Releases: step-security/action-semantic-pull-request
Releases · step-security/action-semantic-pull-request
v6.1.1
What's Changed
- fix: Update auto_cherry_pick.yml by @Raj-StepSecurity in #126
- ci: added claude review workflow by @amanstep in #128
- chore: Cherry-picked changes from upstream by @github-actions[bot] in #127
- fix: Update auto_cherry_pick.yml by @Raj-StepSecurity in #129
- ci: provided node version as input for auto cherry pick by @amanstep in #131
- chore: Cherry-picked changes from upstream by @github-actions[bot] in #132
- chore: Cherry-picked changes from upstream by @github-actions[bot] in #134
- chore: Cherry-picked changes from upstream by @github-actions[bot] in #135
- fix: Security updates by @github-actions[bot] in #142
- fix: fixed subscription check code by @amanstep in #143
- fix: removed package manager property from package.json by @amanstep in #144
New Contributors
Full Changelog: v5...v6.1.1
v5.5.6
What's Changed
- fix: Bump axios to 1.8.2 by @Raj-StepSecurity in #98
- fix: included mit license terms by @Raj-StepSecurity in #99
- fix: auto cherry pick workflow added by @Raj-StepSecurity in #100
- fix: author and repo updated by @Raj-StepSecurity in #102
- fix: apply audit fixes by @github-actions[bot] in #103
- fix: [StepSecurity] Apply security best practices by @stepsecurity-app[bot] in #104
- fix: Security updates by @github-actions[bot] in #109
- ci: add guarddog security scanning workflow by @Raj-StepSecurity in #111
- fix: update auto_cherry_pick.yml by @Raj-StepSecurity in #114
- fix: Security updates by @github-actions[bot] in #120
- fix: Security updates by @github-actions[bot] in #124
New Contributors
- @stepsecurity-app[bot] made their first contribution in #104
Full Changelog: v5...v5.5.6
v5.5.5
What's Changed
- fix: Apply Yarn audit fix
by @github-actions in #88 - fix: update audit package cron to handle build script commit name by @Raj-StepSecurity in #89
- fix: manually resolved vulnerabilities by @Raj-StepSecurity in #91
Full Changelog: v5...v5.5.5
v5.5.4
What's Changed
- Create osv-scanner.toml by @varunsh-coder in #64
- fix: resolve vulnerabilities and audit dependencies by @Raj-StepSecurity in #80
- build: rebuild dist folder by @Raj-StepSecurity in #82
- fix: Fix revert main by @Raj-StepSecurity in #84
- fix: Fix vulnerabilities through workflow by @Raj-StepSecurity in #85
- fix: Apply Yarn audit fix
by @github-actions in #86
New Contributors
- @Raj-StepSecurity made their first contribution in #80
- @github-actions made their first contribution in #86
Full Changelog: v5...v5.5.4
v5.5.3
What's Changed
- chore(deps): Bump actions/dependency-review-action from 4.3.2 to 4.3.4 by @dependabot in #39
- feat: Fast-Forward upstream changes by @shubham-stepsecurity in #42
- chore: update dist folder by @shubham-stepsecurity in #47
Full Changelog: v5...v5.5.3
v5.4.0
What's Changed
- chore(deps): Bump actions/checkout from 3 to 4 by @dependabot in #6
- chore: upgrading dependencies by @ashishkurmi in #23
- chore(deps): Bump ossf/scorecard-action from 2.0.6 to 2.3.3 by @dependabot in #34
- chore(deps): Bump actions/dependency-review-action from 2.5.1 to 4.3.2 by @dependabot in #31
- chore(deps): Bump actions/upload-artifact from 3.1.3 to 4.3.3 by @dependabot in #29
- chore(deps): Bump braces from 3.0.2 to 3.0.3 by @dependabot in #36
- chore(deps): Bump undici from 5.28.3 to 5.28.4 by @dependabot in #37
- chore: match the tags from the upstream forks by @shubham-stepsecurity in #35
- chore(deps): Bump follow-redirects from 1.15.5 to 1.15.6 by @dependabot in #41
- chore: update release workflow by @shubham-stepsecurity in #43
New Contributors
- @dependabot made their first contribution in #6
- @ashishkurmi made their first contribution in #23
- @shubham-stepsecurity made their first contribution in #35
Full Changelog: v1...v5.4.0
v1.0.1
What's Changed
- chore: add security policy by @varunsh-coder in #13
- feat: Add logic to validate subscription by @varunsh-coder in #15
Full Changelog: v1...v1.0.1
v1.0.0
Merge pull request #2 from step-security-bot/stepsecurity_remediation…