From eb7a9db9101217931a1102bb9abc32ba711a06dc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 11 May 2026 01:59:03 +0000 Subject: [PATCH] build(deps): bump the minor-and-patch group with 2 updates Bumps the minor-and-patch group with 2 updates: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) and [ossf/scorecard-action](https://github.com/ossf/scorecard-action). Updates `aquasecurity/trivy-action` from 0.35.0 to 0.36.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](https://github.com/aquasecurity/trivy-action/compare/v0.35.0...v0.36.0) Updates `ossf/scorecard-action` from 2.3.1 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](https://github.com/ossf/scorecard-action/compare/v2.3.1...v2.4.3) --- updated-dependencies: - dependency-name: aquasecurity/trivy-action dependency-version: 0.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/codex-quality-security.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codex-quality-security.yml b/.github/workflows/codex-quality-security.yml index 11d76fe..78b4caf 100644 --- a/.github/workflows/codex-quality-security.yml +++ b/.github/workflows/codex-quality-security.yml @@ -77,7 +77,7 @@ jobs: steps: - uses: actions/checkout@v4 - name: Trivy FS scan - uses: aquasecurity/trivy-action@v0.35.0 + uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: fs scanners: vuln,misconfig,secret @@ -97,4 +97,4 @@ jobs: steps: - uses: actions/checkout@v4 - name: OpenSSF Scorecard - uses: ossf/scorecard-action@v2.3.1 + uses: ossf/scorecard-action@v2.4.3