Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/approve-trivial.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ jobs:
);
core.setOutput('approved', exists ? 'true' : 'false');

- uses: DataDog/dd-octo-sts-action@96a25462dbcb10ebf0bfd6e2ccc917d2ab235b9a # v1.0.4
- uses: DataDog/dd-octo-sts-action@c85802a58e202b7e764b5441e4378c76043c8108 # v1.0.5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Upgrade the composite action invocation too

This updates only the two direct workflow invocations even though .github/actions/upsert-pr-comment/action.yml:27 still pins v1.0.4 and is actively called by both ci.yml:231 and codecheck.yml:55. Consequently, those CI paths continue running the old action and do not receive v1.0.5's dependency vulnerability upgrades; update the composite action's pin to the same verified SHA as part of this bump.

Useful? React with 👍 / 👎.

id: octo-sts
if: steps.existing.outputs.approved != 'true'
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/dependabot-automerge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ jobs:
permissions:
id-token: write # Needed to federate tokens
steps:
- uses: DataDog/dd-octo-sts-action@96a25462dbcb10ebf0bfd6e2ccc917d2ab235b9a # v1.0.4
- uses: DataDog/dd-octo-sts-action@c85802a58e202b7e764b5441e4378c76043c8108 # v1.0.5
id: octo-sts
with:
scope: DataDog/java-profiler
Expand Down
Loading