Skip to content

Upgrade: [dependabot] - bump NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml from 5.5.3 to 5.6.3#2815

Merged
eps-autoapprove-dependabot[bot] merged 1 commit intomainfrom
dependabot/github_actions/NHSDigital/eps-common-workflows/dot-github/workflows/dependabot-auto-approve-and-merge.yml-5.6.3
Mar 9, 2026
Merged

Upgrade: [dependabot] - bump NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml from 5.5.3 to 5.6.3#2815
eps-autoapprove-dependabot[bot] merged 1 commit intomainfrom
dependabot/github_actions/NHSDigital/eps-common-workflows/dot-github/workflows/dependabot-auto-approve-and-merge.yml-5.6.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 6, 2026

Bumps NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml from 5.5.3 to 5.6.3.

Release notes

Sourced from NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml's releases.

v5.6.3

5.6.3 (2026-03-06)

Chore

Info

Release workflow run - Workflow ID: 22773044980

It was initialized by originalphil

v5.6.2

5.6.2 (2026-03-05)

Upgrade

  • [dependabot] - bump conventional-changelog-eslint from 6.0.0 to 6.1.0 (#82) (91d5906)

Info

Release workflow run - Workflow ID: 22730971742

It was initialized by eps-autoapprove-dependabot[bot]

v5.6.1

5.6.1 (2026-03-05)

Fix

  • [AEA-0000] - Always run valid trivy scans even if a previous scan failed, so that all vulnerabilities are identified at once. Shorten feedback cycle for vulnerabilities across multiple scans. (#78) (d116ba9)

Info

Release workflow run - Workflow ID: 22727356777

It was initialized by connoravo-nhs

v5.6.0

5.6.0 (2026-03-05)

Fix

New

... (truncated)

Commits
  • 141907b Chore: [AEA-5986] - Allow semantic release to handle python build (#83)
  • 91d5906 Upgrade: [dependabot] - bump conventional-changelog-eslint from 6.0.0 to 6.1....
  • d116ba9 Fix: [AEA-0000] - Always run valid trivy scans even if a previous scan failed...
  • aac5b79 Fix: [AEA-5986] - Fix publish fame library (#77)
  • d522293 Upgrade: [dependabot] - bump aquasecurity/trivy-action from 0.34.0 to 0.34.1 ...
  • de21183 New: [AEA-5986] - Publish to PyPI (#76)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 6, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Mar 6, 2026

This PR is raised by Dependabot to update a dependency.

Copy link
Copy Markdown

@eps-autoapprove-dependabot eps-autoapprove-dependabot Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@tstephen-nhs
Copy link
Copy Markdown
Contributor

@dependabot recreate

…workflows/dependabot-auto-approve-and-merge.yml

Bumps [NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml](https://github.com/nhsdigital/eps-common-workflows) from 5.5.3 to 5.6.3.
- [Release notes](https://github.com/nhsdigital/eps-common-workflows/releases)
- [Changelog](https://github.com/NHSDigital/eps-common-workflows/blob/main/release.config.cjs)
- [Commits](NHSDigital/eps-common-workflows@8404cf6...141907b)

---
updated-dependencies:
- dependency-name: NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml
  dependency-version: 5.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/NHSDigital/eps-common-workflows/dot-github/workflows/dependabot-auto-approve-and-merge.yml-5.6.3 branch from e34e72d to b008506 Compare March 9, 2026 09:16
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Mar 9, 2026

Copy link
Copy Markdown

@eps-autoapprove-dependabot eps-autoapprove-dependabot Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@eps-autoapprove-dependabot eps-autoapprove-dependabot Bot merged commit ab2ea6c into main Mar 9, 2026
42 of 43 checks passed
@dependabot dependabot Bot deleted the dependabot/github_actions/NHSDigital/eps-common-workflows/dot-github/workflows/dependabot-auto-approve-and-merge.yml-5.6.3 branch March 9, 2026 10:35
tstephen-nhs pushed a commit that referenced this pull request Mar 18, 2026
…workflows/dependabot-auto-approve-and-merge.yml from 5.5.3 to 5.6.3 (#2815)

Bumps
[NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml](https://github.com/nhsdigital/eps-common-workflows)
from 5.5.3 to 5.6.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nhsdigital/eps-common-workflows/releases">NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml's
releases</a>.</em></p>
<blockquote>
<h2>v5.6.3</h2>
<h2><a
href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.2...v5.6.3">5.6.3</a>
(2026-03-06)</h2>
<h3>Chore</h3>
<ul>
<li>[AEA-5986] - Allow semantic release to handle python build (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/83">#83</a>)
(<a
href="https://github.com/NHSDigital/eps-common-workflows/commit/141907b215220e95e3ed3811d0fe8fa18675dbed">141907b</a>)</li>
</ul>
<h2>Info</h2>
<p><a
href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22773044980">Release
workflow run</a> - Workflow ID: 22773044980</p>
<p>It was initialized by <a
href="https://github.com/originalphil">originalphil</a></p>
<h2>v5.6.2</h2>
<h2><a
href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.1...v5.6.2">5.6.2</a>
(2026-03-05)</h2>
<h3>Upgrade</h3>
<ul>
<li>[dependabot] - bump conventional-changelog-eslint from 6.0.0 to
6.1.0 (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/82">#82</a>)
(<a
href="https://github.com/NHSDigital/eps-common-workflows/commit/91d5906640395bcda81360fb4b78adaf2f09fd2e">91d5906</a>)</li>
</ul>
<h2>Info</h2>
<p><a
href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22730971742">Release
workflow run</a> - Workflow ID: 22730971742</p>
<p>It was initialized by <a
href="https://github.com/apps/eps-autoapprove-dependabot">eps-autoapprove-dependabot[bot]</a></p>
<h2>v5.6.1</h2>
<h2><a
href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.0...v5.6.1">5.6.1</a>
(2026-03-05)</h2>
<h3>Fix</h3>
<ul>
<li>[AEA-0000] - Always run valid trivy scans even if a previous scan
failed, so that all vulnerabilities are identified at once. Shorten
feedback cycle for vulnerabilities across multiple scans. (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/78">#78</a>)
(<a
href="https://github.com/NHSDigital/eps-common-workflows/commit/d116ba935f2a9544c7bcc6dc37ea997fada6e780">d116ba9</a>)</li>
</ul>
<h2>Info</h2>
<p><a
href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22727356777">Release
workflow run</a> - Workflow ID: 22727356777</p>
<p>It was initialized by <a
href="https://github.com/connoravo-nhs">connoravo-nhs</a></p>
<h2>v5.6.0</h2>
<h1><a
href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.5.3...v5.6.0">5.6.0</a>
(2026-03-05)</h1>
<h3>Fix</h3>
<ul>
<li>[AEA-5986] - Fix publish fame library (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/77">#77</a>)
(<a
href="https://github.com/NHSDigital/eps-common-workflows/commit/aac5b797ee198b8bd260d618cf7cbdf723860033">aac5b79</a>)</li>
</ul>
<h3>New</h3>
<ul>
<li>[AEA-5986] - Publish to PyPI (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/76">#76</a>)
(<a
href="https://github.com/NHSDigital/eps-common-workflows/commit/de2118390681f2e1701dddcaa463dcea743a6e92">de21183</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/141907b215220e95e3ed3811d0fe8fa18675dbed"><code>141907b</code></a>
Chore: [AEA-5986] - Allow semantic release to handle python build (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/83">#83</a>)</li>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/91d5906640395bcda81360fb4b78adaf2f09fd2e"><code>91d5906</code></a>
Upgrade: [dependabot] - bump conventional-changelog-eslint from 6.0.0 to
6.1....</li>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/d116ba935f2a9544c7bcc6dc37ea997fada6e780"><code>d116ba9</code></a>
Fix: [AEA-0000] - Always run valid trivy scans even if a previous scan
failed...</li>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/aac5b797ee198b8bd260d618cf7cbdf723860033"><code>aac5b79</code></a>
Fix: [AEA-5986] - Fix publish fame library (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/77">#77</a>)</li>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/d5222938de3b91e0fe94db73d61eb9e0f781b1ed"><code>d522293</code></a>
Upgrade: [dependabot] - bump aquasecurity/trivy-action from 0.34.0 to
0.34.1 ...</li>
<li><a
href="https://github.com/NHSDigital/eps-common-workflows/commit/de2118390681f2e1701dddcaa463dcea743a6e92"><code>de21183</code></a>
New: [AEA-5986] - Publish to PyPI (<a
href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/76">#76</a>)</li>
<li>See full diff in <a
href="https://github.com/nhsdigital/eps-common-workflows/compare/8404cf6e3a61ac8de4d1644e175e288aa4965815...141907b215220e95e3ed3811d0fe8fa18675dbed">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml&package-manager=github_actions&previous-version=5.5.3&new-version=5.6.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant