Skip to content

SASTBot: Monthly dependency updates for 15.9

Ghost User requested to merge dependabot-2-2023 into main

What does this MR do?

  • upgrade Semgrep version [1.3.0 => 1.13.0]
  • update Semgrep scanner to v1.13.0
  • update Go dependency modules
    • upgrade github.com/urfave/cli/v2 version [v2.23.7 => v2.24.3]
    • upgrade golang.org/x/crypto version [v0.5.0 => v0.6.0]
  • remove a newly introduced but unused field from semgrep.sarif in the rule check
  • update expectation artifact for python - multi-project

Note: Changelog is autogenerated by SASTBot.

What are the relevant issue numbers?

Does this MR meet the acceptance criteria?

Edited by Lucas Charles

Merge request reports