From 8f8ea7291585657f3acd083973c4c8d5da049b45 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 5 Jun 2026 09:53:42 +0000 Subject: [PATCH 1/2] Bump aquasecurity/trivy-action in /.github/workflows Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.20.0 to 0.35.0. - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](https://github.com/aquasecurity/trivy-action/compare/v0.20.0...0.35.0) --- updated-dependencies: - dependency-name: aquasecurity/trivy-action dependency-version: 0.35.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- .github/workflows/e2e-first-commit.yml | 2 +- .github/workflows/thingsdata-integration.yml | 2 +- .github/workflows/validate-all.yml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/e2e-first-commit.yml b/.github/workflows/e2e-first-commit.yml index a1f13374..0f72235c 100644 --- a/.github/workflows/e2e-first-commit.yml +++ b/.github/workflows/e2e-first-commit.yml @@ -54,7 +54,7 @@ jobs: git push - name: Run Trivy filesystem scan - uses: aquasecurity/trivy-action@v0.20.0 + uses: aquasecurity/trivy-action@0.35.0 with: scan-type: fs scan-ref: . diff --git a/.github/workflows/thingsdata-integration.yml b/.github/workflows/thingsdata-integration.yml index e4f97faa..97e1ab9a 100644 --- a/.github/workflows/thingsdata-integration.yml +++ b/.github/workflows/thingsdata-integration.yml @@ -205,7 +205,7 @@ jobs: - uses: actions/checkout@v4 - name: Run Trivy image scan - uses: aquasecurity/trivy-action@v0.20.0 + uses: aquasecurity/trivy-action@0.35.0 with: scan-type: 'config' scan-ref: 'infrastructure/thingsdata' diff --git a/.github/workflows/validate-all.yml b/.github/workflows/validate-all.yml index 00648e85..c6d46c3e 100644 --- a/.github/workflows/validate-all.yml +++ b/.github/workflows/validate-all.yml @@ -85,7 +85,7 @@ jobs: steps: - uses: actions/checkout@v4 - name: Trivy filesystem scan - uses: aquasecurity/trivy-action@v0.20.0 + uses: aquasecurity/trivy-action@0.35.0 with: scan-type: fs scan-ref: . From c5e98e3281509d9c459110884b35ae5ae6cd52ae Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 11:59:21 +0000 Subject: [PATCH 2/2] docs: actualizar changelog preview del PR --- CHANGELOG.md | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 02466b0a..6705e6c6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,9 +1,17 @@ # CHANGELOG -## [Unreleased] - 2026-08-01 +## [Unreleased] - 2026-09-04 -- Merge fe9a1449e46f3e84ce0fe013375dd0b7938ba43c into e067bde4d081caf85c3af10b51160abef24c466a (0ba736c) -- Revise README for Cast-o framework details (fe9a144) +- Merge 8f8ea7291585657f3acd083973c4c8d5da049b45 into b01ab0112b2a9ff02070e403ad70db8bda2d0ba8 (781b76c) +- Bump aquasecurity/trivy-action in /.github/workflows (8f8ea72) +- docs(evos): integrate castuo-evidence into ecosystem navigation (b01ab01) +- docs: add negative assurance boundary (e3aabfc) +- docs: add private cloud evidence boundary (4d0c0f7) +- ci: align documentation and validation contracts (6c9e233) +- ci: make hardening and Python validation CI-safe (0c86512) +- chore: apply architecture governance and security baseline (5ccf164) +- docs: rewrite README to align with ecosystem contract and evidence-first principles (8484ced) +- Revise README for Cast-o framework details (#11) (f4ea214) - Create SECURITY.md for security policy and reporting (#5) (e067bde) - docs: actualizar resumen visual automatizado (cf1b175) - Add GitHub Actions workflow for Python package with Conda (d1b6e5c)