-
Notifications
You must be signed in to change notification settings - Fork 42
chore(deps): Bump the actions-all group across 1 directory with 13 updates #534
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/github_actions/actions-all-9e78b5746e
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+56
−56
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…dates Bumps the actions-all group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.11.0` | `2.12.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.3.0` | `5.5.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.11` | `3.28.18` | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2.3.0` | `2.4.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.5.0` | `4.7.1` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.3.0` | `4.4.0` | | [actions/cache](https://github.com/actions/cache) | `4.2.2` | `4.2.3` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `6.5.1` | `8.0.0` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.8.1` | `3.8.2` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.15.0` | `6.18.0` | | [crazy-max/ghaction-github-runtime](https://github.com/crazy-max/ghaction-github-runtime) | `3.0.0` | `3.1.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.2` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.1` | `4.6.2` | Updates `step-security/harden-runner` from 2.11.0 to 2.12.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@4d991eb...0634a26) Updates `actions/setup-go` from 5.3.0 to 5.5.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@f111f33...d35c59a) Updates `github/codeql-action` from 3.28.11 to 3.28.18 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@6bb031a...ff0a06e) Updates `dependabot/fetch-metadata` from 2.3.0 to 2.4.0 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@d7267f6...08eff52) Updates `actions/dependency-review-action` from 4.5.0 to 4.7.1 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@3b139cf...da24556) Updates `actions/setup-node` from 4.3.0 to 4.4.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@cdca736...49933ea) Updates `actions/cache` from 4.2.2 to 4.2.3 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@d4323d4...5a3ec84) Updates `golangci/golangci-lint-action` from 6.5.1 to 8.0.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@4696ba8...4afd733) Updates `sigstore/cosign-installer` from 3.8.1 to 3.8.2 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@d7d6bc7...3454372) Updates `docker/build-push-action` from 6.15.0 to 6.18.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@471d1dc...2634353) Updates `crazy-max/ghaction-github-runtime` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/crazy-max/ghaction-github-runtime/releases) - [Commits](crazy-max/ghaction-github-runtime@b3a9207...3cb05d8) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.2 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@f49aabe...05b42c6) Updates `actions/upload-artifact` from 4.6.1 to 4.6.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@4cec3d8...ea165f8) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: actions/setup-go dependency-version: 5.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: github/codeql-action dependency-version: 3.28.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-all - dependency-name: dependabot/fetch-metadata dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: actions/dependency-review-action dependency-version: 4.7.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: actions/setup-node dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: actions/cache dependency-version: 4.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-all - dependency-name: golangci/golangci-lint-action dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-all - dependency-name: sigstore/cosign-installer dependency-version: 3.8.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-all - dependency-name: docker/build-push-action dependency-version: 6.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: crazy-max/ghaction-github-runtime dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-all - dependency-name: ossf/scorecard-action dependency-version: 2.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-all - dependency-name: actions/upload-artifact dependency-version: 4.6.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-all ... Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the actions-all group with 13 updates in the / directory:
2.11.0
2.12.0
5.3.0
5.5.0
3.28.11
3.28.18
2.3.0
2.4.0
4.5.0
4.7.1
4.3.0
4.4.0
4.2.2
4.2.3
6.5.1
8.0.0
3.8.1
3.8.2
6.15.0
6.18.0
3.0.0
3.1.0
2.4.1
2.4.2
4.6.1
4.6.2
Updates
step-security/harden-runner
from 2.11.0 to 2.12.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
0634a26
Merge pull request #541 from step-security/rc-202e3c511
Update action.yml40873e6
Update README.md484c279
Update README.md4c8582f
Update agent versionse8d595c
fix disable_sudo_and_containers bug5d277fc
fix journalctl related bugff2ab22
Merge pull request #536 from rohan-stepsecurity/feat/flag/disable-sudo-and-co...b81d650
fix: run sudo command only when both disable-sudo and disable-sudo-and-docker...769df4e
Update agentUpdates
actions/setup-go
from 5.3.0 to 5.5.0Release notes
Sourced from actions/setup-go's releases.
Commits
d35c59a
chore: update discussions url (#527)29694d7
Add manifest validation and improve error handling (#586)78535dd
Bump eslint-plugin-jest from 27.9.0 to 28.11.0 (#537)bb65d88
Bump ts-jest from 29.1.2 to 29.3.2 (#582)7f17e83
Bump@actions/glob
from 0.4.0 to 0.5.0 (#573)dca8468
Update self-hosted environment validation and bump undici version (#556)691cc35
upgrade actions/cache to 4.0.3 (#574)0aaccfd
Bump undici from 5.28.4 to 5.28.5 (#541)c4c1141
upgrade actions/cache to 4.0.2 (#568)5a083d0
Bump eslint-config-prettier from 8.10.0 to 10.0.1 (#536)Updates
github/codeql-action
from 3.28.11 to 3.28.18Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
ff0a06e
Merge pull request #2896 from github/update-v3.28.18-b86edfc27a41e084
Update changelog for v3.28.18b86edfc
Merge pull request #2893 from github/update-bundle/codeql-bundle-v2.21.3e93b900
Merge branch 'main' into update-bundle/codeql-bundle-v2.21.3510dfa3
Merge pull request #2894 from github/henrymercer/skip-validating-codeql-sarif492d783
Merge branch 'main' into henrymercer/skip-validating-codeql-sarif83bdf3b
Merge pull request #2859 from github/update-supported-enterprise-server-versionscffc916
Merge pull request #2891 from austinpray-mixpanel/patch-14420887
Add deprecation warning for CodeQL 2.16.5 and earlier4e178c5
Update supported versions table in READMEUpdates
dependabot/fetch-metadata
from 2.3.0 to 2.4.0Release notes
Sourced from dependabot/fetch-metadata's releases.
Commits
08eff52
v2.4.0 (#594)821b654
Merge pull request #621 from dependabot/dependabot/github_actions/actions/cre...2c22a37
Bump actions/create-github-app-token from 2.0.2 to 2.0.66ad01a0
Add workflow to publish new version of immutable action on every release (#623)8ca800c
Enable caching ofnpm install
/npm ci
forsetup-node
action (#618)6787635
Merge pull request #616 from dependabot/dependabot/github_actions/actions/cre...a09d4af
Bump actions/create-github-app-token from 1.11.3 to 2.0.23a5ce46
Remove unnecessary hardcoding ofref
(#617)798f45c
Fixup some anchor tags that weren't deeplinking (#614)6c031ac
Tidy up examples slightly (#611)Updates
actions/dependency-review-action
from 4.5.0 to 4.7.1Release notes
Sourced from actions/dependency-review-action's releases.
Commits
da24556
Merge pull request #933 from actions/dangoor/471-release9af0caf
Bump version number for 4.7.1d8f2df2
Merge pull request #932 from actions/907-disallow-expression6e9307a
Discard allow list entries that are not SPDX IDs8805179
Merge pull request #930 from actions/889-allow-no-license014300b
Update build34486f3
Check namespaces when excluding license checks9b155d6
Update buildf199659
Allowing dependencies works with no licenses38ecb5b
Merge pull request #929 from actions/dangoor/4.7-releaseUpdates
actions/setup-node
from 4.3.0 to 4.4.0Release notes
Sourced from actions/setup-node's releases.
Commits
49933ea
Bump@action/cache
from 4.0.2 to 4.0.3 (#1262)e3ce749
feat: support private mirrors (#1240)40337cb
Add support for indented eslint output (#1245)1ccdddc
Make eslint-compact matcher compatible with Stylelint (#98)Updates
actions/cache
from 4.2.2 to 4.2.3Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
5a3ec84
Merge pull request #1577 from salmanmkc/salmanmkc/4-test7de2102
Update releases.md76d40dd
Update to use the latest version of the cache package to obfuscate the SAS76dd5eb
update cache with main8c80c27
new package45cfd0e
updatesedd449b
updated cache with latest changes0576707
latest test before pr3105dc9
update9450d42
maskUpdates
golangci/golangci-lint-action
from 6.5.1 to 8.0.0Release notes
Sourced from golangci/golangci-lint-action's releases.
... (truncated)
Commits
4afd733
8.0.07774f98
feat: use absolute paths by default when using working-directory option (#1231)9fae48a
7.0.116ece5e
docs: clarify that ’args: --path-mode=abs’ is needed for working-directory (...a3942e2
build(deps-dev): bump the dev-dependencies group with 2 updates (#1227)7ecb048
build(deps): bump@types/node
from 22.14.0 to 22.14.1 in the dependencies gro...63a0d0e
build(deps-dev): bump the dev-dependencies group with 3 updates (#1224)c2427fe
docs: update problem matchers section642f8ee
build(deps): bump@types/node
from 22.13.14 to 22.14.0 in the dependencies gr...d84be92
build(deps-dev): bump the dev-dependencies group with 4 updates (#1220)Updates
sigstore/cosign-installer
from 3.8.1 to 3.8.2Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
3454372
install cosign v2 from main (#186)b6ee8f8
Bump actions/setup-go from 5.3.0 to 5.4.0 (#185)Updates
docker/build-push-action
from 6.15.0 to 6.18.0Release notes
Sourced from docker/build-push-action's releases.
Commits
2634353
Merge pull request #1381 from docker/dependabot/npm_and_yarn/docker/actions-t...c0432d2
chore: update generated content0bb1f27
set builder driver and endpoint attributes for dbc summary support5f9dbf9
chore(deps): Bump@docker/actions-toolkit
from 0.61.0 to 0.62.10788c44
Merge pull request #1375 from crazy-max/remove-gcraa179ca
e2e: remove GCR1dc7386
Merge pull request #1364 from crazy-max/history-export-cmd9c9803f
chore: update generated contentdb1f6c4
DOCKER_BUILD_EXPORT_LEGACY env var to opt-in for legacy export721e8c7
Bump@docker/actions-toolkit
from 0.59.0 to 0.61.0Updates
crazy-max/ghaction-github-runtime
from 3.0.0 to 3.1.0Release notes
Sourced from crazy-max/ghaction-github-runtime's releases.
Commits
3cb05d8
Merge pull request #58 from crazy-max/dependabot/npm_and_yarn/actions/core-1....ef7a149
chore: update generated content5bfe170
Merge pull request #55 from crazy-max/dependabot/npm_and_yarn/micromatch-4.0.858529df
Merge pull request #59 from crazy-max/dependabot/npm_and_yarn/cross-spawn-7.0.6ac1af5a
Merge pull request #60 from crazy-max/gha-perms8ae9a9b
ci: set contents read as default workflow permissions22db7e4
new year24046ff
Bump cross-spawn from 7.0.3 to 7.0.6c068fc9
Bump@actions/core
from 1.10.0 to 1.11.10d73af4
Bump micromatch from 4.0.5 to 4.0.8Updates
ossf/scorecard-action
from 2.4.1 to 2.4.2Release notes
Sourced from ossf/scorecard-action's releases.