Skip to content

chore(deps): bump LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml from 1.66.3 to 1.74.1 - #152

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/develop/LerianStudio/github-actions-shared-workflows/dot-github/workflows/pr-security-scan.yml-1.74.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/develop/LerianStudio/github-actions-shared-workflows/dot-github/workflows/pr-security-scan.yml-1.74.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor

Bumps LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml from 1.66.3 to 1.74.1.

Release notes

Sourced from LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml's releases.

v1.74.1

Github-actions-shared-workflows v1.74.1

Fixes:

  • Merged changes from develop to main to ensure the latest updates are reflected in the main branch. (@​bedatty)
  • Updated the pull request validation workflow to request a review when the overall verdict passes, but a specific job fails. This ensures that potential issues are flagged for review even if the overall status is successful. (@​bedatty)

Improvements:

  • Scoped the always() rule specifically to the two-job shape in the coderabbit-gate documentation, providing clearer guidance on its application. (@​bedatty)

Compare changes

v1.74.1-beta.1

No release notes provided.

v1.74.0

Github-actions-shared-workflows v1.74.0

Features:

  • Compute the review verdict from a needs context in the coderabbit-gate. (@​bedatty)
  • Gate CodeRabbit on the analysis verdict in go-pr-validation. (@​bedatty)
  • Keep the end-to-end suite out of the CodeRabbit verdict in js-pr-validation. (@​bedatty)

Improvements:

  • Move the agent rules to .agents/skills and drop the cursor rules. (@​bedatty)

Documentation:

  • Document the analysis verdict output in go-pr-validation. (@​bedatty)
  • Specify which jobs the analysis verdict covers in go-pr-validation. (@​bedatty)

Compare changes

v1.74.0-beta.4

No release notes provided.

v1.74.0-beta.3

No release notes provided.

v1.74.0-beta.2

No release notes provided.

v1.74.0-beta.1

No release notes provided.

v1.73.0

Github-actions-shared-workflows v1.73.0

Features:

... (truncated)

Changelog

Sourced from LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml's changelog.

Github-actions-shared-workflows Changelog

1.74.2

Fixes:

  • Addressed the issue of paginating all Socket app check runs before evaluating them to ensure proper handling of large datasets. (@​fredcamaral)

Improvements:

  • Updated azure/setup-helm action from version 4.3.0 to 5.0.1 to incorporate the latest features and improvements. (@​bedatty)
  • Bumped the github-security group across one directory with four updates to enhance security measures. (@​bedatty)

Compare changes


1.74.1

Fixes:

  • Merged changes from develop to main to ensure the latest updates are reflected in the main branch. (@​bedatty)
  • Updated the pull request validation workflow to request a review when the overall verdict passes, but a specific job fails. This ensures that potential issues are flagged for review even if the overall status is successful. (@​bedatty)

Improvements:

  • Scoped the always() rule specifically to the two-job shape in the coderabbit-gate documentation, providing clearer guidance on its application. (@​bedatty)

Compare changes


1.74.0

Features:

  • Compute the review verdict from a needs context in the coderabbit-gate. (@​bedatty)
  • Gate CodeRabbit on the analysis verdict in go-pr-validation. (@​bedatty)
  • Keep the end-to-end suite out of the CodeRabbit verdict in js-pr-validation. (@​bedatty)

Improvements:

  • Move the agent rules to .agents/skills and drop the cursor rules. (@​bedatty)

Documentation:

  • Document the analysis verdict output in go-pr-validation. (@​bedatty)
  • Specify which jobs the analysis verdict covers in go-pr-validation. (@​bedatty)

Compare changes


1.73.0

... (truncated)

Commits
  • 0e9b600 fix(release): develop to main (#812)
  • 24e8d43 fix(pr-validation): request the review when the verdict passes but a job fail...
  • 41fbcd1 docs(coderabbit-gate): scope the always() rule to the two-job shape
  • bfa944a fix(pr-validation): request the review when the verdict passes but a job failed
  • c5e62f7 chore(release): backmerge main into develop [backmerge]
  • 7714072 chore(release): Update CHANGELOGs for github-actions-shared-workflows:v1.74.0...
  • 026dfd0 feat(release): develop to main (#809)
  • 4b0f549 chore(agents): move the agent rules to .agents/skills and drop the cursor rul...
  • 990602c chore(agents): move the agent rules to .agents/skills and drop the cursor rules
  • 760b22b feat(coderabbit-gate): compute the review verdict from a needs context (#807)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…b/workflows/pr-security-scan.yml

Bumps [LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml](https://github.com/lerianstudio/github-actions-shared-workflows) from 1.66.3 to 1.74.1.
- [Release notes](https://github.com/lerianstudio/github-actions-shared-workflows/releases)
- [Changelog](https://github.com/LerianStudio/github-actions-shared-workflows/blob/main/CHANGELOG.md)
- [Commits](LerianStudio/github-actions-shared-workflows@a3e72f6...0e9b600)

---
updated-dependencies:
- dependency-name: LerianStudio/github-actions-shared-workflows/.github/workflows/pr-security-scan.yml
  dependency-version: 1.74.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added ci Continuous integration pipelines deps Go module dependencies (usually opened by Dependabot) labels Sep 22, 2026
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 56a4559b-a3b1-441a-99dc-a04f29e6b7dd

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added size/XS PR changes < 50 lines and removed deps Go module dependencies (usually opened by Dependabot) labels Sep 22, 2026
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🔍 PR Validation Summary

🚫 PR Blocked — 2 blocking failures

Check Status Blocking
Source Branch ❌ failure yes
PR Title ✅ success yes
PR Description ✅ success yes
Breaking Change Guard ✅ success yes
Blocking Checks Runtime ❌ failure yes
Commit Signatures ✅ success yes
PR Size ⏭️ skipped no
Auto Labels ⏭️ skipped no
PR Metadata ⏭️ skipped no

Fix the blocking checks above before merge.


🔍 View workflow run

@lerian-studio

Copy link
Copy Markdown
Contributor

🔒 Security Scan Results — lib-streaming

✅ PR Mergeable — no blocking findings

Stage Status Blocking?
Filesystem Scan ✅ Clean —
Docker Image Scan ➖ Skipped —
Docker Hub Health Score ➖ Skipped —
Pre-release Version Check ✅ Clean —

Trivy

Filesystem Scan

✅ No vulnerabilities or secrets found.


Pre-release Version Check

✅ No unstable version pins found.


🔍 View full scan logs

@lerian-studio

Copy link
Copy Markdown
Contributor

📊 Unit Test Coverage Report: app

Metric Value
Overall Coverage 86.8% ✅ PASS
Threshold 80%

Coverage by Package

Package Coverage
github.com/LerianStudio/lib-streaming/v4/billing 97.3%
github.com/LerianStudio/lib-streaming/v4/internal/cloudevents 93.7%
github.com/LerianStudio/lib-streaming/v4/internal/config 86.8%
github.com/LerianStudio/lib-streaming/v4/internal/consumer 92.3%
github.com/LerianStudio/lib-streaming/v4/internal/contract 85.0%
github.com/LerianStudio/lib-streaming/v4/internal/dlqheader 40.0%
github.com/LerianStudio/lib-streaming/v4/internal/emitter 100.0%
github.com/LerianStudio/lib-streaming/v4/internal/kafkasec 84.9%
github.com/LerianStudio/lib-streaming/v4/internal/manifest 84.0%
github.com/LerianStudio/lib-streaming/v4/internal/producer 89.1%
github.com/LerianStudio/lib-streaming/v4/internal/transport/eventbridge 87.3%
github.com/LerianStudio/lib-streaming/v4/internal/transport/kafka 56.4%
github.com/LerianStudio/lib-streaming/v4/internal/transport/rabbitmq 93.2%
github.com/LerianStudio/lib-streaming/v4/internal/transport/sqs 84.4%
github.com/LerianStudio/lib-streaming/v4/internal/transport 96.7%
github.com/LerianStudio/lib-streaming/v4/streamingtest 90.7%
github.com/LerianStudio/lib-streaming/v4 86.2%

Generated by Go PR Analysis workflow

Base automatically changed from develop to main September 23, 2026 11:38
@github-actions

Copy link
Copy Markdown

⚠️ Invalid Source Branch

Pull requests to main can only come from:

  • develop
  • release-candidate
  • hotfix/*

Your source branch: dependabot/github_actions/develop/LerianStudio/github-actions-shared-workflows/dot-github/workflows/pr-security-scan.yml-1.74.1

Please change the base branch or create a PR from an allowed branch.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Continuous integration pipelines size/XS PR changes < 50 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant