#3062 PR open: Bump redhat-plumbers-in-action/differential-shellcheck from 4.2.2 to 5.0.1

Labels: dependencies

dependabot opened issue at 2023-11-01 11:47:

Bumps redhat-plumbers-in-action/differential-shellcheck from 4.2.2 to 5.0.1.

Release notes

Sourced from redhat-plumbers-in-action/differential-shellcheck's releases.

v5.0.1

What's Changed

Bug Fixes

Full Changelog: https://github.com/redhat-plumbers-in-action/differential-shellcheck/compare/v5.0.0...v5.0.1

v5.0.0

What's Changed

Breaking

New

  • Show more context for ShellCheck defects and fixes in console output :floppy_disk: (#300) @​jamacku
  • Add support for subdirectory scanning :file_folder: (#294) @​jamacku
  • Add Statistics of defect severities :bar_chart: (#233) @​jamacku
  • Show scanned files in console by default 📜 (#285) @​jamacku

Bug Fixes

  • Fix autodetection of shell scripts in DEBUG mode :kiwi_fruit: (#299) @​jamacku
  • Always gather defect statistics :chart_with_downwards_trend: (#298) @​jamacku
  • Fix count of scanned files in job Summary when running on push event :1234: (#297) @​jamacku
  • Set correct version of ShellCheck in SARIF :coconut: (#296) @​jamacku
  • fix: detection of changed files that might cause failure on some paths :lollipop: (#286) @​jamacku

Maintenance

Documentation

Automation and CI changes

Dependency Updates

... (truncated)

Changelog

Sourced from redhat-plumbers-in-action/differential-shellcheck's changelog.

Changelog

Next release

v5.0.0

  • Added defect statistics based on severity levels. They are available in the console output and in the job Summary page.
  • New option scan-directory. Allows to specify directories that will be scanned. By default Differential ShellCheck scans the whole repository.
  • Show more context for ShellCheck defects and fixes in console output. The defect is now shown in the context of the surrounding code.
  • Fix autodetection of shell scripts in DEBUG mode
  • Fix detection of changed files that might cause failure on paths with special characters.
  • Fix count of scanned files in job Summary when running on push event.
  • Drop support for shell-scripts input
  • Drop support for ignored-codes input
  • Update csutils (csdiff) to 3.0.4

v4.2.2

  • Container images now based on Fedora 38
    • ShellCheck - 0.8.0 -> 0.9.0
    • csutils - 3.0.0 -> 3.0.2

v4.2.1

  • Handle multiple include/exclude paths with newlines

v4.2.0

  • New option exclude-path. Allows to specify list of paths excluded from ShellCheck scanning. It supports globbing and brace expansion. e.g. test/{test1,test2}/**
  • New option include-path. Similar to exclude-path, it allows specifying the list of paths that will be included into scanning. No further checks are performed. It supports globbing and brace expansion. e.g. fixture/**.fixture

v4.1.0

  • grep - do not escape # and ! in patterns
  • Utilize DEBUG to run grep without --silent option
  • Update csutils (csdiff) to 3.0.0

v4.0.2

  • Correctly handle character escaping in filenames (e.g. and &)
  • Improve documentation and more tests

v4.0.0

  • Tag latest is no longer available. Use major tags instead (e.g. v3 or v4).

  • Action can be triggered using GitHub push event

    on:
    

... (truncated)

Commits
  • aa647ec v5.0.1
  • 3dfdfcf fix: uninitialized variable RUNNER_DEBUG
  • 98b3935 fix: drop support for DEBUG in grep
  • c9cc531 fix: incorrect log about fixed issues
  • 0b37fe0 v5.0.0
  • b392c11 deps: use the correct version of super-linter
  • 9988647 deps: add comment with pinned version
  • a58af3b deps: update csutils (csdiff and csgrep) to 3.0.4
  • dc2f863 doc: fix format of warning message
  • e0416c5 doc: add example.sh for testing purposes
  • Additional commits viewable in compare view


Dependabot compatibility
score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

[Export of Github issue for rear/rear.]