Skip to content

chore(deps): bump securego/gosec from 1d458c50e1a9aa6c0d414dfde3998d66cf2c4fc7 to 833d7919e0f1eaf793b5cc4e97050435faee92d1#44

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/securego/gosec-833d7919e0f1eaf793b5cc4e97050435faee92d1
Open

chore(deps): bump securego/gosec from 1d458c50e1a9aa6c0d414dfde3998d66cf2c4fc7 to 833d7919e0f1eaf793b5cc4e97050435faee92d1#44
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/securego/gosec-833d7919e0f1eaf793b5cc4e97050435faee92d1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jan 12, 2026

Bumps securego/gosec from 1d458c50e1a9aa6c0d414dfde3998d66cf2c4fc7 to 833d7919e0f1eaf793b5cc4e97050435faee92d1.

Commits
  • 833d791 refactor(g115): improve coverage (#1462)
  • 0cc9e01 Refine G407 to improve detection and coverage of hardcoded nonces (#1460)
  • 303f84d chore(deps): update all dependencies (#1461)
  • 7387d22 Refactor rules to use callListRule base structure (#1458)
  • 52f5dbf feat(slice): enhance slice bounds analysis with dynamic bounds handling (#1457)
  • 649e2c8 remove deprecated ast.Object (#1455)
  • 35a92b4 feat(sql): enhance SQL injection detection with improved string concatenation...
  • bc9d2bc feat(rules): enhance subprocess variable checks (#1453)
  • 8a5404e feat(resolve): enhance TryResolve to handle KeyValueExpr, IndexExpr, and Slic...
  • 0f6f21c feat: add secrets serialization G117 (#1451)
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [securego/gosec](https://github.com/securego/gosec) from 1d458c50e1a9aa6c0d414dfde3998d66cf2c4fc7 to 833d7919e0f1eaf793b5cc4e97050435faee92d1.
- [Release notes](https://github.com/securego/gosec/releases)
- [Commits](securego/gosec@1d458c5...833d791)

---
updated-dependencies:
- dependency-name: securego/gosec
  dependency-version: 833d7919e0f1eaf793b5cc4e97050435faee92d1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jan 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants