Skip to content

build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 - #574

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/anchore/sbom-action-0.24.1
Closed

build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2#574
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/anchore/sbom-action-0.24.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026

Copy link
Copy Markdown

Bumps anchore/sbom-action from 0.24.0 to 0.24.2.

Release notes

Sourced from anchore/sbom-action's releases.

v0.24.2

Added Features

Additional Changes

(Full Changelog)

Commits
  • 3ad7283 ops: update write permissions for release (#723)
  • 31f5287 chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#724)
  • aa80c8c chore(deps): update Syft to latest release (#722)
  • 74b54e9 chore(deps): bump lodash from 4.17.23 to 4.18.1 (#623)
  • 6b92ff5 chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#721)
  • 4f8983b chore(deps-dev): bump typescript-eslint from 8.65.0 to 8.67.0 (#719)
  • 10f27f4 chore(deps-dev): bump eslint from 10.5.0 to 10.8.1 (#720)
  • 249403a chore(deps-dev): bump @​types/node from 26.1.0 to 26.2.0 (#718)
  • cbf8daa chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#693)
  • 6afc793 fix: pin syft install.sh to the release tag being installed (#716)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 30, 2026
@dependabot
dependabot Bot requested a review from pdfinn as a code owner August 30, 2026 02:18
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 30, 2026
@dependabot dependabot Bot changed the title build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.1 build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2 Aug 31, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/anchore/sbom-action-0.24.1 branch from 0f8e689 to f8edfde Compare August 31, 2026 03:36
@pdfinn

pdfinn commented Aug 31, 2026

Copy link
Copy Markdown
Member

The Fuzz (PR) failure on this PR is not caused by it. ClusterFuzzLite has
been red on master since #570 (2026-08-29) — libinterp/load.c now calls
freejitcode(), which is defined only in comp-amd64.c / comp-arm64.c,
and .clusterfuzzlite/build.sh links load.c alone. The fuzzers fail to
link, so "Building fuzzers failed".

The code PRs opened before that still show green because they are based on
older master; the dependabot PRs are based on current master, which is why
they show it. Nothing to do here.

Details and a proposed fix are in the issue I am filing for it.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/anchore/sbom-action-0.24.1 branch from f8edfde to 040837a Compare September 1, 2026 08:06
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.24.0 to 0.24.2.
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@e22c389...3ad7283)

---
updated-dependencies:
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/anchore/sbom-action-0.24.1 branch from 040837a to 95f1276 Compare September 2, 2026 06:56
@dependabot @github

dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Author

Superseded by #590.

@dependabot dependabot Bot closed this Sep 6, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/anchore/sbom-action-0.24.1 branch September 6, 2026 02:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant