Skip to content

Bump Afterlife-Guide/SemVer.Action from 1.1.1.16 to 1.2.2.14#194

Closed
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/github_actions/Afterlife-Guide/SemVer.Action-1.2.2.14
Closed

Bump Afterlife-Guide/SemVer.Action from 1.1.1.16 to 1.2.2.14#194
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/github_actions/Afterlife-Guide/SemVer.Action-1.2.2.14

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 7, 2025

Bumps Afterlife-Guide/SemVer.Action from 1.1.1.16 to 1.2.2.14.

Release notes

Sourced from Afterlife-Guide/SemVer.Action's releases.

1.2.2.14

What's Changed

Full Changelog: Afterlife-Guide/SemVer.Action@1.2.1.19...1.2.2.14

1.2.1.19

What's Changed

Full Changelog: Afterlife-Guide/SemVer.Action@1.2.0.13...1.2.1.19

1.2.0.13

What's Changed

... (truncated)

Changelog

Sourced from Afterlife-Guide/SemVer.Action's changelog.

[1.2.2.14] - 2025-11-07

[1.2.1.19] - 2025-09-09

Changed

  • Reverted Docker non-root (#240)

[1.2.0.13] - 2025-09-08

Fixed

  • Fixed security vulnerability by preventing direct use of user-controlled data in workflow run blocks to prevent command injection

Changed

  • Migrated from thomaseizinger/keep-a-changelog-new-release to baynezy/ChangeLogger.Action (#210)
  • Added GH_TOKEN environment variable to all GitHub Action workflows for consistent token access (#215)
  • Set up copilot environment (#225)
  • Updated Dockerfile to use uppercase 'AS' in multi-stage builds for SonarQube compliance (#229)

Fixed

  • Reduced Information logging calls in WriteJsonCommand.cs to comply with SonarQube rule S6664 (#230)

Security

  • Updated all external GitHub Actions to use full commit SHA hashes instead of version tags for improved security (#235)
  • Updated Docker image to run as non-root user instead of root user to improve security posture (#233)
Commits
  • 9102e86 Merge pull request #274 from Afterlife-Guide/release/1.2.2.14
  • 8d86d83 Prepare release 1.2.2.14
  • f7d25f6 Merge pull request #273 from Afterlife-Guide/feature/issue-0-revert
  • 3950902 Revert "Enable non-root access to workspace files"
  • edddda9 Merge pull request #272 from Afterlife-Guide/dependabot/nuget/test/SemVer.Jso...
  • cd0fd16 Bump the verify group with 1 update
  • 412fe10 Merge pull request #271 from Afterlife-Guide/dependabot/nuget/test/SemVer.Jso...
  • aba85f1 Bump the verify group with 1 update
  • d7789bb Merge pull request #270 from Afterlife-Guide/dependabot/nuget/test/SemVer.Jso...
  • f41f9d2 Bump the verify group with 1 update
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [Afterlife-Guide/SemVer.Action](https://github.com/afterlife-guide/semver.action) from 1.1.1.16 to 1.2.2.14.
- [Release notes](https://github.com/afterlife-guide/semver.action/releases)
- [Changelog](https://github.com/Afterlife-Guide/SemVer.Action/blob/develop/CHANGELOG.md)
- [Commits](Afterlife-Guide/SemVer.Action@1.1.1.16...1.2.2.14)

---
updated-dependencies:
- dependency-name: Afterlife-Guide/SemVer.Action
  dependency-version: 1.2.2.14
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Nov 7, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Nov 7, 2025

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Nov 19, 2025

Superseded by #203.

@dependabot dependabot bot closed this Nov 19, 2025
@dependabot dependabot bot deleted the dependabot/github_actions/Afterlife-Guide/SemVer.Action-1.2.2.14 branch November 19, 2025 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 min review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants