#3237 PR open: Bump redhat-plumbers-in-action/differential-shellcheck from 5.1.2 to 5.3.0

Labels: dependencies

dependabot opened issue at 2024-06-01 11:11:

Bumps redhat-plumbers-in-action/differential-shellcheck from 5.1.2 to 5.3.0.

Release notes

Sourced from redhat-plumbers-in-action/differential-shellcheck's releases.

v5.3.0

What's Changed

New

Maintenance

Other changes

  • Add mention about sarif-tools - conversion tool :turtle: (#404) @​jamacku

Full Changelog: https://github.com/redhat-plumbers-in-action/differential-shellcheck/compare/v5.2.0...v5.3.0

v5.2.0

What's Changed

New

Documentation

  • Simplify if statements in GHA workflows and in examples :duck: (#401) @​jamacku

Automation and CI changes

Dependency Updates

  • build(deps): bump redhat-plumbers-in-action/advanced-issue-labeler from 3.1.0 to 3.2.0 (#398) @​dependabot

Full Changelog: https://github.com/redhat-plumbers-in-action/differential-shellcheck/compare/v5.1.2...v5.2.0

Changelog

Sourced from redhat-plumbers-in-action/differential-shellcheck's changelog.

Changelog

Next release

v5.3.0

  • Add support for different display engines (csgrep, sarif-fmt)
  • Update csutils (csdiff) to 3.3.0
    • csdiff: match findings by line content without spaces if available
    • csgrep --hash-v1: match csdiff/v1 fingerprint prefix
    • sarif: initial implementation of csdiff/v1 fingerprints
    • sarif: add descriptions for ShellCheck rules

v5.2.0

  • Provide html output with detected defects
  • Allow specifying WORK_DIR for intermediate files
  • Update csutils (csdiff) to 3.2.2
    • propagate the imp flag as level in the SARIF format
    • propagate endLine/endColumn in the JSON and SARIF formats

v5.1.2

  • Fix curl Argument list too long by using a payload.json file - by @​mpoberezhniy
  • Container images now based on Fedora 40
  • Update csutils (csdiff) to 3.2.1

v5.1.0

  • Improve shell script detection based on emacs file mode header

v5.0.2

  • Container images now based on Fedora 39
  • Update csutils (csdiff) to 3.1.0

v5.0.0

  • Added defect statistics based on severity levels. They are available in the console output and in the job Summary page.
  • New option scan-directory. Allows to specify directories that will be scanned. By default Differential ShellCheck scans the whole repository.
  • Show more context for ShellCheck defects and fixes in console output. The defect is now shown in the context of the surrounding code.
  • Fix autodetection of shell scripts in DEBUG mode
  • Fix detection of changed files that might cause failure on paths with special characters.
  • Fix count of scanned files in job Summary when running on push event.
  • Drop support for shell-scripts input
  • Drop support for ignored-codes input
  • Update csutils (csdiff) to 3.0.4

v4.2.2

... (truncated)

Commits
  • 60c9f2b v5.3.0
  • c6f8c3e update CHANGELOG
  • ed794da test: fix is_github_actions() test
  • 4510914 doc: update CHANGELOG
  • aba7ca1 feat: update to csdiff 3.3.0
  • 1c1e617 doc: update image resolution
  • cb3a8c3 test: generate_SARIF()
  • c8739cb test: is_github_actions()
  • fea9835 test: use function to check if scripts run in unit tests environment
  • 5665c85 feat: add support for different display engines
  • Additional commits viewable in compare view


Dependabot compatibility
score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

[Export of Github issue for rear/rear.]