Skip to content

chore(ci): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 0ad473d1988aeee2bc3fa2c571e2701465225715 - #33

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-dependency-review.yml-0ad473d1988aeee2bc3fa2c571e2701465225715
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-dependency-review.yml-0ad473d1988aeee2bc3fa2c571e2701465225715

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor

Bumps NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 0ad473d1988aeee2bc3fa2c571e2701465225715.

Changelog

Sourced from NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml's changelog.

Changelog

This file is a release ledger: every heading below is a real release, and scripts/check_release_ledger.py enforces that in both directions.

The project follows Semantic Versioning.

[Unreleased]

  • Re-verify GitLab Free and Open Source allowances against current primary sources, with separate review deadlines and explicit eligibility conditions.

  • Preserve complete redacted private security evidence in a bounded, checksummed run-log ZIP when artifact upload fails. Scanner enforcement and failed fallback remain blocking; no new token permission or external storage is required.

  • Add optional check_name to the private-free security bundle so callers can retain an existing required check identity when migrating away from SARIF publication, with all four scanners and evidence artifacts preserved.

  • Synchronize pins by catalog action family, preserving independent subpath actions and reusable workflows in the same repository. Apply the reviewed dependency updates from #92 with matching catalog and transitive-image records; historical evidence digests are no longer rewritten by an unrelated action update.

  • Stop treating the publisher as an Enterprise Cloud buyer of Code Security, Secret Protection and Code Quality. Paid programmes stay explicitly selectable; public CodeQL, SARIF, Scorecard and attestations stay. Private repositories without those purchases use the private-free programme. A live GitHub plan belongs to one organization and is not copied between accounts. Consumer adoption resolves the programme from the immutable release being pinned, not from main. Private attestations stay an Enterprise Cloud plan gate, independent of the three add-ons.

  • Dependabot catalog convergence commits only catalog and generated docs, so the default GITHUB_TOKEN can push without workflows permission. Catalog-only follows the unique workflow pin per action and fails closed when identities are mixed, so the catalog cannot describe a pin the tree does not share. Ordinary merge in this repository does not require a general CI status check; ci-gate stays truthful advisory evidence. Authored skill metadata: mappings stay mappings.

  • Re-verify four vendor allowance records with staggered review dates, correct Ubicloud's monthly credit and Harness's conditional CI credit semantics, and align the disclosed Checkov image tag with the existing pinned action.

  • Publish unsuccessful completed self-workflow attempts as unassigned, repository-local CI evidence; preserve actual conclusions and exact attempts.

  • Accept exact matching development-commit comments and correct nested action pin validation and container whitespace rejection. Keep registrations scoped to their actual action paths.

  • Declare both git-submodule and reusable-workflow consumption in the GDS

... (truncated)

Commits
  • 0ad473d Merge pull request #106 from NDDev-OpenNetwork/chore/pin-reusable-workflows-2...
  • f50edc7 chore(ci): sync catalog pin for github-actions ci-feedback
  • 01fb74b chore(ci): pin reusable workflows to current module mains
  • 9eb9e07 Merge pull request #104 from NDDev-OpenNetwork/chore/no-unattributed-extra-ap...
  • e0dc39b fix(ruleset): disable extra approval for unattributed agent commits
  • a624689 Merge pull request #100 from NDDev-OpenNetwork/fix/security-evidence-log-fall...
  • 8419bdf fix: retain security evidence when artifact delivery fails
  • 3e70397 Merge pull request #99 from NDDev-OpenNetwork/fix/pin-the-fuzzing-base-image
  • 4958996 fix(fuzz): pin the ClusterFuzzLite base image by digest
  • 9231ee7 Merge pull request #98 from fix/private-security-check-identity-20260907
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…ic-dependency-review.yml

Bumps [NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml](https://github.com/nddev-opennetwork/ci-workflows) from 1ab6708b62ec7bd17f2d8a519c6fcc39edb22243 to 0ad473d1988aeee2bc3fa2c571e2701465225715.
- [Release notes](https://github.com/nddev-opennetwork/ci-workflows/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/ci-workflows/blob/main/CHANGELOG.md)
- [Commits](NDDev-OpenNetwork/ci-workflows@1ab6708...0ad473d)

---
updated-dependencies:
- dependency-name: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml
  dependency-version: 0ad473d1988aeee2bc3fa2c571e2701465225715
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants