deps(actions): bump KineticCafe/actions-dco from 3.1.0 to 3.2.0 in the actions-all group - #1526
deps(actions): bump KineticCafe/actions-dco from 3.1.0 to 3.2.0 in the actions-all group#1526dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions-all group with 1 update: [KineticCafe/actions-dco](https://github.com/kineticcafe/actions-dco). Updates `KineticCafe/actions-dco` from 3.1.0 to 3.2.0 - [Release notes](https://github.com/kineticcafe/actions-dco/releases) - [Changelog](https://github.com/KineticCafe/actions-dco/blob/main/CHANGELOG.md) - [Commits](KineticCafe/actions-dco@1da0428...5f160e3) --- updated-dependencies: - dependency-name: KineticCafe/actions-dco dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all ... Signed-off-by: dependabot[bot] <support@github.com>
|
Fresh adversarial review — current head FindingsHIGH — required Windows regression lane is red
No separate workflow-security finding: the action remains SHA-pinned, DCO passed, and v3.2.0's default-branch configuration lookup is a hardening change rather than PR-controlled policy input. I read all existing PR-conversation comments, reviews, and review threads: all were empty. Residual merge gates
Recommendation: not mergeable until the red CI gate is resolved and the current-base/governance gates are green. |
Bumps the actions-all group with 1 update: KineticCafe/actions-dco.
Updates
KineticCafe/actions-dcofrom 3.1.0 to 3.2.0Release notes
Sourced from KineticCafe/actions-dco's releases.
Changelog
Sourced from KineticCafe/actions-dco's changelog.
... (truncated)
Commits
5f160e3feat: Add used configuration reportb1fee4echore: Build for releasec963bcbchore: Remove inline config5704499chore: Bump release version and add changelogfc47443feat: Support default branch config file54e60fachore: Carry decode errors up and present better errors.a171fbcchore: Clean up documentationcd84bf8chore: Add regression test for unknown authors15d7c62chore: Update action dependencies3ac7462chore: Use oaspec 0.69.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions