diff --git a/.github/workflows/pull_request.yml b/.github/workflows/pull_request.yml index 60bedee2d0..3245f759a2 100644 --- a/.github/workflows/pull_request.yml +++ b/.github/workflows/pull_request.yml @@ -9,7 +9,7 @@ permissions: {} jobs: dependabot-auto-approve-and-merge: needs: quality_checks - uses: NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml@c8f899f30a6a726859b0277faa73cd9ff7f4de20 + uses: NHSDigital/eps-common-workflows/.github/workflows/dependabot-auto-approve-and-merge.yml@e798d5aee897de6f7dc387dd5623fcd9ba4c8929 permissions: contents: write pull-requests: write diff --git a/.grype.yaml b/.grype.yaml index d07cef7c42..cd29dc4fe8 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -1,3 +1,5 @@ ignore: # path-to-regexp - dependency of aws-sdk-client-mock - vulnerability: GHSA-j3q9-mxjg-w52f + # protobufjs - dependency of @redocly/cli + - vulnerability: GHSA-xq3m-2v4x-88gg