Skip to content

Bump dependencies using scripts/bump-deps.sh#2017

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
create-pull-request/patch
Open

Bump dependencies using scripts/bump-deps.sh#2017
github-actions[bot] wants to merge 1 commit into
mainfrom
create-pull-request/patch

Conversation

@github-actions

Copy link
Copy Markdown

This PR created by create-pull-request must be closed and reopened manually to trigger automated checks.

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@github-actions github-actions Bot requested a review from a team as a code owner June 16, 2026 11:45
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Jun 16, 2026
@sondavidb sondavidb closed this Jun 17, 2026
@sondavidb sondavidb reopened this Jun 17, 2026
@github-actions

Copy link
Copy Markdown
Author

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
gomod/github.com/urfave/cli/v3 3.10.0 🟢 6.7
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 5Found 7/12 approved changesets -- score normalized to 5
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection🟢 4branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
SAST🟢 3SAST tool is not run on all commits -- score normalized to 3

Scanned Files

  • cmd/go.mod

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant