Skip to content

Conversation

@rudy-regazzoni-sonarsource
Copy link
Contributor

The upload-artifact action has safe versions in both v3.x (3.2+) and v4.x (4.4+) due to a backported fix. Updated the rule description to clarify the vulnerable version ranges.

The upload-artifact action has safe versions in both v3.x (3.2+) and v4.x (4.4+)
due to a backported fix. Updated the rule description to clarify the vulnerable
version ranges.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@hashicorp-vault-sonar-prod
Copy link
Contributor

hashicorp-vault-sonar-prod bot commented Dec 12, 2025

SONARIAC-2401

@rudy-regazzoni-sonarsource rudy-regazzoni-sonarsource changed the title SONARIAC-2401 Update S8262 to mention v3.2+ backported fix Modify rule S8262: mention v3.2+ backported fix Dec 12, 2025
@sonarqube-next
Copy link

Quality Gate passed Quality Gate passed for 'rspec-tools'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Copy link
Contributor

@GabinL21 GabinL21 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks

@sonarqube-next
Copy link

Quality Gate passed Quality Gate passed for 'rspec-frontend'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@rudy-regazzoni-sonarsource rudy-regazzoni-sonarsource added this pull request to the merge queue Dec 12, 2025
github-merge-queue bot pushed a commit that referenced this pull request Dec 12, 2025
The upload-artifact action has safe versions in both v3.x (3.2+) and v4.x (4.4+)
due to a backported fix. Updated the rule description to clarify the vulnerable
version ranges.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Dec 12, 2025
@rudy-regazzoni-sonarsource rudy-regazzoni-sonarsource added this pull request to the merge queue Dec 12, 2025
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Dec 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants