Skip to content

SASTBot: Monthly dependency updates for 18.3

What does this MR do?

  • upgrade Gitleaks version [8.25.1 => 8.28.0]
  • upgrade github.com/urfave/cli/v2 version [v2.27.6 => v2.27.7]
  • upgrade gitlab.com/gitlab-org/security-products/analyzers/command/v3 version [v3.2.0 => v3.3.2]
  • upgrade gitlab.com/gitlab-org/security-products/analyzers/report/v5 version [v5.10.0 => v5.13.1]

For SpotBugs, consider whether this change needs to be manually backported to the v5 branch since it's still used by the majority of GitLab 18.x users. More context can be found in this issue.

CHANGELOG is generated by SASTBot.

What are the relevant issue numbers?

  • +

Does this MR meet the acceptance criteria?

Edited by Craig Smith

Merge request reports

Loading