SASTBot: Monthly dependency updates for 18.3
What does this MR do?
- upgrade
Gitleaks
version [8.25.1
=>8.28.0
] - upgrade
github.com/urfave/cli/v2
version [v2.27.6
=>v2.27.7
] - upgrade
gitlab.com/gitlab-org/security-products/analyzers/command/v3
version [v3.2.0
=>v3.3.2
] - upgrade
gitlab.com/gitlab-org/security-products/analyzers/report/v5
version [v5.10.0
=>v5.13.1
]
For SpotBugs, consider whether this change needs to be manually backported to the v5 branch since it's still used by the majority of GitLab 18.x users. More context can be found in this issue.
CHANGELOG is generated by SASTBot.
What are the relevant issue numbers?
- +
Does this MR meet the acceptance criteria?
-
Changelog entry added -
Documentation created/updated for GitLab EE, if necessary -
Documentation created/updated for this project, if necessary -
Documentation reviewed by technical writer or follow-up review issue created -
Tests added for this feature/bug -
Job definition updated, if necessary -
Conforms to the code review guidelines -
Conforms to the Go guidelines -
Security reports checked/validated by reviewer
Edited by Craig Smith