build(deps): bump SonarSource/sonarqube-scan-action from 7 to 7.1.0 and no longer installed dependencies during the build - #138
Conversation
Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 7 to 7.1.0. - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@v7...v7.1.0) --- updated-dependencies: - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Fabustus
left a comment
There was a problem hiding this comment.
Please change the title according to the changes:
e.g. build(deps): bump SonarSource/sonarqube-scan-action from 7 to custom tag based on 7.1.0
a4e42a2 to
f48a3bc
Compare
This is infact not a custom tag, but the default information about the action version that should be given. When passing a tag, a malious attack could change the version behind the tag and point a broken version. See githubactions:S7637 |
|



Bumps SonarSource/sonarqube-scan-action from 7 to 7.1.0.
Release notes
Sourced from SonarSource/sonarqube-scan-action's releases.
Commits
ed9f3aaSQSCANGHA-112 Migrate installation step8f44848SQSCANGHA-115 Delete legacy shell script6a808e9SQSCANGHA-115 Migrate sanity checks9db6169SQSCANGHA-117 Set up js build5837ebfBUILD-8875: Migrate to standardized GitHub runner names1a6d90eSQSCANGHA-102 Pin actions/cache to a full-length commit SHA (#199)016cabfSQSCANGHA-101 Add more command injection testsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)