Skip to content

build(deps): bump hoobio/pipeline-tools from 1.6.0 to 2.3.0#167

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hoobio/pipeline-tools-2.3.0
Open

build(deps): bump hoobio/pipeline-tools from 1.6.0 to 2.3.0#167
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hoobio/pipeline-tools-2.3.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 29, 2026

Bumps hoobio/pipeline-tools from 1.6.0 to 2.3.0.

Release notes

Sourced from hoobio/pipeline-tools's releases.

v2.3.0

2.3.0 (2026-05-23)

Features

  • sbom: scope catalogers + add optional GitHub Actions scan (#30) (7fa1923)

v2.2.1

2.2.1 (2026-05-23)

Bug Fixes

  • sbom: chmod + chown output after docker scans (fix Access denied downstream) (#28) (6353ded)

v2.2.0

2.2.0 (2026-05-23)

Features

  • bun lockfile SBOM support + DT findings PR gate (GH + ADO) (#26) (f9e3a35)

v2.1.0

2.1.0 (2026-05-21)

Features

  • dt: auto-migrate v1 ci/<X> legacies + channel-aware prune defaults (#23) (90002c8)

v2.0.0

2.0.0 (2026-05-21)

⚠ BREAKING CHANGES

  • consolidate SBOM build behind Build-CycloneDxSbom.ps1 and enforce hierarchy (#21)

Features

  • consolidate SBOM build behind Build-CycloneDxSbom.ps1 and enforce hierarchy (#21) (c2c1996)
Changelog

Sourced from hoobio/pipeline-tools's changelog.

2.3.0 (2026-05-23)

Features

  • sbom: scope catalogers + add optional GitHub Actions scan (#30) (7fa1923)

2.2.1 (2026-05-23)

Bug Fixes

  • sbom: chmod + chown output after docker scans (fix Access denied downstream) (#28) (6353ded)

2.2.0 (2026-05-23)

Features

  • bun lockfile SBOM support + DT findings PR gate (GH + ADO) (#26) (f9e3a35)

2.1.0 (2026-05-21)

Features

  • dt: auto-migrate v1 ci/<X> legacies + channel-aware prune defaults (#23) (90002c8)

2.0.0 (2026-05-21)

⚠ BREAKING CHANGES

  • consolidate SBOM build behind Build-CycloneDxSbom.ps1 and enforce hierarchy (#21)

Features

  • consolidate SBOM build behind Build-CycloneDxSbom.ps1 and enforce hierarchy (#21) (c2c1996)
Commits
  • a303c7f chore(main): release 2.3.0 (#31)
  • 7fa1923 feat(sbom): scope catalogers + add optional GitHub Actions scan (#30)
  • ba93169 chore(main): release 2.2.1 (#29)
  • 6353ded fix(sbom): chmod + chown output after docker scans (fix Access denied downstr...
  • 6867467 chore(main): release 2.2.0 (#27)
  • f9e3a35 feat: bun lockfile SBOM support + DT findings PR gate (GH + ADO) (#26)
  • 90ff21e fix: ADO mark-latest skipped when callers pass runtime variables (#25)
  • 323b420 chore(main): release 2.1.0 (#24)
  • 90002c8 feat(dt): auto-migrate v1 ci/<X> legacies + channel-aware prune defaults (#23)
  • 6ed1f40 chore(main): release 2.0.0 (#22)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hoobio/pipeline-tools](https://github.com/hoobio/pipeline-tools) from 1.6.0 to 2.3.0.
- [Release notes](https://github.com/hoobio/pipeline-tools/releases)
- [Changelog](https://github.com/hoobio/pipeline-tools/blob/main/CHANGELOG.md)
- [Commits](hoobio/pipeline-tools@v1.6.0...v2.3.0)

---
updated-dependencies:
- dependency-name: hoobio/pipeline-tools
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 29, 2026
@github-actions
Copy link
Copy Markdown
Contributor

✅ WACK Results (x64)

🟢 23 passed ⚠️ 1 excluded

Excluded Tests

Test Reason
Blocked executables mscordbi.dll and Microsoft.CommandPalette.Extensions.Toolkit.dll (PowerToys SDK) reference CreateProcessW — these are third-party binaries outside our control
All tests
Test Result
Blocked executables ⚠️ Excluded
Install signed driver and executable files 🟢 Pass
Archive files usage 🟢 Pass
Properties 🟢 Pass
General metadata correctness 🟢 Pass
Type name correctness 🟢 Pass
Type name case-sensitivity 🟢 Pass
Type location 🟢 Pass
ExclusiveTo attribute 🟢 Pass
Special use capabilities 🟢 Pass
Debug configuration 🟢 Pass
Branding 🟢 Pass
App resources 🟢 Pass
Private code signing 🟢 Pass
Banned file analyzer 🟢 Pass
Resource Packages 🟢 Pass
Enterprise Features 🟢 Pass
Registry checks 🟢 Pass
File association verbs 🟢 Pass
App manifest 🟢 Pass
Application count 🟢 Pass
User account control run level 🟢 Pass
Platform appropriate files 🟢 Pass
DPIAwarenessValidation 🟢 Pass

@github-actions
Copy link
Copy Markdown
Contributor

✅ WACK Results (ARM64)

🟢 23 passed ⚠️ 1 excluded

Excluded Tests

Test Reason
Blocked executables mscordbi.dll and Microsoft.CommandPalette.Extensions.Toolkit.dll (PowerToys SDK) reference CreateProcessW — these are third-party binaries outside our control
All tests
Test Result
Blocked executables ⚠️ Excluded
Install signed driver and executable files 🟢 Pass
Archive files usage 🟢 Pass
Properties 🟢 Pass
General metadata correctness 🟢 Pass
Type name correctness 🟢 Pass
Type name case-sensitivity 🟢 Pass
Type location 🟢 Pass
ExclusiveTo attribute 🟢 Pass
Special use capabilities 🟢 Pass
Debug configuration 🟢 Pass
Branding 🟢 Pass
App resources 🟢 Pass
Private code signing 🟢 Pass
Banned file analyzer 🟢 Pass
Resource Packages 🟢 Pass
Enterprise Features 🟢 Pass
Registry checks 🟢 Pass
File association verbs 🟢 Pass
App manifest 🟢 Pass
Application count 🟢 Pass
User account control run level 🟢 Pass
Platform appropriate files 🟢 Pass
DPIAwarenessValidation 🟢 Pass

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants