chore(deps): bump sigstore/gh-action-sigstore-python from 3.4.0 to 3.5.0 - #560
Conversation
Bumps [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) from 3.4.0 to 3.5.0. - [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases) - [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/gh-action-sigstore-python@v3.4.0...v3.5.0) --- updated-dependencies: - dependency-name: sigstore/gh-action-sigstore-python dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
🤖 Claude Code ReviewPR Code ReviewScope: Single-line diff bumping Code Quality
Testing
Documentation
Security
SummaryThis is a clean, low-risk automated dependency bump with no defects. Nothing blocking. The only forward-looking suggestion (not required for this PR) is to consider pinning third-party GitHub Actions to commit SHAs instead of version tags across the workflow for stronger supply-chain integrity — but that's a repo-wide convention question, not something to fix in a single Dependabot bump. Verdict: ✅ ApproveAutomated code review analyzing defects and coding standards |
Super-linter summary
All files and directories linted successfully For more information, see the GitHub Actions workflow run Powered by Super-linter |
Coverage reportClick to see where and how coverage changed
This report was generated by python-coverage-comment-action |
||||||||||||||||||||||||||||||
…-sigstore-python-3.5.0
🤖 Claude Code ReviewPR Code ReviewThis PR is a single-line version bump: Code Quality
Testing
Documentation
Security
One note (not blocking)The action is pinned by tag ( Overall: ✅ Approve. This is a routine, low-risk dependency version bump (likely from Dependabot) with no functional or security concerns.Automated code review analyzing defects and coding standards |
Bumps sigstore/gh-action-sigstore-python from 3.4.0 to 3.5.0.
Release notes
Sourced from sigstore/gh-action-sigstore-python's releases.
Commits
790bc6bbuild(deps): bump github/codeql-action/upload-sarif in the actions group (#445)513a149build(deps): bump platformdirs in the python-dependencies group (#446)74e0040Bump sigstore from 4.4 to 4.5 (#444)52538fdbuild(deps): bump the actions group across 1 directory with 4 updates (#439)cbab91dbuild(deps): bump the python-dependencies group across 1 directory with 9 upd...1d3524cbuild(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 in the acti...a174484build(deps): bump sigstore from 4.3.0 to 4.4.0 in the python-dependencies gro...0b384a6build(deps): bump the actions group with 2 updates (#429)f11d8f8build(deps): bump typing-extensions in the python-dependencies group (#430)258577bbuild(deps): bump the python-dependencies group with 2 updates (#428)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)