From 07a2f04e10d3bae43986622f0ef6676d57c56952 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:24:00 +0000 Subject: [PATCH] chore(ci): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml Bumps [NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml](https://github.com/nddev-opennetwork/ci-workflows) from 0.1.24 to 0.1.26. - [Release notes](https://github.com/nddev-opennetwork/ci-workflows/releases) - [Changelog](https://github.com/NDDev-OpenNetwork/ci-workflows/blob/main/CHANGELOG.md) - [Commits](https://github.com/nddev-opennetwork/ci-workflows/compare/37a827f921f62353664fc4bcd872f05b65efe71a...a7b90bdf1ac12465cbd07072e3360442cfc8eec6) --- updated-dependencies: - dependency-name: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml dependency-version: 0.1.26 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/security.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 46ee5ea8e..8ecbf7703 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -58,7 +58,7 @@ jobs: contents: read id-token: write # mints the OIDC token its publication is signed with security-events: write # Scorecard publishes its findings to code scanning - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml@37a827f921f62353664fc4bcd872f05b65efe71a # 0.1.24 + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml@a7b90bdf1ac12465cbd07072e3360442cfc8eec6 # 0.1.26 # There is no `osv` job, and the absence is the honest answer rather than an # oversight.