Skip to content

Bump securego/gosec from 2.24.0 to 2.24.7#491

Merged
arnested merged 1 commit intomainfrom
dependabot/github_actions/securego/gosec-2.24.7
Mar 2, 2026
Merged

Bump securego/gosec from 2.24.0 to 2.24.7#491
arnested merged 1 commit intomainfrom
dependabot/github_actions/securego/gosec-2.24.7

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 2, 2026

Bumps securego/gosec from 2.24.0 to 2.24.7.

Release notes

Sourced from securego/gosec's releases.

v2.24.7

Changelog

  • bb17e422fc34bf4c0a2e5cab9d07dc45a68c040c Ignore nosec comments in action integration workflow to generate some warnings (#1573)
  • e1502ad21653d1c6717e33f1221c3ce2d5c8581f Add a workflow for action integration test (#1571)
  • f8691bd77bab5430ccb538e6f253275e82577afc fix(sarif): avoid invalid null relationships in SARIF output (#1569)
  • ade1d0e0a04ec8ae98da98614d42524621d40df2 chore: migrate gosec container image references to GHCR (#1567)

v2.24.6

Changelog

  • 88835e86bba381290c2f60a1c73610995b1502eb Update gorelease to use the latest cosign bundle argument (#1565)
Commits
  • bb17e42 Ignore nosec comments in action integration workflow to generate some warning...
  • e1502ad Add a workflow for action integration test (#1571)
  • f8691bd fix(sarif): avoid invalid null relationships in SARIF output (#1569)
  • ade1d0e chore: migrate gosec container image references to GHCR (#1567)
  • 88835e8 Update gorelease to use the latest cosign bundle argument (#1565)
  • 4b8cc9a Migrate goreleaser to use the proper cosign arguments (#1564)
  • 22485d5 Update the cosing to version v3.0.5 (#1563)
  • 46e53da fix(release): use existing cosign-installer action version (#1562)
  • a7ab382 chore(prompts): add skill and prompt to update supported Go versions (#1561)
  • 84df6fa chore(prompts): add action version update skill and prompt (#1560)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [securego/gosec](https://github.com/securego/gosec) from 2.24.0 to 2.24.7.
- [Release notes](https://github.com/securego/gosec/releases)
- [Commits](securego/gosec@v2.24.0...v2.24.7)

---
updated-dependencies:
- dependency-name: securego/gosec
  dependency-version: 2.24.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Mar 2, 2026
@dependabot dependabot bot requested a review from arnested as a code owner March 2, 2026 20:22
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Mar 2, 2026
@arnested arnested merged commit b9e03a3 into main Mar 2, 2026
21 checks passed
@arnested arnested deleted the dependabot/github_actions/securego/gosec-2.24.7 branch March 2, 2026 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant