Skip to content

ci: bump hashgraph-online/ai-plugin-scanner-action from 1.2.731 to 1.2.767 in the minor-and-patch group - #672

Merged
cdeust merged 1 commit into
mainfrom
dependabot/github_actions/minor-and-patch-955188e01a
Oct 8, 2026
Merged

cdeust merged 1 commit into
mainfrom
dependabot/github_actions/minor-and-patch-955188e01a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 1 update: hashgraph-online/ai-plugin-scanner-action.

Updates hashgraph-online/ai-plugin-scanner-action from 1.2.731 to 1.2.767

Release notes

Sourced from hashgraph-online/ai-plugin-scanner-action's releases.

v1.2.767

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/ab20104e095c2ff9e20ba1abdc982640dc4b2c3a with plugin-scanner 3.26.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.766...v1.2.767

v1.2.766

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/5af2ac7babb0c6d5dd599885278e0d0226546cf4 with plugin-scanner 3.25.2.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.765...v1.2.766

v1.2.765

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/97acff7b9afb9efba82542673a67af029451ee91 with plugin-scanner 3.25.1.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.764...v1.2.765

v1.2.764

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/4445c906db6e1aa99a3a2d68f307dce36f34a140 with plugin-scanner 3.25.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.763...v1.2.764

v1.2.763

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/f70c671b64d694af5ceb00746fb1c3153270a815 with plugin-scanner 3.24.2.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.762...v1.2.763

v1.2.762

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/41da530160ba8ab086712cd52c273f67fedaf6b5 with plugin-scanner 3.24.1.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.761...v1.2.762

v1.2.761

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/c29201e65f0ece60affc11582f352aea1cbbacc4 with plugin-scanner 3.24.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.760...v1.2.761

v1.2.760

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/71a4d31857216e9796821ceb2f4723078b12e4e5 with plugin-scanner 3.23.1.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.759...v1.2.760

v1.2.759

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/7399202ef348a022faa364d648f9a2bc95a95a87 with plugin-scanner 3.23.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.758...v1.2.759

v1.2.758

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/5ba252eaea5cb1b7814beee90059beccecbc150d with plugin-scanner 3.22.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.757...v1.2.758

... (truncated)

Commits
  • ac513da chore: publish action bundle v1.2.767 (plugin-scanner 3.26.0)
  • d0e7bf3 chore: publish action bundle v1.2.766 (plugin-scanner 3.25.2)
  • 9b911d6 chore: publish action bundle v1.2.765 (plugin-scanner 3.25.1)
  • ff6dc07 chore: publish action bundle v1.2.764 (plugin-scanner 3.25.0)
  • 9a85f17 chore: publish action bundle v1.2.763 (plugin-scanner 3.24.2)
  • bbc7770 chore: publish action bundle v1.2.762 (plugin-scanner 3.24.1)
  • 435859c chore: publish action bundle v1.2.761 (plugin-scanner 3.24.0)
  • 71e83ec chore: publish action bundle v1.2.760 (plugin-scanner 3.23.1)
  • 76aa88a chore: publish action bundle v1.2.759 (plugin-scanner 3.23.0)
  • 164f557 chore: publish action bundle v1.2.758 (plugin-scanner 3.22.0)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 1 update: [hashgraph-online/ai-plugin-scanner-action](https://github.com/hashgraph-online/ai-plugin-scanner-action).


Updates `hashgraph-online/ai-plugin-scanner-action` from 1.2.731 to 1.2.767
- [Release notes](https://github.com/hashgraph-online/ai-plugin-scanner-action/releases)
- [Commits](hashgraph-online/ai-plugin-scanner-action@89815d8...ac513da)

---
updated-dependencies:
- dependency-name: hashgraph-online/ai-plugin-scanner-action
  dependency-version: 1.2.767
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026
@cdeust

cdeust commented Oct 8, 2026

Copy link
Copy Markdown
Owner

ZETETIC-REVIEW: APPROVE
ffb340b

Cortex #672: ci: bump hashgraph-online/ai-plugin-scanner-action 1.2.731 to 1.2.767

Reviewer: code-reviewer (read-only). Stakes: Low (one-line SHA pin bump in a CI workflow, no product code). Base: 206ac67 is an ancestor of the head (git merge-base --is-ancestor).

Findings

  1. Diff (gh pr diff 672): one file, .github/workflows/hol-plugin-scanner.yml line 53, pin 89815d8b (v1.2.731) to ac513da02cd2d28e6da5593e55add3f5b4cdce1e (v1.2.767). Trailing version comment updated in the same edit. Nothing else changed.
  2. Pin equals the tag at the source: gh api repos/hashgraph-online/ai-plugin-scanner-action/git/ref/tags/v1.2.767 returns object type commit, sha ac513da02cd2d28e6da5593e55add3f5b4cdce1e (lightweight tag, so there is no annotated tag object to dereference; git/tags/<sha> returns 404 as expected). The old tag v1.2.731 resolves to 89815d8b, matching the removed line.
  3. Upstream change content (gh api .../compare/v1.2.731...v1.2.767): 36 commits, each an automated "publish action bundle" commit. action.yml is not modified. Changed files: README.md, scanner-runtime-requirements.txt and scanner-cisco-runtime-requirements.txt (each drops publicsuffixlist), scanner-sha256.txt (new digest), scanner-version.txt (plugin-scanner 3.14.0 to 3.26.0). The release body of v1.2.767 (gh release view) says only that it was published automatically from hol-guard ab20104e with plugin-scanner 3.26.0; there are no human release notes.
  4. The workflow ran on the PR head: run 37743361906 (HOL plugin scanner, success). Its log shows "Download action repository ...@ac513da02cd2d28e6da5593e55add3f5b4cdce1e" and "Successfully installed plugin-scanner-3.26.0", so the new bundle was exercised, not the old one. The plugin-scanner check run also passed.
  5. gh pr checks 672: every check pass or skipping. Skipped: Docker Build (runtime, devcontainer; path filter excludes .github/**), CodeQL, Fuzz scheduled batch, Tag a release. No CANCELLED and no failed job. gh run list --commit ffb340bf: CI, HOL plugin scanner, Fuzz, Upstream identity all completed/success.
  6. mergeStateStatus: CLEAN.
  7. Observation, not introduced by this diff: the scan log warns that pip selected yanked securesystemslib 1.5.0. The same warning appears in main's latest HOL scan run 37743064878, which used scanner 3.14.0, so it predates this PR and comes from the action's upstream pinned requirements, which are not Cortex files. Not blocking this PR; worth an upstream report if the owner wants one (I opened nothing).

Not verified

  • hol-guard's own changelog between plugin-scanner 3.14.0 and 3.26.0 (new or changed scan rules). I relied on the action-repo compare plus the empirical passing scan on this PR.
  • The SARIF upload contents and code-scanning alerts produced by 3.26.0.
  • PyPI provenance verification internals of the action (the step passed; I did not audit its script).

Merge order

Merge #672 first (one line, no dependency surface), then #673. The reverse order is equally safe: the two PRs touch disjoint files and both are based on 206ac67. Branch protection on main reports required_status_checks.strict: false and the repo has 0 rulesets, consistent with #614 merging while BEHIND today, so the second PR does not need @dependabot rebase.

@cdeust
cdeust merged commit 4a742ed into main Oct 8, 2026
25 checks passed
@cdeust
cdeust deleted the dependabot/github_actions/minor-and-patch-955188e01a branch October 8, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant