-
Notifications
You must be signed in to change notification settings - Fork 65
chore: bump the all group across 1 directory with 15 updates #1141
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/github_actions/all-c56bb09bf1
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
0ae882d
to
8702935
Compare
@dependabot rebase |
8702935
to
cbda93f
Compare
Bumps the all group with 15 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.10.4` | `2.11.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.9` | `3.28.13` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.2.0` | `4.3.0` | | [actions/cache](https://github.com/actions/cache) | `4.2.0` | `4.2.3` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.3.0` | `5.4.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.9.0` | `3.10.0` | | [crazy-max/ghaction-github-runtime](https://github.com/crazy-max/ghaction-github-runtime) | `3.0.0` | `3.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.0` | `4.6.2` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.1.8` | `4.2.1` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.6` | `7.0.8` | | [docker/login-action](https://github.com/docker/login-action) | `3.3.0` | `3.4.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.29.0` | `0.30.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.1` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `6.3.1` | `7.0.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.3.1` | `5.4.0` | Updates `step-security/harden-runner` from 2.10.4 to 2.11.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@cb605e5...4d991eb) Updates `github/codeql-action` from 3.28.9 to 3.28.13 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@9e8d078...1b549b9) Updates `actions/setup-node` from 4.2.0 to 4.3.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@1d0ff46...cdca736) Updates `actions/cache` from 4.2.0 to 4.2.3 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@1bd1e32...5a3ec84) Updates `actions/setup-go` from 5.3.0 to 5.4.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@f111f33...0aaccfd) Updates `docker/setup-buildx-action` from 3.9.0 to 3.10.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@f7ce87c...b5ca514) Updates `crazy-max/ghaction-github-runtime` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/crazy-max/ghaction-github-runtime/releases) - [Commits](crazy-max/ghaction-github-runtime@b3a9207...3cb05d8) Updates `actions/upload-artifact` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@65c4c4a...ea165f8) Updates `actions/download-artifact` from 4.1.8 to 4.2.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@fa0a91b...95815c3) Updates `peter-evans/create-pull-request` from 7.0.6 to 7.0.8 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@67ccf78...271a8d0) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) Updates `aquasecurity/trivy-action` from 0.29.0 to 0.30.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@18f2510...6c175e9) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.1 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@62b2cac...f49aabe) Updates `golangci/golangci-lint-action` from 6.3.1 to 7.0.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@2e78893...1481404) Updates `codecov/codecov-action` from 5.3.1 to 5.4.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@13ce06b...0565863) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: actions/setup-node dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: actions/cache dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: crazy-max/ghaction-github-runtime dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: actions/download-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: aquasecurity/trivy-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: golangci/golangci-lint-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: all - dependency-name: codecov/codecov-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com>
cbda93f
to
32dd467
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the all group with 15 updates in the / directory:
2.10.4
2.11.0
3.28.9
3.28.13
4.2.0
4.3.0
4.2.0
4.2.3
5.3.0
5.4.0
3.9.0
3.10.0
3.0.0
3.1.0
4.6.0
4.6.2
4.1.8
4.2.1
7.0.6
7.0.8
3.3.0
3.4.0
0.29.0
0.30.0
2.4.0
2.4.1
6.3.1
7.0.0
5.3.1
5.4.0
Updates
step-security/harden-runner
from 2.10.4 to 2.11.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
4d991eb
Merge pull request #498 from step-security/rc-184ea872f
Update README.md65d6f6e
Add workflows1034c9a
Update package-lock.jsonab221e2
Update agent7cb6c2f
Update agentUpdates
github/codeql-action
from 3.28.9 to 3.28.13Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
1b549b9
Merge pull request #2819 from github/update-v3.28.13-e0ea1410282630c8
Update changelog for v3.28.13e0ea141
Merge pull request #2818 from github/cklin/empty-pr-diff-rangeb361a91
Diff-informed analysis: fix empty PR handlingbd1d9ab
Merge pull request #2816 from github/cklin/overlay-file-listb98ae6c
Add overlay-database-utils tests9825184
Add getFileOidsUnderPath() testsac67cff
Merge pull request #2817 from github/cklin/default-setup-diff-informed9c674ba
build: refresh js filesd109dd5
Detect PR branches for Default SetupUpdates
actions/setup-node
from 4.2.0 to 4.3.0Release notes
Sourced from actions/setup-node's releases.
Commits
cdca736
Bump@actions/tool-cache
from 2.0.1 to 2.0.2 (#1220)22c0e74
Bump@vercel/ncc
from 0.38.1 to 0.38.3 (#1203)a7c2d94
actions/cache upgrade (#1251)8026329
Bump@actions/glob
from 0.4.0 to 0.5.0 (#1200)Updates
actions/cache
from 4.2.0 to 4.2.3Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
5a3ec84
Merge pull request #1577 from salmanmkc/salmanmkc/4-test7de2102
Update releases.md76d40dd
Update to use the latest version of the cache package to obfuscate the SAS76dd5eb
update cache with main8c80c27
new package45cfd0e
updatesedd449b
updated cache with latest changes0576707
latest test before pr3105dc9
update9450d42
maskUpdates
actions/setup-go
from 5.3.0 to 5.4.0Release notes
Sourced from actions/setup-go's releases.
Commits
0aaccfd
Bump undici from 5.28.4 to 5.28.5 (#541)c4c1141
upgrade actions/cache to 4.0.2 (#568)5a083d0
Bump eslint-config-prettier from 8.10.0 to 10.0.1 (#536)1d82324
Bump semver from 7.6.0 to 7.6.3 (#535)Updates
docker/setup-buildx-action
from 3.9.0 to 3.10.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
b5ca514
Merge pull request #408 from docker/dependabot/npm_and_yarn/docker/actions-to...1418a4e
chore: update generated content93acf83
build(deps): bump@docker/actions-toolkit
from 0.54.0 to 0.56.0Updates
crazy-max/ghaction-github-runtime
from 3.0.0 to 3.1.0Release notes
Sourced from crazy-max/ghaction-github-runtime's releases.
Commits
3cb05d8
Merge pull request #58 from crazy-max/dependabot/npm_and_yarn/actions/core-1....ef7a149
chore: update generated content5bfe170
Merge pull request #55 from crazy-max/dependabot/npm_and_yarn/micromatch-4.0.858529df
Merge pull request #59 from crazy-max/dependabot/npm_and_yarn/cross-spawn-7.0.6ac1af5a
Merge pull request #60 from crazy-max/gha-perms8ae9a9b
ci: set contents read as default workflow permissions22db7e4
new year24046ff
Bump cross-spawn from 7.0.3 to 7.0.6c068fc9
Bump@actions/core
from 1.10.0 to 1.11.10d73af4
Bump micromatch from 4.0.5 to 4.0.8Updates
actions/upload-artifact
from 4.6.0 to 4.6.2Release notes
Sourced from actions/upload-artifact's releases.
Commits
ea165f8
Merge pull request #685 from salmanmkc/salmanmkc/3-new-upload-artifacts-release0839620
Prepare for new release of actions/upload-artifact with new toolkit cache ver...4cec3d8
Merge pull request #673 from actions/yacaovsnc/artifact_2.2.2e9fad96
license cache update for artifactb26fd06
Update to use artifact 2.2.2 packageUpdates
actions/download-artifact
from 4.1.8 to 4.2.1Release notes
Sourced from actions/download-artifact's releases.
Commits
95815c3
Merge pull request #391 from GhadimiR/main278fca4
Move log statements6890984
Merge branch 'main' into mainf9415c0
Run unit tests in CI76a6eb5
Merge pull request #392 from GhadimiR/add_unit_testsa2426d7
Merge branch 'main' into add_unit_tests3ffa694
lint53f6aa5
Add extra assertion to download single artifact testb456700
lint9eab798
Configure tsconfigUpdates
peter-evans/create-pull-request
from 7.0.6 to 7.0.8Release notes
Sourced from peter-evans/create-pull-request's releases.
Commits
271a8d0
fix: suppress output for some git operations (#3776)6f7efd1
test: update cpr-example-command13c47c5
build(deps-dev): bump prettier from 3.5.1 to 3.5.2 (#3754)63e5829
build(deps): bump@octokit/plugin-paginate-rest
from 11.4.2 to 11.4.3 (#3753)a92c90f
build(deps-dev): bump eslint-import-resolver-typescript (#3752)b23b62d
build(deps-dev): bump ts-jest from 29.2.5 to 29.2.6 (#3751)dd2324f
fix: use showFileAtRefBase64 to read per-commit file contents (#3744)367180c
ci: remove testv5 cmd25575a1
build: update distribution (#3736)a56e7a5
build(deps): bump@octokit/core
from 6.1.3 to 6.1.4 (#3711)Updates
docker/login-action
from 3.3.0 to 3.4.0Release notes
Sourced from docker/login-action's releases.
Commits
74a5d14
Merge pull request #856 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...2f4f00e
chore: update generated content67c1845
build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...3d4cc89
Merge pull request #844 from graysonpike/master6cc823a
Merge pull request #823 from docker/dependabot/npm_and_yarn/proxy-agent-depen...d94e792
chore: update generated content033db0d
Merge pull request #812 from docker/dependabot/github_actions/codecov/codecov...09c2ae9
build(deps): bump https-proxy-agentba56f00
ci: update deprecated input for codecov-action75bf9a7
Merge pull request #858 from docker/dependabot/npm_and_yarn/docker/actions-to...Updates
aquasecurity/trivy-action
from 0.29.0 to 0.30.0Release notes
Sourced from aquasecurity/trivy-action's releases.
Commits
6c175e9
chore: bump trivy to v0.60.0 (#453)53e8848
Improve README/SBOM (#439)ef1b561
fix: typo in description of an input for action.yaml (#452)a11da62
fix: Update default trivy version in README (#444)Updates
ossf/scorecard-action
from 2.4.0 to 2.4.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
f49aabe
bump docker to ghcr v2.4.1 (#1478)30a595b
🌱 Bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 (#1515)69ae593
omit vcs info from build (#1514)6a62a1c
add input for specifying--file-mode
(#1509)2722664
🌱 Bump the github-actions group with 2 updates (#1510)ae0ef31
🌱 Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 (#1512)3676bbc
🌱 Bump golang from 1.23.6 to 1.24.0...Description has been truncated