这是indexloc提供的服务,不要输入任何密码
Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jun 1, 2022

Bumps github.com/CycloneDX/cyclonedx-go from 0.5.0 to 0.6.0.

Release notes

Sourced from github.com/CycloneDX/cyclonedx-go's releases.

v0.6.0

Changelog

Features

  • 3cc319e20e6f9f6565c3365b62515575859ccf1f: feat: add support for bom links (#33) (@​nscuro)

Fixes

  • 5f285ff028c09f67aa62338dc06fe8e5a6932936: fix: add missing Properties (#39) (@​desenna)

Building and Packaging

  • d06379863c460d7627bccc0d911e667e867bd029: build(deps): bump actions/checkout from 3.0.0 to 3.0.2 (@​dependabot[bot])
  • 0b1d408e1e008c9972eac2206108511f98fc0738: build(deps): bump actions/setup-go from 3.0.0 to 3.1.0 (@​dependabot[bot])
  • 47702c484c166133a6f5072e975b4351334c238d: build(deps): bump apache/skywalking-eyes from 0.2.0 to 0.3.0 (@​dependabot[bot])
  • 5940b17535582a8f9111f5c013dd69c9e07bce53: build(deps): bump golangci/golangci-lint-action from 3.1.0 to 3.2.0 (@​dependabot[bot])

v0.5.2

Changelog

Fixes

  • 0a1487ee034a465f34a8b9f8a7198d93c4811c45: fix: edit casing of email (#30) (@​jspeed-meyers)
  • 644d3e5e219bcfea92bfbfce354ae95c3f4fed55: fix: encoding of XML chars in tags (@​derkoe)

Building and Packaging

  • dea6490495cfeea64fc85e00fa000d9388d60ab9: build(actions): set permissions and timeouts (@​nscuro)
  • 22c6201e3ff21d4db95325cd75551ce717be4b6b: build(actions): update cyclonedx cli to 0.24.0 (@​nscuro)
  • 9d0e58ed92da13937f91a87ab763bc9f5e303496: build(goreleaser): use native sboms feature (@​nscuro)

v0.5.1

Changelog

Fixes

  • 1fd9caf52906ff41300f8a13e8d1f28fbdefef6d: fix: make vuln rating score optional (@​nscuro)

Building and Packaging

  • 1f31d499debebde7a64746ce989478b76c60b8e3: build(ci): add setup-go to lint job (@​nscuro)
  • 018dff2c923dd820dda0a1b9a2b05b7e2dcf7078: build(deps): bump github.com/stretchr/testify from 1.7.0 to 1.7.1 (@​dependabot[bot])
  • 15708b3ca5da621b37ceddb403c96556b8302ade: build(deps): bump golangci/golangci-lint-action from 2 to 3.1.0 (@​dependabot[bot])
  • a2abeb69f0173b530208c1728e58c2530305574f: build(deps): update actions/checkout to v3.0.0 (@​nscuro)
  • ba3af87b824294d93c368ff33e35e32e7f230b80: build(deps): update actions/setup-go to v3.0.0 (@​nscuro)
Commits
  • 7d9a561 Merge pull request #37 from CycloneDX/dependabot/github_actions/actions/setup...
  • 0b1d408 build(deps): bump actions/setup-go from 3.0.0 to 3.1.0
  • 5f285ff fix: add missing Properties (#39)
  • 207c038 Merge pull request #34 from CycloneDX/dependabot/github_actions/apache/skywal...
  • 47702c4 build(deps): bump apache/skywalking-eyes from 0.2.0 to 0.3.0
  • 007af4c Merge pull request #35 from CycloneDX/dependabot/github_actions/golangci/gola...
  • 5940b17 build(deps): bump golangci/golangci-lint-action from 3.1.0 to 3.2.0
  • 3cc319e feat: add support for bom links (#33)
  • 3064f67 Merge pull request #29 from CycloneDX/dependabot/github_actions/actions/check...
  • d063798 build(deps): bump actions/checkout from 3.0.0 to 3.0.2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go) from 0.5.0 to 0.6.0.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml)
- [Commits](CycloneDX/cyclonedx-go@v0.5.0...v0.6.0)

---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jun 1, 2022
@github-actions
Copy link

github-actions bot commented Aug 1, 2022

This PR is stale because it has been labeled with inactivity.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Aug 22, 2022

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/go_modules/github.com/CycloneDX/cyclonedx-go-0.6.0 branch August 22, 2022 01:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code lifecycle/stale

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant