Skip to content

poutine 0.17.0#220640

Merged
BrewTestBot merged 2 commits intomasterfrom
bump-poutine-0.17.0
Apr 18, 2025
Merged

poutine 0.17.0#220640
BrewTestBot merged 2 commits intomasterfrom
bump-poutine-0.17.0

Conversation

@BrewTestBot
Copy link
Contributor

Created by brew bump


Created with brew bump-formula-pr.

Details

release notes
# Changelog for `poutine` v0.17.0 🎉🎂

Happy 1st Anniversary to poutine! We're thrilled to mark this milestone with a significant release packed with new capabilities and improvements.

New Features 🌟

  • 🚀 Groundbreaking Stale Branch Analysis: Introduced by @Talgarr, newest full time member of our Security Research team, this highly efficient stale branches scanner helps uncover potentially exploitable pull_request_target vulnerabilities lurking in forgotten branches, even if they've been patched in the default branch. (#285)
  • Enhanced LOTP Analysis: Added support for many more Living Off The Pipeline (LOTP) tools, contributed by @Talgarr. (#286)

Improvements 🔧

  • Optimized Skip Rule Logic: Refined the logic for skipping rules during analysis for better performance and accuracy. (#287)
  • Linter Migration: Completed migration to a new linter setup as part of ongoing code quality efforts. (#284)

Dependency Updates ⬆️

GitHub Actions

  • Updated ossf/scorecard-action from v2.4.0 to v2.4.1. (#268)
  • Updated step-security/harden-runner from v2.10.4 to v2.11.0. (#270)
  • Updated github/codeql-action from v3.28.8 to v3.28.13. (#281)
  • Updated goreleaser/goreleaser-action from v6.1.0 to v6.3.0. (#282)

Go Libraries

  • Updated Go language version to 1.24. (#284)
  • Updated github.com/spf13/cobra from v1.8.1 to v1.9.1. (#275)
  • Updated github.com/open-policy-agent/opa from v1.1.0 to v1.3.0. (#277)
  • General dependency updates. (#284)

New Contributors 👋

  • Welcome @Talgarr from our Security Research team, making their first direct code contribution to the poutine repository (#285)! @Talgarr has been a major contributor to the related LOTP project, significantly influencing rule improvements in this release.

Full Changelog 📜

For a detailed view of all changes, see the full changelog.

@github-actions github-actions bot added go Go use is a significant feature of the PR or issue bump-formula-pr PR was created using `brew bump-formula-pr` labels Apr 18, 2025
@github-actions
Copy link
Contributor

🤖 An automated task has requested bottles to be published to this PR.

Please do not push to this PR branch before the bottle commits have been pushed, as this results in a state that is difficult to recover from. If you need to resolve a merge conflict, please use a merge commit. Do not force-push to this PR branch.

@github-actions github-actions bot added the CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. label Apr 18, 2025
@BrewTestBot BrewTestBot enabled auto-merge April 18, 2025 20:40
@BrewTestBot BrewTestBot added this pull request to the merge queue Apr 18, 2025
Merged via the queue into master with commit 30a005e Apr 18, 2025
17 checks passed
@BrewTestBot BrewTestBot deleted the bump-poutine-0.17.0 branch April 18, 2025 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bump-formula-pr PR was created using `brew bump-formula-pr` CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. go Go use is a significant feature of the PR or issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants