Skip to content

deps(actions)(deps): bump MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml from 2.1.0 to 2.1.1 in the third-party-actions-minor-patch group across 1 directory - #1984

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/third-party-actions-minor-patch-4dc0ca9a3a
Open

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the third-party-actions-minor-patch group with 1 update in the / directory: MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml.

Updates MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml from 2.1.0 to 2.1.1

Release notes

Sourced from MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml's releases.

2.1.1

@​metamask/action-code-scanner-github

Added

  • Add .github/ as a workspace package for workflow versioning

Changed

  • Use token exchange for release publishing instead of GITHUB_TOKEN
  • Grant workflows: write permission in onboarding workflow

Fixed

  • Update onboarding workflow to grant write permission for workflows (#92)
  • Fix: slack action (#95)
  • fix: resource not accessible by integration
  • Fix Slack webhook configuration to use webhook-type input instead of deprecated SLACK_WEBHOOK_TYPE env var
  • Add actions: read permission to zizmor job to fix "resource not accessible by integration" errors in private repositories
Changelog

Sourced from MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[2.1.1]

Added

  • Add .github/ as a workspace package for workflow versioning

Changed

  • Use token exchange for release publishing instead of GITHUB_TOKEN
  • Grant workflows: write permission in onboarding workflow

Fixed

  • Fix Slack webhook configuration to use webhook-type input instead of deprecated SLACK_WEBHOOK_TYPE env var
  • Add actions: read permission to the zizmor job to fix "resource not accessible by integration" errors in private repositories

[2.1.0]

Added

  • Add zizmor static analysis of GitHub Actions workflows

Fixed

  • Addressed zizmor findings

[2.0.5]

Added

  • feat: add rule to catch npx usage in JS/TS/YAML

Fixed

  • fix: add .security-scanner directory to ignored paths

[2.0.4]

Changed

  • Updated language detector to remove Javascript as fallback default language

... (truncated)

Commits
  • becb242 2.1.1 (#99)
  • 241152c chore: Add MetaMask/core-platform as co-owner to CODEOWNERS file (#100)
  • f6b7fda fix: fix changelog (#98)
  • 21274fc add missing changelog (#97)
  • 2779d1f Fix: slack action (#95)
  • d46d169 fix SLACK_WEBHOOK_TYPE to lowercase in workflow files (#94)
  • 737eb37 Merge pull request #92 from MetaMask/onboarding-automation-permissions-fix
  • e43c3d2 Merge pull request #93 from MetaMask/mrtenz/use-token-exchange-for-release
  • 4a31b66 Fix contents permission in main.yml
  • 3bd10d5 ci: use token exchange for release workflow
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Jul 13, 2026
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@dependabot dependabot Bot changed the title deps(actions)(deps): bump MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml from 2.1.0 to 2.1.1 in the third-party-actions-minor-patch group deps(actions)(deps): bump MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml from 2.1.0 to 2.1.1 in the third-party-actions-minor-patch group across 1 directory Jul 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/third-party-actions-minor-patch-4dc0ca9a3a branch 3 times, most recently from 6cbf53e to 5ede36f Compare July 27, 2026 03:06
…ub/workflows/security-scan.yml

Bumps the third-party-actions-minor-patch group with 1 update in the / directory: [MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml](https://github.com/metamask/action-security-code-scanner).


Updates `MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/metamask/action-security-code-scanner/releases)
- [Changelog](https://github.com/MetaMask/action-security-code-scanner/blob/main/CHANGELOG.md)
- [Commits](MetaMask/action-security-code-scanner@ff5edd4...becb242)

---
updated-dependencies:
- dependency-name: MetaMask/action-security-code-scanner/.github/workflows/security-scan.yml
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: third-party-actions-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/third-party-actions-minor-patch-4dc0ca9a3a branch from 5ede36f to 3dcdb60 Compare August 3, 2026 03:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants