Skip to content

BUILD-10765 Important: Update SonarSource/gh-action_release to 6.5.0#313

Closed
mikolaj-matuszny-ext-sonarsource wants to merge 1 commit intomasterfrom
feat/BUILD-10765/update-gh-action_release
Closed

BUILD-10765 Important: Update SonarSource/gh-action_release to 6.5.0#313
mikolaj-matuszny-ext-sonarsource wants to merge 1 commit intomasterfrom
feat/BUILD-10765/update-gh-action_release

Conversation

@mikolaj-matuszny-ext-sonarsource
Copy link
Copy Markdown
Contributor

Important: Update SonarSource/gh-action_release to c52861bb0e5dd564187f3fd74e048f20aef0f761 (6.5.0) for compliance with allowed versions.

See: https://discuss.sonarsource.com/t/action-required-update-your-github-actions-cache-release-and-releasability-before-10-04/23899/5

@sonar-review-alpha
Copy link
Copy Markdown

sonar-review-alpha bot commented Apr 2, 2026

Summary

Upgrades the SonarSource/gh-action_release action from v6.4.1 to v6.5.0 in the release workflow, addressing a SonarSource compliance requirement. This is a straightforward action version bump with no changes to workflow logic or configuration.

What reviewers should know

The change affects two job steps in .github/workflows/release.yml (lines 14 and 23), both updating the action commit hash and version tag consistently. Verify the commit hash c52861bb0e5dd564187f3fd74e048f20aef0f761 corresponds to the intended v6.5.0 release if needed. No workflow configuration or behavior changes are present.


  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

@hashicorp-vault-sonar-prod
Copy link
Copy Markdown

hashicorp-vault-sonar-prod bot commented Apr 2, 2026

BUILD-10765

@sonarqube-next
Copy link
Copy Markdown

sonarqube-next bot commented Apr 2, 2026

Quality Gate passed Quality Gate passed for 'Python Scanner'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Copy link
Copy Markdown

@sonar-review-alpha sonar-review-alpha bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

Clean, minimal change — two consistent action version bumps in the release workflow with no logic or configuration changes. Safe to merge.

🗣️ Give feedback

@SonarTech
Copy link
Copy Markdown
Contributor

Superseded by #314 (re-created under SonarTech account)

@SonarTech SonarTech closed this Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants