003ccode\u003ebd6e702\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032\"\u003e\u003ccode\u003e6268c9d\u003c/code\u003e\u003c/a\u003e pull BuildKit image before builder creation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11\"\u003e\u003ccode\u003ee823525\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/621\"\u003e#621\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d\"\u003e\u003ccode\u003e533ed8e\u003c/code\u003e\u003c/a\u003e build(deps): bump the codeql-actions group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99\"\u003e\u003ccode\u003ebedaf13\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/620\"\u003e#620\u003c/a\u003e from crazy-max/shared-error-helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2\"\u003e\u003ccode\u003ed5079fb\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v3...v4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 6 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNode 24 as default runtime (requires \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003eActions Runner v2.327.1\u003c/a\u003e or later) by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1470\"\u003edocker/build-push-action#1470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated \u003ccode\u003eDOCKER_BUILD_NO_SUMMARY\u003c/code\u003e and \u003ccode\u003eDOCKER_BUILD_EXPORT_RETENTION_DAYS\u003c/code\u003e envs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1473\"\u003edocker/build-push-action#1473\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove legacy export-build tool support for build summary by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1474\"\u003edocker/build-push-action#1474\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch to ESM and update config/test wiring by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1466\"\u003edocker/build-push-action#1466\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 1.11.1 to 3.0.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1454\"\u003edocker/build-push-action#1454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.62.1 to 0.79.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1453\"\u003edocker/build-push-action#1453\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1472\"\u003edocker/build-push-action#1472\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1479\"\u003edocker/build-push-action#1479\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump minimatch from 3.1.2 to 3.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1463\"\u003edocker/build-push-action#1463\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.2...v7.0.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.2...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve port in \u003ccode\u003eGIT_AUTH_TOKEN\u003c/code\u003e host by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1458\"\u003edocker/build-push-action#1458\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.1...v6.19.2\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.1...v6.19.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDerive \u003ccode\u003eGIT_AUTH_TOKEN\u003c/code\u003e host from GitHub server URL by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1456\"\u003edocker/build-push-action#1456\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.19.0...v6.19.1\"\u003ehttps://github.com/docker/build-push-action/compare/v6.19.0...v6.19.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.19.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eScope default git auth token to \u003ccode\u003egithub.com\u003c/code\u003e by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1451\"\u003edocker/build-push-action#1451\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.11 to 1.1.12 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1396\"\u003edocker/build-push-action#1396\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump form-data from 2.5.1 to 2.5.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1391\"\u003edocker/build-push-action#1391\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 3.14.1 to 3.14.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1429\"\u003edocker/build-push-action#1429\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.21 to 4.17.23 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1446\"\u003edocker/build-push-action#1446\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.3 to 0.2.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1398\"\u003edocker/build-push-action#1398\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 5.28.4 to 5.29.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1397\"\u003edocker/build-push-action#1397\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.18.0...v6.19.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.18.0...v6.19.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.18.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.61.0 to 0.62.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1381\"\u003edocker/build-push-action#1381\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\n\u003ca href=\"https://docs.docker.com/build/ci/github-actions/build-summary/\"\u003eBuild summary\u003c/a\u003e is now supported with \u003ca href=\"https://docs.docker.com/build-cloud/\"\u003eDocker Build Cloud\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.17.0...v6.18.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.17.0...v6.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.17.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.59.0 to 0.61.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1364\"\u003edocker/build-push-action#1364\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nBuild record is now exported using the \u003ca href=\"https://docs.docker.com/reference/cli/docker/buildx/history/export/\"\u003e\u003ccode\u003ebuildx history export\u003c/code\u003e\u003c/a\u003e command instead of the legacy export-build tool.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v6.16.0...v6.17.0\"\u003ehttps://github.com/docker/build-push-action/compare/v6.16.0...v6.17.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.16.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle no default attestations env var by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1343\"\u003edocker/build-push-action#1343\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/v6...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/dependency-review-action` from 4.9.0 to 5.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/dependency-review-action/releases\"\u003eactions/dependency-review-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.0\u003c/h2\u003e\n\u003cp\u003eThis is a new major version of the Dependency Review Action which updates the runtime to node24. This requires a minimum Actions Runner version \u003ca href=\"https://github.com/actions/runner/releases/tag/v2.327.1\"\u003ev2.327.1\u003c/a\u003e to run.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd .github/copilot-instructions.md for Copilot coding agent by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1067\"\u003eactions/dependency-review-action#1067\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js runtime from 20 to 24 by \u003ca href=\"https://github.com/scottschreckengaust\"\u003e\u003ccode\u003e@​scottschreckengaust\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1084\"\u003eactions/dependency-review-action#1084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump spdx-license-ids from 3.0.20 to 3.0.23 by \u003ca href=\"https://github.com/mongolyy\"\u003e\u003ccode\u003e@​mongolyy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1091\"\u003eactions/dependency-review-action#1091\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: bump actions/checkout from v4 to v6 in workflow examples by \u003ca href=\"https://github.com/Marukome0743\"\u003e\u003ccode\u003e@​Marukome0743\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1077\"\u003eactions/dependency-review-action#1077\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: patched version display for advisories with non-strict semver ranges (e.g. Maven beta versions) by \u003ca href=\"https://github.com/tspascoal\"\u003e\u003ccode\u003e@​tspascoal\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1076\"\u003eactions/dependency-review-action#1076\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve security findings by \u003ca href=\"https://github.com/AshelyTC\"\u003e\u003ccode\u003e@​AshelyTC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1094\"\u003eactions/dependency-review-action#1094\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ev5.0.0 release branch by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1098\"\u003eactions/dependency-review-action#1098\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scottschreckengaust\"\u003e\u003ccode\u003e@​scottschreckengaust\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1084\"\u003eactions/dependency-review-action#1084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongolyy\"\u003e\u003ccode\u003e@​mongolyy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1091\"\u003eactions/dependency-review-action#1091\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Marukome0743\"\u003e\u003ccode\u003e@​Marukome0743\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1077\"\u003eactions/dependency-review-action#1077\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0\"\u003ehttps://github.com/actions/dependency-review-action/compare/v4.9.0...v5.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a1d282b36b6f3519aa1f3fc636f609c47dddb294\"\u003e\u003ccode\u003ea1d282b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1098\"\u003e#1098\u003c/a\u003e from actions/ahpook/v5-release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/eb6c199c5a85c7387f1f0b02b3ba5c6364740695\"\u003e\u003ccode\u003eeb6c199\u003c/code\u003e\u003c/a\u003e update examples to show \u003ca href=\"https://github.com/v5\"\u003e\u003ccode\u003e@​v5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/3943c2c5beaaaf1806eb3758273c203dabcbf89c\"\u003e\u003ccode\u003e3943c2c\u003c/code\u003e\u003c/a\u003e v5.0.0 release branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/454943c880b147adbfe7de0cdd3ece1c00882033\"\u003e\u003ccode\u003e454943c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1094\"\u003e#1094\u003c/a\u003e from actions/ashelytc/security-findings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/6d92a1228e9e9db334f02c09f84fe9217d2b4463\"\u003e\u003ccode\u003e6d92a12\u003c/code\u003e\u003c/a\u003e revert \u003ccode\u003e@​typescript-eslint/parser\u003c/code\u003e update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a8e5a7e93695b41abf6d1083cd220bee39a720f0\"\u003e\u003ccode\u003ea8e5a7e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1076\"\u003e#1076\u003c/a\u003e from tspascoal/fix-version-matching-for-non-string-s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/b6b7079031ef4ed61656c221988f1f3bcbf35101\"\u003e\u003ccode\u003eb6b7079\u003c/code\u003e\u003c/a\u003e update \u003ccode\u003e@​typescript-eslint/parser\u003c/code\u003e to 8.40.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/821a21dd691f162c4c5c2e9754a344accde9a208\"\u003e\u003ccode\u003e821a21d\u003c/code\u003e\u003c/a\u003e update more dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/05aaaae45cf4c420de012addf2a72e3435ddaa63\"\u003e\u003ccode\u003e05aaaae\u003c/code\u003e\u003c/a\u003e run npm audit fix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/55d3e754501fc13c84b95637ce51f135012d41ea\"\u003e\u003ccode\u003e55d3e75\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1077\"\u003e#1077\u003c/a\u003e from Marukome0743/docs/checkout\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/dependency-review-action/compare/2031cfc080254a8a887f58cffee85186f0e49e48...a1d282b36b6f3519aa1f3fc636f609c47dddb294\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 4 to 7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003ev7 What's new\u003c/h2\u003e\n\u003ch3\u003eDirect Uploads\u003c/h3\u003e\n\u003cp\u003eAdds support for uploading single files directly (unzipped). Callers can set the new \u003ccode\u003earchive\u003c/code\u003e parameter to \u003ccode\u003efalse\u003c/code\u003e to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The \u003ccode\u003ename\u003c/code\u003e parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.\u003c/p\u003e\n\u003ch3\u003eESM\u003c/h3\u003e\n\u003cp\u003eTo support new versions of the \u003ccode\u003e@actions/*\u003c/code\u003e packages, we've upgraded the package to ESM.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd proxy integration test by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade the module to ESM and bump dependencies by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/762\"\u003eactions/upload-artifact#762\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport direct file uploads by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/764\"\u003eactions/upload-artifact#764\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- made their first contribution in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/upload-artifact/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003ev6 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/upload-artifact@v6 now runs on Node.js 24 (\u003ccode\u003eruns.using: node24\u003c/code\u003e) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eNode.js 24\u003c/h3\u003e\n\u003cp\u003eThis release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpload Artifact Node 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/719\"\u003eactions/upload-artifact#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update \u003ccode\u003e@​actions/artifact\u003c/code\u003e for Node.js 24 punycode deprecation by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/744\"\u003eactions/upload-artifact#744\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare release v6.0.0 for Node.js 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/745\"\u003eactions/upload-artifact#745\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0\"\u003ehttps://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBREAKING CHANGE:\u003c/strong\u003e this update supports Node \u003ccode\u003ev24.x\u003c/code\u003e. This is not a breaking change per-se but we're treating it as such.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate README.md by \u003ca href=\"https://github.com/GhadimiR\"\u003e\u003ccode\u003e@​GhadimiR\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/681\"\u003eactions/upload-artifact#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca href=\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/712\"\u003eactions/upload-artifact#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: spell out the first use of GHES by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/727\"\u003eactions/upload-artifact#727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate GHES guidance to include reference to Node 20 version by \u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/725\"\u003eactions/upload-artifact#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/artifact\u003c/code\u003e to \u003ccode\u003ev4.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ePrepare \u003ccode\u003ev5.0.0\u003c/code\u003e by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/734\"\u003eactions/upload-artifact#734\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f\"\u003e\u003ccode\u003ebbbca2d\u003c/code\u003e\u003c/a\u003e Support direct file uploads (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/764\"\u003e#764\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/589182c5a4cec8920b8c1bce3e2fab1c97a02296\"\u003e\u003ccode\u003e589182c\u003c/code\u003e\u003c/a\u003e Upgrade the module to ESM and bump dependencies (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/762\"\u003e#762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/47309c993abb98030a35d55ef7ff34b7fa1074b5\"\u003e\u003ccode\u003e47309c9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/754\"\u003e#754\u003c/a\u003e from actions/Link-/add-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/02a8460834e70dab0ce194c64360c59dc1475ef0\"\u003e\u003ccode\u003e02a8460\u003c/code\u003e\u003c/a\u003e Add proxy integration test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/b7c566a772e6b6bfb58ed0dc250532a479d7789f\"\u003e\u003ccode\u003eb7c566a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/745\"\u003e#745\u003c/a\u003e from actions/upload-artifact-v6-release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e516bc8500aaf3d07d591fcd4ae6ab5f9c391d5b\"\u003e\u003ccode\u003ee516bc8\u003c/code\u003e\u003c/a\u003e docs: correct description of Node.js 24 support in README\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/upload-artifact/compare/v4...v7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/download-artifact` from 4 to 8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/download-artifact/releases\"\u003eactions/download-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.0.0\u003c/h2\u003e\n\u003ch2\u003ev8 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nHash mismatches will now error by default. Users can override this behavior with a setting change (see below).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eDirect downloads\u003c/h3\u003e\n\u003cp\u003eTo support direct uploads in \u003ccode\u003eactions/upload-artifact\u003c/code\u003e, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the \u003ccode\u003eContent-Type\u003c/code\u003e header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new \u003ccode\u003eskip-decompress\u003c/code\u003e parameter to \u003ccode\u003etrue\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eEnforced checks (breaking)\u003c/h3\u003e\n\u003cp\u003eA previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the \u003ccode\u003edigest-mismatch\u003c/code\u003e parameter. To be secure by default, we are now defaulting the behavior to \u003ccode\u003eerror\u003c/code\u003e which will fail the workflow run.\u003c/p\u003e\n\u003ch3\u003eESM\u003c/h3\u003e\n\u003cp\u003eTo support new versions of the @actions/* packages, we've upgraded the package to ESM.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDon't attempt to un-zip non-zipped downloads by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/460\"\u003eactions/download-artifact#460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a setting to specify what to do on hash mismatch and default it to \u003ccode\u003eerror\u003c/code\u003e by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/461\"\u003eactions/download-artifact#461\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/download-artifact/compare/v7...v8.0.0\"\u003ehttps://github.com/actions/download-artifact/compare/v7...v8.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003ev7 - What's new\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nactions/download-artifact@v7 now runs on Node.js 24 (\u003ccode\u003eruns.using: node24\u003c/code\u003e) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eNode.js 24\u003c/h3\u003e\n\u003cp\u003eThis release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate GHES guidance to include reference to Node 20 version by \u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/440\"\u003eactions/download-artifact#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDownload Artifact Node24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/415\"\u003eactions/download-artifact#415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update \u003ccode\u003e@​actions/artifact\u003c/code\u003e to fix Node.js 24 punycode deprecation by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/451\"\u003eactions/download-artifact#451\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare release v7.0.0 for Node.js 24 support by \u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/452\"\u003eactions/download-artifact#452\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/patrikpolyak\"\u003e\u003ccode\u003e@​patrikpolyak\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/440\"\u003eactions/download-artifact#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/download-artifact/pull/415\"\u003eactions/download-artifact#415\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0\"\u003ehttps://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c\"\u003e\u003ccode\u003e3e5f45b\u003c/code\u003e\u003c/a\u003e Add regression tests for CJK characters (\u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/471\"\u003e#471\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/e6d03f67377d4412c7aa56a8e2e4988e6ec479dd\"\u003e\u003ccode\u003ee6d03f6\u003c/code\u003e\u003c/a\u003e Add a regression test for artifact name + content-type mismatches (\u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/472\"\u003e#472\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3\"\u003e\u003ccode\u003e70fc10c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/461\"\u003e#461\u003c/a\u003e from actions/danwkennedy/digest-mismatch-behavior\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/f258da9a506b755b84a09a531814700b86ccfc62\"\u003e\u003ccode\u003ef258da9\u003c/code\u003e\u003c/a\u003e Add change docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/ccc058e5fbb0bb2352213eaec3491e117cbc4a5c\"\u003e\u003ccode\u003eccc058e\u003c/code\u003e\u003c/a\u003e Fix linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/bd7976ba57ecea96e6f3df575eb922d11a12a9fd\"\u003e\u003ccode\u003ebd7976b\u003c/code\u003e\u003c/a\u003e Add a setting to specify what to do on hash mismatch and default it to \u003ccode\u003eerror\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/ac21fcf45e0aaee541c0f7030558bdad38d77d6c\"\u003e\u003ccode\u003eac21fcf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/download-artifact/issues/460\"\u003e#460\u003c/a\u003e from actions/danwkennedy/download-no-unzip\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/15999bff51058bc7c19b50ebbba518eaef7c26c0\"\u003e\u003ccode\u003e15999bf\u003c/code\u003e\u003c/a\u003e Add note about package bumps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/974686ed5098c7f9c9289ec946b9058e496a2561\"\u003e\u003ccode\u003e974686e\u003c/code\u003e\u003c/a\u003e Bump the version to \u003ccode\u003ev8\u003c/code\u003e and add release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/download-artifact/commit/fbe48b1d2756394be4cd4358ed3bc1343b330e75\"\u003e\u003ccode\u003efbe48b1\u003c/code\u003e\u003c/a\u003e Update test names to make it clearer what they do\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/download-artifact/compare/v4...v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `oven-sh/setup-bun` from 1 to 2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oven-sh/setup-bun/releases\"\u003eoven-sh/setup-bun's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eoven-sh/setup-bun\u003c/code\u003e is the github action for setting up Bun.\u003c/p\u003e\n\u003cp\u003eThis release introduces support for the \u003ccode\u003ebun-version-file\u003c/code\u003e option, fixes \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/79\"\u003eoven-sh/setup-bun#79\u003c/a\u003e, and adds bun paths \u0026amp; urls to the output (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/81\"\u003eoven-sh/setup-bun#81\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor more information, see \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/pull/76\"\u003eoven-sh/setup-bun#76\u003c/a\u003e by \u003ca href=\"https://github.com/adeherysh\"\u003e\u003ccode\u003e@​adeherysh\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/pull/80\"\u003eoven-sh/setup-bun#80\u003c/a\u003e by \u003ca href=\"https://github.com/xHyroM\"\u003e\u003ccode\u003e@​xHyroM\u003c/code\u003e\u003c/a\u003e :tada:\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/oven-sh/setup-bun/compare/v1...v2\"\u003ehttps://github.com/oven-sh/setup-bun/compare/v1...v2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eoven-sh/setup-bun\u003c/code\u003e is the github action for setting up Bun.\u003c/p\u003e\n\u003cp\u003eThis release introduces support for the \u003ccode\u003ebun-download-url\u003c/code\u003e input, which lets you override the URL used to download the .zip file for Bun.\u003c/p\u003e\n\u003cp\u003eHere's an example:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- name: Setup Bun\r\n  uses: oven-sh/setup-bun@v1.2.2\r\n  with:\r\n    bun-version: latest\r\n    bun-download-url: \u0026quot;https://github.com/oven-sh/bun/releases/latest/download/bun-${{runner.os == 'macOS' \u0026amp;\u0026amp; 'darwin' || runner.os}}-${{ runner.arch == 'X64' \u0026amp;\u0026amp; 'x64' || 'arm64' }}.zip\u0026quot;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003ev1.2.1\u003c/h2\u003e\n\u003ch1\u003esetup-bun \u003ccode\u003ev1.2.1\u003c/code\u003e\u003c/h1\u003e\n\u003cp\u003eDownload, install, and setup \u003ca href=\"https://bun.sh\"\u003eBun\u003c/a\u003e in GitHub Actions.\u003c/p\u003e\n\u003ch2\u003eUsage\u003c/h2\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- uses: oven-sh/setup-bun@v1\r\n  with:\r\n    bun-version: latest\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch3\u003eUsing a custom NPM registry\u003c/h3\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- uses: oven-sh/setup-bun@v1\r\n  with:\r\n    registry-url: \u0026quot;https://npm.pkg.github.com/\u0026quot;\r\n    scope: \u0026quot;@foo\u0026quot;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eIf you need to authenticate with a private registry, you can set the \u003ccode\u003eBUN_AUTH_TOKEN\u003c/code\u003e environment variable.\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e- name: Install Dependencies\r\n  env:\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/0c5077e51419868618aeaa5fe8019c62421857d6\"\u003e\u003ccode\u003e0c5077e\u003c/code\u003e\u003c/a\u003e release: v2.2.0 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/177\"\u003e#177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/1255e43b02f74b77bb39330ef756405951c3303a\"\u003e\u003ccode\u003e1255e43\u003c/code\u003e\u003c/a\u003e ci: update actions for the \u003ccode\u003eRelease new action version\u003c/code\u003e workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/175\"\u003e#175\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/61861d1f6a3acf561f12343ea89e2c71ff4af529\"\u003e\u003ccode\u003e61861d1\u003c/code\u003e\u003c/a\u003e ci: update actions for the \u003ccode\u003eautofix.ci\u003c/code\u003e workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/174\"\u003e#174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/6f5bd063f58cadd19ae42cca8bb41b191e9949bd\"\u003e\u003ccode\u003e6f5bd06\u003c/code\u003e\u003c/a\u003e ci: use \u003ccode\u003eactions/checkout@v6.0.2\u003c/code\u003e in the test workflow (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/173\"\u003e#173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/e3914758a49697077f7bcd190d36582a61667aad\"\u003e\u003ccode\u003ee391475\u003c/code\u003e\u003c/a\u003e build: update action runtime to Node.js 24 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/176\"\u003e#176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/ecf28ddc73e819eb6fa29df6b34ef8921c743461\"\u003e\u003ccode\u003eecf28dd\u003c/code\u003e\u003c/a\u003e release: v2.1.3 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/95edc153a3f71202eb7d8f0ee7b43c6b8b16763f\"\u003e\u003ccode\u003e95edc15\u003c/code\u003e\u003c/a\u003e fix: validate cached binary version matches requested version (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/146\"\u003e#146\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/4c32875876eebbbb9bc34b8ee07ba2d7bb4b3462\"\u003e\u003ccode\u003e4c32875\u003c/code\u003e\u003c/a\u003e feat: add AVX2 support detection for x64 Linux systems (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/167\"\u003e#167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/0ff83bfc51e05dd2251088164ec6a5e8533b476b\"\u003e\u003ccode\u003e0ff83bf\u003c/code\u003e\u003c/a\u003e fix: use native Windows ARM64 binary for Bun \u0026gt;= 1.3.10 (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/165\"\u003e#165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oven-sh/setup-bun/commit/ab8cb4e8f89912a29b87e4abc4554f2301648a5c\"\u003e\u003ccode\u003eab8cb4e\u003c/code\u003e\u003c/a\u003e feat: add bun- prefix to cache keys (\u003ca href=\"https://redirect.github.com/oven-sh/setup-bun/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/oven-sh/setup-bun/compare/v1...v2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 4 to 6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate packages, migrate to ESM by \u003ca href=\"https://github.com/Samirat\"\u003e\u003ccode\u003e@​Samirat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1760\"\u003eactions/cache#1760\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v6.0.0\"\u003ehttps://github.com/actions/cache/compare/v5...v6.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/cache\u003c/code\u003e to v5.1.0 - handle read-only cache access by \u003ca href=\"https://github.com/jasongin\"\u003e\u003ccode\u003e@​jasongin\u003c/cod...\n\n_Description has been truncated_","html_url":"https://github.com/simhadris17/SimhaStack/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/simhadris17%2FSimhaStack/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T21:38:59.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5532743281","node_id":"PR_kwDOTayYl88AAAABEfbqag","number":18,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group across 1 directory with 6 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T21:38:59.000Z","updated_at":"2026-09-21T21:39:36.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":6,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.3.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.3.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.5.1","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"},{"name":"pypa/gh-action-pypi-publish","old_version":"1.14.1","new_version":"1.14.2","repository_url":"https://github.com/pypa/gh-action-pypi-publish"},{"name":"sigstore/gh-action-sigstore-python","old_version":"3.4.0","new_version":"3.5.0","repository_url":"https://github.com/sigstore/gh-action-sigstore-python"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.3.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.5.1` | `4.6.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n| [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.1` | `1.14.2` |\n| [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) | `3.4.0` | `3.5.0` |\n\n\nUpdates `hadolint/hadolint-action` from 3.3.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/75bb911ebea0ab9b6188cbaba353bb3de62287e7\"\u003e\u003ccode\u003e75bb911\u003c/code\u003e\u003c/a\u003e fixup! Update hadolint.sh\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/631cc83a1d7add7571da26544581e8bb9db9c62a\"\u003e\u003ccode\u003e631cc83\u003c/code\u003e\u003c/a\u003e Update repository reference in problem-matcher.json\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/2332a7b74a6de0dda2e2221d575162eba76ba5e5...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.3.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.5.1 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/abd2ef45e78c5afb21d64d4ca52ee8550d9572c7...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/releases\"\u003epypa/gh-action-pypi-publish's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.14.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🛠️ Urgh… Another release!? Again? Explain yourself!\u003c/h2\u003e\n\u003cp\u003eLooking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!tip]\nSo what \u003cem\u003emost\u003c/em\u003e people will find useful is \u003ca href=\"https://github.com/takluyver\"\u003e\u003ccode\u003e@​takluyver\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/takluyver\"\u003e💰\u003c/a\u003e's update of Twine to v7 that we use internally (\u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003e🧐 Tell me why..\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eTL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like \u003ca href=\"https://redirect.github.com/aio-libs/aiohttp/pull/13226\"\u003eaio-libs/aiohttp#13226\u003c/a\u003e around July 23.\nOn this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.\u003c/p\u003e\n\u003cp\u003eI had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.\u003c/p\u003e\n\u003cp\u003eOver the course of investigation, \u003ca href=\"https://github.com/facutuesca\"\u003e\u003ccode\u003e@​facutuesca\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/facutuesca\"\u003e💰\u003c/a\u003e found and fixed a related underlying cache invalidation bug in \u003ca href=\"https://redirect.github.com/sigstore/sigstore-python/pull/1838\"\u003esigstore/sigstore-python#1838\u003c/a\u003e, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.\u003c/p\u003e\n\u003cp\u003eMike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: \u003ca href=\"https://publishing-five-minute-timeout.tiiny.site\"\u003ehttps://publishing-five-minute-timeout.tiiny.site\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🫶 New Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415\"\u003e#415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/takluyver\"\u003e\u003ccode\u003e@​takluyver\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e🪞 Full Diff\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2\"\u003ehttps://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e🧔‍♂️ Release Manager:\u003c/strong\u003e \u003ca href=\"https://github.com/sponsors/webknjaz\"\u003e\u003ccode\u003e@​webknjaz\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://stand-with-ukraine.pp.ua\"\u003e🇺🇦\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e🙏 Special Thanks\u003c/strong\u003e to \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/davidbrochart\"\u003e💰\u003c/a\u003e and \u003ca href=\"https://github.com/Dreamsorcerer\"\u003e\u003ccode\u003e@​Dreamsorcerer\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/Dreamsorcerer\"\u003e💰\u003c/a\u003e for turning my attention (in \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415\"\u003e#415\u003c/a\u003e and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. \u003ca href=\"https://github.com/bdraco\"\u003e\u003ccode\u003e@​bdraco\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/bdraco\"\u003e💰\u003c/a\u003e came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. \u003ca href=\"https://github.com/miketheman\"\u003e\u003ccode\u003e@​miketheman\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/miketheman\"\u003e💰\u003c/a\u003e confirmed the Warehouse-side details. Also, \u003ca href=\"https://github.com/jku\"\u003e\u003ccode\u003e@​jku\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/jku\"\u003e💰\u003c/a\u003e and \u003ca href=\"https://github.com/woodruffw\"\u003e\u003ccode\u003e@​woodruffw\u003c/code\u003e\u003c/a\u003e\u003ca href=\"https://github.com/sponsors/woodruffw\"\u003e💰\u003c/a\u003e helped work through, review and release the Sigstore ecosystem upstream libs.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e💬 Discuss\u003c/strong\u003e \u003ca href=\"https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j\"\u003eon Bluesky 🦋\u003c/a\u003e, \u003ca href=\"https://mastodon.social/@webknjaz/117005132816750073\"\u003eon Mastodon 🐘\u003c/a\u003e and [on GitHub][release discussion].\u003c/p\u003e\n\u003cp\u003e[![GH Sponsors badge]][GH Sponsors URL]\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/dc37677b2e1c63e2034f94d8a5b11f265b73ba33\"\u003e\u003ccode\u003edc37677\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/417\"\u003e#417\u003c/a\u003e from trail-of-forks/ft/bump-deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/8b2f23418f024937cf97f77534a597947105e772\"\u003e\u003ccode\u003e8b2f234\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypi-attestations\u003c/code\u003e and \u003ccode\u003esigstore\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/78b72dbfed6e025eb89577c059edc936f8a2df14\"\u003e\u003ccode\u003e78b72db\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416\"\u003e#416\u003c/a\u003e from takluyver/twine-v7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/commit/92f4d2a159875dd135a7e56b7b3262f502b23a13\"\u003e\u003ccode\u003e92f4d2a\u003c/code\u003e\u003c/a\u003e Update twine to v7\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pypa/gh-action-pypi-publish/compare/ba38be9e461d3875417946c167d0b5f3d385a247...dc37677b2e1c63e2034f94d8a5b11f265b73ba33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sigstore/gh-action-sigstore-python` from 3.4.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/releases\"\u003esigstore/gh-action-sigstore-python's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe action now uses \u003ca href=\"https://github.com/sigstore/sigstore-python\"\u003esigstore\u003c/a\u003e 4.5.0\u003c/li\u003e\n\u003cli\u003eBump other dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/compare/v3.4.0...v3.5.0\"\u003ehttps://github.com/sigstore/gh-action-sigstore-python/compare/v3.4.0...v3.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/790bc6befb9d733738f18d8f895854b453640ec9\"\u003e\u003ccode\u003e790bc6b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action/upload-sarif in the actions group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/445\"\u003e#445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/513a14942a452294df6cf0387762f4872d190109\"\u003e\u003ccode\u003e513a149\u003c/code\u003e\u003c/a\u003e build(deps): bump platformdirs in the python-dependencies group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/446\"\u003e#446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/74e004047800e50833c6fe90f17003f764a112fa\"\u003e\u003ccode\u003e74e0040\u003c/code\u003e\u003c/a\u003e Bump sigstore from 4.4 to 4.5 (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/444\"\u003e#444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/52538fdda336882a056c40b6364f8b39cf117401\"\u003e\u003ccode\u003e52538fd\u003c/code\u003e\u003c/a\u003e build(deps): bump the actions group across 1 directory with 4 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/439\"\u003e#439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/cbab91d8551b56009e61847b6403dea3baaf5509\"\u003e\u003ccode\u003ecbab91d\u003c/code\u003e\u003c/a\u003e build(deps): bump the python-dependencies group across 1 directory with 9 upd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/1d3524cb549bc0806f8ed27cdf6b6434d37a42a1\"\u003e\u003ccode\u003e1d3524c\u003c/code\u003e\u003c/a\u003e build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 in the acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/a1744845fbc68281e15c62b04220920b9f3c0766\"\u003e\u003ccode\u003ea174484\u003c/code\u003e\u003c/a\u003e build(deps): bump sigstore from 4.3.0 to 4.4.0 in the python-dependencies gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/0b384a68485d27aa4751533ff55c1d3ac2eb46af\"\u003e\u003ccode\u003e0b384a6\u003c/code\u003e\u003c/a\u003e build(deps): bump the actions group with 2 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/429\"\u003e#429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/f11d8f862eca1b34affd24b3403ae612f0980527\"\u003e\u003ccode\u003ef11d8f8\u003c/code\u003e\u003c/a\u003e build(deps): bump typing-extensions in the python-dependencies group (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/430\"\u003e#430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/commit/258577b06d5c2d98682589ca8b6e432ec9bfe070\"\u003e\u003ccode\u003e258577b\u003c/code\u003e\u003c/a\u003e build(deps): bump the python-dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/sigstore/gh-action-sigstore-python/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/sigstore/gh-action-sigstore-python/compare/5b79a39c381910c090341a2c9b0bf022c8b387e1...790bc6befb9d733738f18d8f895854b453640ec9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/creezio/hermes-agent-creezio/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/creezio%2Fhermes-agent-creezio/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"}},{"old_version":"2.3.8","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T20:59:32.000Z","version_change":"2.3.8 → 2.6.0","issue":{"uuid":"5532400452","node_id":"PR_kwDOUiFKBs8AAAABEfJ--g","number":6,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T20:59:32.000Z","updated_at":"2026-09-22T05:03:55.825Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"hadolint/hadolint-action","old_version":"3.1.0","new_version":"3.5.0","repository_url":"https://github.com/hadolint/hadolint-action"},{"name":"docker/build-push-action","old_version":"7.1.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"docker/login-action","old_version":"4.1.0","new_version":"4.6.0","repository_url":"https://github.com/docker/login-action"},{"name":"cachix/install-nix-action","old_version":"31.11.0","new_version":"31.11.1","repository_url":"https://github.com/cachix/install-nix-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.3.8","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.1.0` | `3.5.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.4.0` |\n| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |\n| [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.8` | `2.6.0` |\n\nUpdates `hadolint/hadolint-action` from 3.1.0 to 3.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hadolint/hadolint-action/releases\"\u003ehadolint/hadolint-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.5.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.4.0...v3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-24)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.1 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e941db07\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.4.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.3.0...v3.4.0\"\u003e3.4.0\u003c/a\u003e (2026-07-30)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump Hadolint to v2.15.0 (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e2a66e89\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.3.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.2.0...v3.3.0\"\u003e3.3.0\u003c/a\u003e (2025-09-22)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etrigger release workflow (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e2332a7b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.2.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/compare/v3.1.0...v3.2.0\"\u003e3.2.0\u003c/a\u003e (2025-09-03)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enew minor release (\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/3fc49fb50d59c6ab7917a2e4195dba633e515b29\"\u003e3fc49fb\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003e\u003ccode\u003e06be81b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/107\"\u003e#107\u003c/a\u003e from gizero/bump-hadolint-base-image-to-2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/941db0791d5d2906c0688cdfeb142afc2026e9a5\"\u003e\u003ccode\u003e941db07\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/d0e9595267e318f60cfb87e46a36191931e75083\"\u003e\u003ccode\u003ed0e9595\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/106\"\u003e#106\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/78\"\u003egh-78\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df662ab7a1f3ea4c2fe010d242dbda3a079a57b5\"\u003e\u003ccode\u003edf662ab\u003c/code\u003e\u003c/a\u003e Problem Matcher: Capture code and severity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/32c6895df40d4c982b0de822c4c8536908def4d8\"\u003e\u003ccode\u003e32c6895\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/85\"\u003e#85\u003c/a\u003e from rjbell4/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/146301c88f3177f4e61f3049a62b1c839939a00a\"\u003e\u003ccode\u003e146301c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/105\"\u003e#105\u003c/a\u003e from m-ildefons/\u003ca href=\"https://redirect.github.com/hadolint/hadolint-action/issues/100\"\u003egh-100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/df8eaaf67fe22a4499b3883b6d87ad304d4d355e\"\u003e\u003ccode\u003edf8eaaf\u003c/code\u003e\u003c/a\u003e CI: run integration tests with different runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2a66e89f53d0771bb131a7fa31f3136336094aa6\"\u003e\u003ccode\u003e2a66e89\u003c/code\u003e\u003c/a\u003e feat: Bump Hadolint to v2.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2332a7b74a6de0dda2e2221d575162eba76ba5e5\"\u003e\u003ccode\u003e2332a7b\u003c/code\u003e\u003c/a\u003e feat: trigger release workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hadolint/hadolint-action/commit/2bfd2b95f895100db2ca84c3054a8ce50f1fc611\"\u003e\u003ccode\u003e2bfd2b9\u003c/code\u003e\u003c/a\u003e Don't trigger release workflow on Tag\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hadolint/hadolint-action/compare/54c9adbab1582c2ef04b2016b760714a4bfde3cf...06be81baf89a55ffd0e24b8f04a4185738dd3387\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.1.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1567\"\u003edocker/build-push-action#1567\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1545\"\u003edocker/build-push-action#1545\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1572\"\u003edocker/build-push-action#1572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1568\"\u003edocker/build-push-action#1568\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1566\"\u003edocker/build-push-action#1566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1547\"\u003edocker/build-push-action#1547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1564\"\u003edocker/build-push-action#1564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.2 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1563\"\u003edocker/build-push-action#1563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1525\"\u003edocker/build-push-action#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.87.0 to 0.90.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1517\"\u003edocker/build-push-action#1517\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 2.0.2 to 5.0.6 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1534\"\u003edocker/build-push-action#1534\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-builder from 1.1.4 to 1.2.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1529\"\u003edocker/build-push-action#1529\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.5.7 to 5.8.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1521\"\u003edocker/build-push-action#1521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.6 to 8.5.10 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1526\"\u003edocker/build-push-action#1526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tar from 6.2.1 to 7.5.15 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1533\"\u003edocker/build-push-action#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.1.0...v7.2.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/login-action` from 4.1.0 to 4.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/login-action/releases\"\u003edocker/login-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden buildx scoped config path handling by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1059\"\u003edocker/login-action#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1095.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1051\"\u003edocker/login-action#1051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.1 to 5.2.2 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1057\"\u003edocker/login-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.22 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1056\"\u003edocker/login-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.2...v4.6.0\"\u003ehttps://github.com/docker/login-action/compare/v4.5.2...v4.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSurface Docker Hub OIDC error responses by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1058\"\u003edocker/login-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.1...v4.5.2\"\u003ehttps://github.com/docker/login-action/compare/v4.5.1...v4.5.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003edhi.io\u003c/code\u003e as Docker Hub OIDC registry by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1054\"\u003edocker/login-action#1054\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.5.0...v4.5.1\"\u003ehttps://github.com/docker/login-action/compare/v4.5.0...v4.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action#docker-hub\"\u003eDocker Hub OIDC\u003c/a\u003e login support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1048\"\u003edocker/login-action#1048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1091.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1037\"\u003edocker/login-action#1037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.94.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1044\"\u003edocker/login-action#1044\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1050\"\u003edocker/login-action#1050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.16 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1046\"\u003edocker/login-action#1046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.2.0 to 5.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1038\"\u003edocker/login-action#1038\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.4.0...v4.5.0\"\u003ehttps://github.com/docker/login-action/compare/v4.4.0...v4.5.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip empty \u003ccode\u003eregistry-auth\u003c/code\u003e secret mask by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1035\"\u003edocker/login-action#1035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1077.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1034\"\u003edocker/login-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/login-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve names in esbuild bundle by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1022\"\u003edocker/login-action#1022\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​aws-sdk/client-ecr\u003c/code\u003e and \u003ccode\u003e@​aws-sdk/client-ecr-public\u003c/code\u003e to 3.1076.0 \u003ca href=\"https://redirect.github.com/docker/login-action/pull/999\"\u003edocker/login-action#999\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1030\"\u003edocker/login-action#1030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.90.0 to 0.92.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1004\"\u003edocker/login-action#1004\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1027\"\u003edocker/login-action#1027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/core\u003c/code\u003e from 3.1.0 to 3.2.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1023\"\u003edocker/login-action#1023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​sigstore/verify\u003c/code\u003e from 3.1.0 to 3.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1029\"\u003edocker/login-action#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump http-proxy-agent and https-proxy-agent to 9.1.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1017\"\u003edocker/login-action#1017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 5.2.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1028\"\u003edocker/login-action#1028\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1031\"\u003edocker/login-action#1031\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump tmp from 0.2.5 to 0.2.7 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1002\"\u003edocker/login-action#1002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.24.1 to 6.27.0 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1020\"\u003edocker/login-action#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.3 to 7.3.6 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/1019\"\u003edocker/login-action#1019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/login-action/compare/v4.2.0...v4.3.0\"\u003ehttps://github.com/docker/login-action/compare/v4.2.0...v4.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e from 3.0.0 to 3.0.1 in \u003ca href=\"https://redirect.github.com/docker/login-action/pull/976\"\u003edocker/login-action#976\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f\"\u003e\u003ccode\u003edbcb813\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1051\"\u003e#1051\u003c/a\u003e from docker/dependabot/npm_and_yarn/aws-sdk-dependen...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc\"\u003e\u003ccode\u003e5bcb015\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752\"\u003e\u003ccode\u003eb30b2f2\u003c/code\u003e\u003c/a\u003e build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108\"\u003e\u003ccode\u003e9087f1e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1057\"\u003e#1057\u003c/a\u003e from docker/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4\"\u003e\u003ccode\u003e0009830\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92\"\u003e\u003ccode\u003e2325523\u003c/code\u003e\u003c/a\u003e build(deps): bump js-yaml from 5.2.1 to 5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688\"\u003e\u003ccode\u003e4ec1d4a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1056\"\u003e#1056\u003c/a\u003e from docker/dependabot/npm_and_yarn/postcss-8.5.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3\"\u003e\u003ccode\u003e5fc99ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1053\"\u003e#1053\u003c/a\u003e from docker/dependabot/github_actions/aws-actions/co...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb\"\u003e\u003ccode\u003ee512bd5\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1052\"\u003e#1052\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5\"\u003e\u003ccode\u003ea146c91\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/login-action/issues/1059\"\u003e#1059\u003c/a\u003e from crazy-max/harden-buildx-scope-paths\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...dbcb813823bdd20940b903addbd779551569679f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cachix/install-nix-action` from 31.11.0 to 31.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cachix/install-nix-action/releases\"\u003ecachix/install-nix-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev31.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003enix: 2.35.1 -\u0026gt; 2.35.2 by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/pull/281\"\u003ecachix/install-nix-action#281\u003c/a\u003e\nFixes a crash (\u003ca href=\"https://redirect.github.com/NixOS/nix/issues/16005\"\u003e\u003ccode\u003eAssertion '!awake.empty()' failed\u003c/code\u003e\u003c/a\u003e) that could abort builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\"\u003ehttps://github.com/cachix/install-nix-action/compare/v31.11.0...v31.11.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003e\u003ccode\u003e13d8dd5\u003c/code\u003e\u003c/a\u003e fix(ci): skip latest installer on x86_64-darwin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/875018fe555aee647c21ea81888659240cd8e27b\"\u003e\u003ccode\u003e875018f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cachix/install-nix-action/issues/281\"\u003e#281\u003c/a\u003e from cachix/create-pull-request/patch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cachix/install-nix-action/commit/6624a11f6c07674a3ff71d2431865aecf3587190\"\u003e\u003ccode\u003e6624a11\u003c/code\u003e\u003c/a\u003e nix: 2.35.1 -\u0026gt; 2.35.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.8 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.1\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.3.8.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions/checkout action to v7 by \u003ca href=\"https://github.com/renovate-bot\"\u003e\u003ccode\u003e@​renovate-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/133\"\u003egoogle/osv-scanner-action#133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve package namespaces when querying osv.dev API (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2978\"\u003e#2978\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRe-add support for the \u003ccode\u003eOSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY\u003c/code\u003e environment variable (fixes \u003ca href=\"https://redirect.github.com/google/osv-scanner/issues/2983\"\u003e#2983\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix local vulnerability matching (\u003ccode\u003e--offline-vulnerabilities\u003c/code\u003e) not working when network capability is \u003ccode\u003eNetworkOnline\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.0...v2.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.5.0\u003c/h2\u003e\n\u003cp\u003eThis updates OSV-Scanner to v2.5.0 as well as:\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: gate reusable workflow outputs with a flag by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/130\"\u003egoogle/osv-scanner-action#130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin download-artifact action to SHA by \u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add runs-on input to reusable workflows by \u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: address zizmor warnings by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/135\"\u003egoogle/osv-scanner-action#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: add GOTOOLCHAIN=auto env to osv-scanner calls by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/138\"\u003egoogle/osv-scanner-action#138\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SVilgelm\"\u003e\u003ccode\u003e@​SVilgelm\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/127\"\u003egoogle/osv-scanner-action#127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BeyondEvil\"\u003e\u003ccode\u003e@​BeyondEvil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/131\"\u003egoogle/osv-scanner-action#131\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.3.8...v2.5.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6e4298ebc4db23e847df9b2e2de2939d6f066c67\"\u003e\u003ccode\u003e6e4298e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/141\"\u003e#141\u003c/a\u003e from google/update-to-v2.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/5957b4e7a8725730a37d973099c16b9fe44cfc5f\"\u003e\u003ccode\u003e5957b4e\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.5.1 reusable workflows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/9a498708959aeaef5ef730655706c5a1df1edbc2...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Chensihakniroth/anakot-agent-v1/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Chensihakniroth%2Fanakot-agent-v1/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T19:51:20.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5531737691","node_id":"PR_kwDOTn5yY88AAAABEenkRw","number":90,"state":"open","title":"chore(actions)(deps): bump the actions-minor-patch group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T19:51:20.000Z","updated_at":"2026-09-21T19:51:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(actions)(deps): bump","group_name":"actions-minor-patch","update_count":5,"packages":[{"name":"github/codeql-action/init","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.38.0","new_version":"4.38.1","repository_url":"https://github.com/github/codeql-action"},{"name":"docker/setup-buildx-action","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/docker/setup-buildx-action"},{"name":"docker/build-push-action","old_version":"7.3.0","new_version":"7.4.0","repository_url":"https://github.com/docker/build-push-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the actions-minor-patch group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |\n| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |\n| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.5.1` | `2.6.0` |\n\nUpdates `github/codeql-action/init` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.38.0 to 4.38.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003e\u003ccode\u003e1c5b675\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4152\"\u003e#4152\u003c/a\u003e from github/update-v4.38.1-a65b83a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17\"\u003e\u003ccode\u003ea97cdca\u003c/code\u003e\u003c/a\u003e Add changelog entry for \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611\"\u003e\u003ccode\u003ecc6c691\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258\"\u003e\u003ccode\u003ea65b83a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4146\"\u003e#4146\u003c/a\u003e from github/henrymercer/per-language-bundles-pr\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042\"\u003e\u003ccode\u003e07fa87d\u003c/code\u003e\u003c/a\u003e Clarify the latest-nightly eligibility exception\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae\"\u003e\u003ccode\u003ef18f353\u003c/code\u003e\u003c/a\u003e Describe the bundle URL resolver\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46\"\u003e\u003ccode\u003eecec9b5\u003c/code\u003e\u003c/a\u003e Share per-language telemetry fields without renaming\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af\"\u003e\u003ccode\u003e79fe3a1\u003c/code\u003e\u003c/a\u003e Move download telemetry into the status-report directory\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607\"\u003e\u003ccode\u003eead1f7d\u003c/code\u003e\u003c/a\u003e Rename the platform module\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f\"\u003e\u003ccode\u003e549d498\u003c/code\u003e\u003c/a\u003e Simplify per-language platform eligibility checks\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/setup-buildx-action` from 4.3.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/setup-buildx-action/releases\"\u003edocker/setup-buildx-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip BuildKit image pre-pulls for explicit endpoints by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/624\"\u003edocker/setup-buildx-action#624\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse official Buildx releases for cloud driver by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/606\"\u003edocker/setup-buildx-action#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePull BuildKit image before builder creation by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/609\"\u003edocker/setup-buildx-action#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse shared error helpers for Buildx and Docker commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/620\"\u003edocker/setup-buildx-action#620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.95.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/610\"\u003edocker/setup-buildx-action#610\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/618\"\u003edocker/setup-buildx-action#618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/619\"\u003edocker/setup-buildx-action#619\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/614\"\u003edocker/setup-buildx-action#614\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 5.3.0 to 5.4.2 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/608\"\u003edocker/setup-buildx-action#608\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/617\"\u003edocker/setup-buildx-action#617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/pull/611\"\u003edocker/setup-buildx-action#611\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0\"\u003ehttps://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003e\u003ccode\u003ef87e599\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/624\"\u003e#624\u003c/a\u003e from crazy-max/skip-pull-with-endpoint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022\"\u003e\u003ccode\u003ee700274\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07\"\u003e\u003ccode\u003e3061c91\u003c/code\u003e\u003c/a\u003e skip BuildKit image pre-pulls for explicit endpoints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003\"\u003e\u003ccode\u003e594f3bf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/609\"\u003e#609\u003c/a\u003e from crazy-max/pull-buildkit-image-before-create\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25\"\u003e\u003ccode\u003ebd6e702\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032\"\u003e\u003ccode\u003e6268c9d\u003c/code\u003e\u003c/a\u003e pull BuildKit image before builder creation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11\"\u003e\u003ccode\u003ee823525\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/621\"\u003e#621\u003c/a\u003e from docker/dependabot/github_actions/codeql-actions-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d\"\u003e\u003ccode\u003e533ed8e\u003c/code\u003e\u003c/a\u003e build(deps): bump the codeql-actions group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99\"\u003e\u003ccode\u003ebedaf13\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/setup-buildx-action/issues/620\"\u003e#620\u003c/a\u003e from crazy-max/shared-error-helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2\"\u003e\u003ccode\u003ed5079fb\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...f87e5991a6d7451dcb8d9637bfbc97413f497069\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.3.0 to 7.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.4.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse the shared error helper for Buildx commands by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1620\"\u003edocker/build-push-action#1620\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrevent workflow command injection in metadata logs by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1617\"\u003edocker/build-push-action#1617\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.92.0 to 0.100.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1614\"\u003edocker/build-push-action#1614\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1618\"\u003edocker/build-push-action#1618\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1621\"\u003edocker/build-push-action#1621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1609\"\u003edocker/build-push-action#1609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.13 to 1.1.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1592\"\u003edocker/build-push-action#1592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump csv-parse from 7.0.0 to 7.0.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1613\"\u003edocker/build-push-action#1613\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.3.0 to 4.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1605\"\u003edocker/build-push-action#1605\u003c/a\u003e \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1615\"\u003edocker/build-push-action#1615\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump nanoid from 3.3.16 to 3.3.18 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1611\"\u003edocker/build-push-action#1611\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss from 8.5.10 to 8.5.25 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1590\"\u003edocker/build-push-action#1590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump postcss-selector-parser from 7.1.1 to 7.1.5 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1606\"\u003edocker/build-push-action#1606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump sigstore from 4.1.0 to 4.1.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1577\"\u003edocker/build-push-action#1577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.27.0 to 6.28.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1594\"\u003edocker/build-push-action#1594\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003e\u003ccode\u003ec3c9e26\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1621\"\u003e#1621\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42\"\u003e\u003ccode\u003e459b674\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e\"\u003e\u003ccode\u003e4dedcb2\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.99.0 to 0.100.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952\"\u003e\u003ccode\u003e379bf63\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1620\"\u003e#1620\u003c/a\u003e from crazy-max/buildx-error-message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6\"\u003e\u003ccode\u003e9877975\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94\"\u003e\u003ccode\u003e7ed0556\u003c/code\u003e\u003c/a\u003e use the shared Buildx error summary helper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1\"\u003e\u003ccode\u003e91670ba\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1618\"\u003e#1618\u003c/a\u003e from docker/dependabot/npm_and_yarn/docker/actions-t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a\"\u003e\u003ccode\u003e80dbc86\u003c/code\u003e\u003c/a\u003e [dependabot skip] chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d\"\u003e\u003ccode\u003e50cac3a\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.98.0 to 0.99.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1\"\u003e\u003ccode\u003e03b4d6c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1617\"\u003e#1617\u003c/a\u003e from crazy-max/fix-metadata-workflow-commands\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/mintoriakamoto/Hercules/pull/90","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mintoriakamoto%2FHercules/issues/90","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/90/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T13:37:58.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5527747551","node_id":"PR_kwDOTVqsYM8AAAABEbZOEg","number":113,"state":"open","title":"chore(deps): bump the github-actions group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T13:37:58.000Z","updated_at":"2026-09-21T20:27:44.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"github-actions","update_count":3,"packages":[{"name":"github/codeql-action/init","old_version":"4.37.9","new_version":"4.38.0","repository_url":"https://github.com/github/codeql-action"},{"name":"github/codeql-action/analyze","old_version":"4.37.9","new_version":"4.38.0","repository_url":"https://github.com/github/codeql-action"},{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action).\n\nUpdates `github/codeql-action/init` from 4.37.9 to 4.38.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/init's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/init's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003e\u003ccode\u003eb96794f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4131\"\u003e#4131\u003c/a\u003e from github/update-v4.38.0-7e08580a9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef\"\u003e\u003ccode\u003e02d5093\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6\"\u003e\u003ccode\u003e7e08580\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4130\"\u003e#4130\u003c/a\u003e from github/henrymercer/workflow-runner-sizing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698\"\u003e\u003ccode\u003ebfcc52b\u003c/code\u003e\u003c/a\u003e Run slow macOS checks on larger runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4\"\u003e\u003ccode\u003e8c251e7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4129\"\u003e#4129\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1\"\u003e\u003ccode\u003e0b7ca40\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505\"\u003e\u003ccode\u003e40484b3\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df\"\u003e\u003ccode\u003e977e6ce\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4124\"\u003e#4124\u003c/a\u003e from github/henrymercer/toolcache-bundle-cleanup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc\"\u003e\u003ccode\u003e40a6b38\u003c/code\u003e\u003c/a\u003e Address toolcache cleanup review feedback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252\"\u003e\u003ccode\u003edeece8f\u003c/code\u003e\u003c/a\u003e Apply suggestion from \u003ca href=\"https://github.com/henrymercer\"\u003e\u003ccode\u003e@​henrymercer\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/analyze` from 4.37.9 to 4.38.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/analyze's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/analyze's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.1 - 18 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4146\"\u003e#4146\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e CodeQL bundle when available. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to \u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested path that is used elsewhere. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead of falling back to downloading the bundle before extracting it. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the \u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to be specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository property\u003c/a\u003e. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition always takes precedence unless the value of the repository property starts with \u003ccode\u003e!\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the \u003ccode\u003eremote=\u003c/code\u003e prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003e\u003ccode\u003eb96794f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4131\"\u003e#4131\u003c/a\u003e from github/update-v4.38.0-7e08580a9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef\"\u003e\u003ccode\u003e02d5093\u003c/code\u003e\u003c/a\u003e Update changelog for v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6\"\u003e\u003ccode\u003e7e08580\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4130\"\u003e#4130\u003c/a\u003e from github/henrymercer/workflow-runner-sizing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698\"\u003e\u003ccode\u003ebfcc52b\u003c/code\u003e\u003c/a\u003e Run slow macOS checks on larger runners\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4\"\u003e\u003ccode\u003e8c251e7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4129\"\u003e#4129\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1\"\u003e\u003ccode\u003e0b7ca40\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505\"\u003e\u003ccode\u003e40484b3\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df\"\u003e\u003ccode\u003e977e6ce\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/4124\"\u003e#4124\u003c/a\u003e from github/henrymercer/toolcache-bundle-cleanup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc\"\u003e\u003ccode\u003e40a6b38\u003c/code\u003e\u003c/a\u003e Address toolcache cleanup review feedback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252\"\u003e\u003ccode\u003edeece8f\u003c/code\u003e\u003c/a\u003e Apply suggestion from \u003ca href=\"https://github.com/henrymercer\"\u003e\u003ccode\u003e@​henrymercer\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.5.1 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/windwardline/pathfinder/pull/113","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/windwardline%2Fpathfinder/issues/113","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/113/packages"}},{"old_version":"2.5.1","new_version":"2.6.0","update_type":"minor","path":null,"pr_created_at":"2026-09-21T07:44:00.000Z","version_change":"2.5.1 → 2.6.0","issue":{"uuid":"5524164261","node_id":"PR_kwDOGBFizs8AAAABEYhKtA","number":172,"state":"closed","title":"ci(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml from 2.5.1 to 2.6.0","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-21T07:44:13.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T07:44:00.000Z","updated_at":"2026-09-21T07:44:20.000Z","time_to_close":13,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps)","packages":[{"name":"google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml","old_version":"2.5.1","new_version":"2.6.0","repository_url":"https://github.com/google/osv-scanner-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) from 2.5.1 to 2.6.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/google/osv-scanner-action/releases\"\u003egoogle/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix JSON results export by \u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e  in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the job when a scan does not complete by \u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Update to v2.6.0 by \u003ca href=\"https://github.com/another-rex\"\u003e\u003ccode\u003e@​another-rex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/144\"\u003egoogle/osv-scanner-action#144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alimony\"\u003e\u003ccode\u003e@​alimony\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/139\"\u003egoogle/osv-scanner-action#139\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/thomasleplus\"\u003e\u003ccode\u003e@​thomasleplus\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/pull/142\"\u003egoogle/osv-scanner-action#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\"\u003ehttps://github.com/google/osv-scanner-action/compare/v2.5.1...v2.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003e\u003ccode\u003ea345acf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/144\"\u003e#144\u003c/a\u003e from google/update-to-v2.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/6b289e01b25bdfc0e015b18fe26dacf9b14925bc\"\u003e\u003ccode\u003e6b289e0\u003c/code\u003e\u003c/a\u003e Update unified workflow example to point to v2.6.0 reusable workflows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/c7c7bcb0773cc4678a674ada03a66cc5c4325476\"\u003e\u003ccode\u003ec7c7bcb\u003c/code\u003e\u003c/a\u003e Update reusable workflows to point to v2.6.0 actions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/7f58dd6750d78fc29a900ba64b1a0f946f62fba4\"\u003e\u003ccode\u003e7f58dd6\u003c/code\u003e\u003c/a\u003e \u0026quot;Update actions to use v2.6.0 osv-scanner image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/8e5cf47b818121e8b405931c82126c2630b0b20d\"\u003e\u003ccode\u003e8e5cf47\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/139\"\u003e#139\u003c/a\u003e from alimony/fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/bf5f9247efc2c6371208619929a5ec5092acb63c\"\u003e\u003ccode\u003ebf5f924\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/ffa0a5f39214d80778c9b494822d94d0d9668458\"\u003e\u003ccode\u003effa0a5f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/google/osv-scanner-action/issues/142\"\u003e#142\u003c/a\u003e from google/fix-json-export-code\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/259ba4a9934b98dab293dece8e6dd02c7118257a\"\u003e\u003ccode\u003e259ba4a\u003c/code\u003e\u003c/a\u003e Fix JSON results export\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/d291480cd4ef7e673606295ee18ae3d1a3eb35ff\"\u003e\u003ccode\u003ed291480\u003c/code\u003e\u003c/a\u003e Check for file size as well\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/osv-scanner-action/commit/2dff55c378e96f2357700383349278fb382d9fd1\"\u003e\u003ccode\u003e2dff55c\u003c/code\u003e\u003c/a\u003e Fail the job when a scan does not complete\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/google/osv-scanner-action/compare/6e4298ebc4db23e847df9b2e2de2939d6f066c67...a345acffa64b0eaede81a3d9aae6141214d9c8fc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml\u0026package-manager=github_actions\u0026previous-version=2.5.1\u0026new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/thomasleplus/thomasleplus/pull/172","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/thomasleplus%2Fthomasleplus/issues/172","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/172/packages"}}]}