Skip to content

SASTBot: Monthly dependency updates for 15.10

Ghost User requested to merge dependabot-3-2023 into main

What does this MR do?

  • upgrade Semgrep version [1.3.0 => 1.14.0]
  • go modules updates
    • upgrade github.com/stretchr/testify version [v1.8.1 => v1.8.2]
    • upgrade github.com/urfave/cli/v2 version [v2.23.7 => v2.25.0]
    • upgrade gitlab.com/gitlab-org/security-products/analyzers/report/v3 version [v3.17.0 => v3.18.0]
    • upgrade gitlab.com/gitlab-org/security-products/analyzers/ruleset version [v1.4.0 => v1.4.1]
    • upgrade golang.org/x/crypto version [v0.5.0 => v0.7.0]
  • update QA expectation artifacts
  • add engine_kind to the exclusion during semgrep_rules_check

Note: Changelog is autogenerated by SASTBot.

What are the relevant issue numbers?

Does this MR meet the acceptance criteria?

Edited by Vishwa Bhat

Merge request reports