ci(deps): bump google/osv-scanner-action from 2.1.0 to 2.2.1
Open
Number: #62
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
August 22, 2025 at 02:44 AM UTC
(10 months ago)
(10 months ago)
Updated:
August 22, 2025 at 02:45 AM UTC
(10 months ago)
(10 months ago)
Labels:
dependencies github_actions
dependencies github_actions
Description:
Bumps google/osv-scanner-action from 2.1.0 to 2.2.1.
Release notes
Sourced from google/osv-scanner-action's releases.
v2.2.1
What's Changed
OSV-Scanner now supports all OSV-Scalibr features behind experimental flags (
--experimental-plugins, see details here)!Features:
- [Feature #2146](google/osv-scanner#2146) Allow manual OSV-Scalibr plugin selection.
- [Feature #2144](google/osv-scanner#2144) Add OSV-Scalibr version to osv-scanner --version output.
- [Feature #2021](google/osv-scanner#2021) Add experimental support for running OSV-Scalibr detectors.
- [Feature #2079](google/osv-scanner#2079) Fall back to offline extractor if the transitive one fails, so at least direct dependencies are returned.
- [Feature #2032](google/osv-scanner#2032) Add summary section at the top of outputs and a 'Fixed Version' column.
- [Feature #2076](google/osv-scanner#2076) Support Ubuntu severity type.
Fixes:
- [Bug #2141](google/osv-scanner#2141) Fix OSV-Scanner json scans not matching with correct ecosystem.
- [Bug #2084](google/osv-scanner#2084) Show absolute paths when scanning containers.
- [Bug #2126](google/osv-scanner#2126) Log and preserve package count before continuing on db error.
- [Bug #2095](google/osv-scanner#2095) Pass through plugin capabilities correctly.
- [Bug #2051](google/osv-scanner#2051) Properly flag if running on Linux or Mac OSs for plugin compatibility.
- [Bug #2072](google/osv-scanner#2072) Add missing "text" property in description fields.
- [Bug #2068](google/osv-scanner#2068) Change links in output to go to the specific vulnerability page instead of the list page.
- [Bug #2064](google/osv-scanner#2064) Fix SARIF v3 output to include results.
- [Bug #2151](google/osv-scanner#2151) Filter by ecosystem before querying.
API Changes:
- [API Change #2096](google/osv-scanner#2096) Allow log handler to be overridden.
[!WARNING] This release was originally incorrectly pointing to the bugged v2.2.0 osv-scanner release, it has now been retagged to the correct v2.2.1 release.
Commits
456ceb7Merge pull request #91 from google/update-to-v2.2.1233fa8eUpdate unified workflow example to point to v2.2.1 reusable workflows8878e97Update reusable workflows to point to v2.2.1 actions6580e6c"Update actions to use v2.2.1 osv-scanner image"79f88c2Merge pull request #90 from google/fix-update-script63b1aa2Use the right andeecdbccFix variable nameba543a9fix: Allow the update script to contain previous tagsd576d6dMerge pull request #79 from jess-lowe/jess-lowe-patch-14c3b1e9Merge pull request #80 from jess-lowe/jess-lowe-patch-2- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Package:
google/osv-scanner-action
Ecosystem:
actions
actions
Version Change:
2.1.0 → 2.2.1
Update Type:
Minor
Minor
Technical Details
| ID: | 5604438 |
| UUID: | 2764938661 |
| Node ID: | PR_kwDOAzspqs6kzZ2l |
| Host: | GitHub |
| Repository: | thomasleplus/JavaInfo |
| Merge State: | Unknown |