build(deps): bump google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc - #595
Conversation
dc8c472 to
34940f9
Compare
81cef29 to
c65bbb5
Compare
|
Warning Review limit reached
Next review available in: 23 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughOSV 스캐너 작업이 upstream 재사용 워크플로의 고정 커밋을 새 SHA로 변경합니다. 실행 조건, 권한 및 입력 설정은 유지됩니다. ChangesOSV 스캐너 워크플로
Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/osv-scanner-pr.yml:
- Line 42: Update the comments on lines 37–41 adjacent to the osv-scanner
reusable workflow reference to describe commit
9fd1bcce27f67e3bd819a0a7620e332803dc43bc and its actual v2.3.8 behavior. Align
the export-results and nested pin descriptions with this pinned upstream
revision, while leaving the workflow reference unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: e9047c2e-4f3c-4e3c-9fa9-76ab70ea3b27
📒 Files selected for processing (1)
.github/workflows/osv-scanner-pr.yml
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
144699c to
543313e
Compare
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
A newer version of google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
2872531 to
30f645a
Compare
seonghobae
left a comment
There was a problem hiding this comment.
Reviewed the rebased current head. The change remains limited to the SHA-pinned upstream OSV reusable workflow and accurate adjacent provenance comments; the prior review thread is resolved and no actionable feedback remains.
…nner-reusable-pr.yml Bumps [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc. - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@3a7550f...9fd1bcc) --- updated-dependencies: - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: a82132c0bd6c7261ffcb78e754c46c70ab57ad9a dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
9c45e4f to
5ad3553
Compare
Bumps google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml from 3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 to 9fd1bcce27f67e3bd819a0a7620e332803dc43bc.
Commits
9fd1bccMerge pull request #138 from google/fix/gotoolchain-auto01a87d5fix: add GOTOOLCHAIN=auto env to osv-scanner callsa82132cMerge pull request #135 from google/fix-zizmor-excessive-permissions272ff57fix: address zizmor template injection warnings10621fbrefactor: move permissions to job level to satisfy zizmorfa4ff67Merge pull request #131 from BeyondEvil/feat/add-runs-on-inpute3f946afeat: add runs-on input to reusable workflowsb8ac13fMerge pull request #127 from SVilgelm/patch-105957d4Merge pull request #130 from google/gate-outputs-with-flag-20260519f6fb127Pin download-artifact action to SHASummary by CodeRabbit