Conversation
|
@dependabot rebase |
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.0 to 9.2.1. - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@1e7e51e...82606bf) --- updated-dependencies: - dependency-name: golangci/golangci-lint-action dependency-version: 9.2.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
762781e to
2c11f11
Compare
potiuk
left a comment
There was a problem hiding this comment.
LGTM — pinned SHA bump (v9.2.0 → v9.2.1) with clean source-diff and reproducible JS bundle. The Binary download verification ✗ finding is a pre-existing action-design pattern (downloads golangci-lint at runtime without in-source checksum check), unchanged from approved v9.2.0. Filed upstream as golangci/golangci-lint-action#1396 to address the underlying gap.
|
Resolution follow-up: the verify pipeline now accepts GitHub release immutability + Sigstore attestation as an equivalent trust anchor for the runtime-download finding (per maintainer @ldez's explanation in golangci/golangci-lint-action#1396). Implemented in #887: |
Bumps golangci/golangci-lint-action from 9.2.0 to 9.2.1.
Release notes
Sourced from golangci/golangci-lint-action's releases.
Commits
82606bfchore: prepare release v9.2.197c8387chore: improve workflows (#1394)28d0a19build(deps): bump the dependencies group across 1 directory with 2 updates633fbc7build(deps): bump github/codeql-action from 4.35.3 to 4.35.4 (#1391)59f43e2build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 (#1389)9eb174ebuild(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 (#1386)4f52504build(deps): bump github/codeql-action from 4 to 4.35.2 (#1384)6f87dfddocs: update examplesc9500d7chore: improve workflows03b1faachore: improve issue templates