Skip to content

Commit 3136eee

Browse files
Bump the gh-minor group across 1 directory with 16 updates
Bumps the gh-minor group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/setup-go](https://github.com/actions/setup-go) | `5.0.1` | `5.3.0` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.2.0` | `3.6.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.7.1` | `3.10.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.9.0` | `6.15.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.2.0` | `5.4.0` | | [actions/cache](https://github.com/actions/cache) | `4.1.1` | `4.2.2` | | [helm/kind-action](https://github.com/helm/kind-action) | `1.10.0` | `1.12.0` | | [azure/setup-helm](https://github.com/azure/setup-helm) | `4.2.0` | `4.3.0` | | [helm/chart-testing-action](https://github.com/helm/chart-testing-action) | `2.6.1` | `2.7.0` | | [fluxcd/flux2](https://github.com/fluxcd/flux2) | `2.4.0` | `2.5.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.3` | `4.6.1` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.26.12` | `3.28.11` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.7.0` | `3.8.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.17.3` | `0.18.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.0.0` | `6.2.1` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.27.0` | `0.29.0` | Updates `actions/setup-go` from 5.0.1 to 5.3.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@cdcb360...f111f33) Updates `docker/setup-qemu-action` from 3.2.0 to 3.6.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@49b3bc8...2910929) Updates `docker/setup-buildx-action` from 3.7.1 to 3.10.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@c47758b...b5ca514) Updates `docker/build-push-action` from 6.9.0 to 6.15.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@4f58ea7...471d1dc) Updates `actions/setup-python` from 5.2.0 to 5.4.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@f677139...4237552) Updates `actions/cache` from 4.1.1 to 4.2.2 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@3624ceb...d4323d4) Updates `helm/kind-action` from 1.10.0 to 1.12.0 - [Release notes](https://github.com/helm/kind-action/releases) - [Commits](helm/kind-action@0025e74...a1b0e39) Updates `azure/setup-helm` from 4.2.0 to 4.3.0 - [Release notes](https://github.com/azure/setup-helm/releases) - [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md) - [Commits](Azure/setup-helm@fe7b79c...b9e5190) Updates `helm/chart-testing-action` from 2.6.1 to 2.7.0 - [Release notes](https://github.com/helm/chart-testing-action/releases) - [Commits](helm/chart-testing-action@e6669bc...0d28d31) Updates `fluxcd/flux2` from 2.4.0 to 2.5.1 - [Release notes](https://github.com/fluxcd/flux2/releases) - [Changelog](https://github.com/fluxcd/flux2/blob/main/.goreleaser.yml) - [Commits](fluxcd/flux2@5350425...8d5f40d) Updates `actions/upload-artifact` from 4.4.3 to 4.6.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b4b15b8...4cec3d8) Updates `github/codeql-action` from 3.26.12 to 3.28.11 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@c36620d...6bb031a) Updates `sigstore/cosign-installer` from 3.7.0 to 3.8.1 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@dc72c7d...d7d6bc7) Updates `anchore/sbom-action` from 0.17.3 to 0.18.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f5e124a...f325610) Updates `goreleaser/goreleaser-action` from 6.0.0 to 6.2.1 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@286f3b1...90a3faa) Updates `aquasecurity/trivy-action` from 0.27.0 to 0.29.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@5681af8...18f2510) --- updated-dependencies: - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: docker/setup-qemu-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: docker/build-push-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: actions/setup-python dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: actions/cache dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: helm/kind-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: azure/setup-helm dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: helm/chart-testing-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: fluxcd/flux2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: anchore/sbom-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: goreleaser/goreleaser-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: aquasecurity/trivy-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 90ae7db commit 3136eee

11 files changed

+47
-47
lines changed

.github/workflows/build-and-publish.yaml

+7-7
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
- name: Checkout
2323
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
2424
- name: Setup Go
25-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
25+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2626
with:
2727
go-version-file: go.mod
2828
- name: Setup Terraform
@@ -57,12 +57,12 @@ jobs:
5757
echo "BUILD_VERSION=${BUILD_VERSION}" >> "$GITHUB_OUTPUT"
5858
echo "BUILD_SHA=${BUILD_SHA}" >> "$GITHUB_OUTPUT"
5959
- name: Setup QEMU
60-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
60+
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
6161
with:
6262
platforms: all
6363
- name: Setup Docker Buildx
6464
id: buildx
65-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
65+
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
6666
with:
6767
buildkitd-flags: "--debug"
6868
- name: Login to GitHub Container Registry
@@ -72,7 +72,7 @@ jobs:
7272
username: ${{ github.actor }}
7373
password: ${{ secrets.GITHUB_TOKEN }}
7474
- name: Publish multi-arch tf-controller container image
75-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
75+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
7676
with:
7777
push: true
7878
builder: ${{ steps.buildx.outputs.name }}
@@ -91,7 +91,7 @@ jobs:
9191
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
9292
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
9393
- name: Build multi-arch tf-runner base image
94-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
94+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
9595
with:
9696
push: true
9797
builder: ${{ steps.buildx.outputs.name }}
@@ -112,7 +112,7 @@ jobs:
112112
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
113113
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
114114
- name: Publish multi-arch tf-runner container image
115-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
115+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
116116
with:
117117
push: true
118118
builder: ${{ steps.buildx.outputs.name }}
@@ -131,7 +131,7 @@ jobs:
131131
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
132132
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
133133
- name: Publish multi-arch branch-planner container image
134-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
134+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
135135
with:
136136
push: true
137137
builder: ${{ steps.buildx.outputs.name }}

.github/workflows/docs.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
contents: write
1919
steps:
2020
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
21-
- uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
21+
- uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
2222
with:
2323
python-version: 3.x
2424
- name: Install mkdocs

.github/workflows/e2e.yaml

+3-3
Original file line numberDiff line numberDiff line change
@@ -27,22 +27,22 @@ jobs:
2727
with:
2828
version: 4.14.2
2929
- name: Setup Go
30-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
30+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
3131
with:
3232
go-version-file: go.mod
3333
cache-dependency-path: |
3434
**/go.sum
3535
**/go.mod
3636
- name: Cache Docker layers
37-
uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
37+
uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
3838
id: cache
3939
with:
4040
path: /tmp/.buildx-cache
4141
key: ${{ runner.os }}-buildx-ghcache-${{ github.sha }}
4242
restore-keys: |
4343
${{ runner.os }}-buildx-ghcache-
4444
- name: Setup Kubernetes
45-
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
45+
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
4646
with:
4747
version: v0.18.0
4848
node_image: kindest/node:v1.24.12@sha256:1e12918b8bc3d4253bc08f640a231bb0d3b2c5a9b28aa3f2ca1aee93e1e8db16

.github/workflows/helm-test.yaml

+5-5
Original file line numberDiff line numberDiff line change
@@ -19,16 +19,16 @@ jobs:
1919
fetch-depth: 0
2020

2121
- name: Set up Helm
22-
uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v3.5.0
22+
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v3.5.0
2323
with:
2424
version: latest
2525

26-
- uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
26+
- uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
2727
with:
2828
python-version: "3.10"
2929

3030
- name: Set up chart-testing
31-
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992 # v2.6.1
31+
uses: helm/chart-testing-action@0d28d3144d3a25ea2cc349d6e59901c4ff469b3b # v2.7.0
3232

3333
- name: Run chart-testing (list-changed)
3434
id: list-changed
@@ -62,7 +62,7 @@ jobs:
6262
if: steps.list-changed.outputs.changed == 'true'
6363

6464
- name: Create kind cluster
65-
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
65+
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
6666
if: steps.list-changed.outputs.changed == 'true'
6767

6868
- name: Load test images into KIND
@@ -72,7 +72,7 @@ jobs:
7272
if: steps.list-changed.outputs.changed == 'true'
7373

7474
- name: Install Flux CLI
75-
uses: fluxcd/flux2/action@5350425cdcd5fa015337e09fa502153c0275bd4b # main
75+
uses: fluxcd/flux2/action@8d5f40dca5aa5d3c0fc3414457dda15a0ac92fa4 # main
7676
if: steps.list-changed.outputs.changed == 'true'
7777

7878
- name: Install Source controller

.github/workflows/ossf.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -34,14 +34,14 @@ jobs:
3434
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
3535
# format to the repository Actions tab.
3636
- name: "Upload artifact"
37-
uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
37+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
3838
with:
3939
name: SARIF file
4040
path: results.sarif
4141
retention-days: 5
4242

4343
# required for Code scanning alerts
4444
- name: "Upload SARIF results to code scanning"
45-
uses: github/codeql-action/upload-sarif@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
45+
uses: github/codeql-action/upload-sarif@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
4646
with:
4747
sarif_file: results.sarif

.github/workflows/release-runners.yaml

+6-6
Original file line numberDiff line numberDiff line change
@@ -31,12 +31,12 @@ jobs:
3131
- name: Check out
3232
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
3333
- name: Setup QEMU
34-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
34+
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
3535
with:
3636
platforms: all
3737
- name: Setup Docker Buildx
3838
id: buildx
39-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
39+
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
4040
with:
4141
buildkitd-flags: "--debug"
4242
- name: Login to Docker Registry
@@ -46,7 +46,7 @@ jobs:
4646
username: ${{ github.actor }}
4747
password: ${{ secrets.GITHUB_TOKEN }}
4848
- name: Publish multi-arch tf-runner base image
49-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
49+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
5050
with:
5151
push: true
5252
no-cache: true
@@ -80,12 +80,12 @@ jobs:
8080
- name: Check out
8181
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
8282
- name: Setup QEMU
83-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
83+
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
8484
with:
8585
platforms: all
8686
- name: Setup Docker Buildx
8787
id: buildx
88-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
88+
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
8989
with:
9090
buildkitd-flags: "--debug"
9191
- name: Login to Docker Registry
@@ -95,7 +95,7 @@ jobs:
9595
username: ${{ github.actor }}
9696
password: ${{ secrets.GITHUB_TOKEN }}
9797
- name: Publish multi-arch tf-runner MPL images
98-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
98+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
9999
with:
100100
push: true
101101
no-cache: true

.github/workflows/release.yaml

+11-11
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,9 @@ jobs:
3434
- name: Setup Kustomize
3535
uses: fluxcd/pkg/actions/kustomize@30c101fc7c9fac4d84937ff4890a3da46a9db2dd # main
3636
- name: Setup Cosign
37-
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
37+
uses: sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
3838
- name: Setup Syft
39-
uses: anchore/sbom-action/download-syft@f5e124a5e5e1d497a692818ae907d3c45829d033 # v0.17.3
39+
uses: anchore/sbom-action/download-syft@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
4040
- name: Prepare
4141
id: prep
4242
run: |
@@ -47,12 +47,12 @@ jobs:
4747
echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" >> "$GITHUB_OUTPUT"
4848
echo "VERSION=${VERSION}" >> "$GITHUB_OUTPUT"
4949
- name: Setup QEMU
50-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
50+
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
5151
with:
5252
platforms: all
5353
- name: Setup Docker Buildx
5454
id: buildx
55-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
55+
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
5656
with:
5757
buildkitd-flags: "--debug"
5858
- name: Login to GitHub Container Registry
@@ -62,7 +62,7 @@ jobs:
6262
username: ${{ github.actor }}
6363
password: ${{ secrets.GITHUB_TOKEN }}
6464
- name: Publish multi-arch tofu-controller container image
65-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
65+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
6666
with:
6767
push: true
6868
no-cache: true
@@ -83,7 +83,7 @@ jobs:
8383
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
8484
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
8585
- name: Publish multi-arch tf-runner base image
86-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
86+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
8787
with:
8888
push: true
8989
builder: ${{ steps.buildx.outputs.name }}
@@ -102,7 +102,7 @@ jobs:
102102
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
103103
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
104104
- name: Publish multi-arch tf-runner container image
105-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
105+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
106106
with:
107107
push: true
108108
no-cache: true
@@ -123,7 +123,7 @@ jobs:
123123
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
124124
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
125125
- name: Publish multi-arch tf-runner-azure container image
126-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
126+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
127127
with:
128128
push: true
129129
no-cache: true
@@ -144,7 +144,7 @@ jobs:
144144
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
145145
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
146146
- name: Publish multi-arch branch-planner container image
147-
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
147+
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
148148
with:
149149
push: true
150150
no-cache: true
@@ -196,12 +196,12 @@ jobs:
196196
kustomize build ./config/package > ./config/release/${{ env.CONTROLLER }}.packages.yaml
197197
echo '[CHANGELOG](https://github.com/flux-iac/${{ env.CONTROLLER }}/blob/main/CHANGELOG.md)' > ./config/release/notes.md
198198
- name: Setup Go
199-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
199+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
200200
with:
201201
go-version-file: go.mod
202202
- name: Create release
203203
if: startsWith(github.ref, 'refs/tags/v')
204-
uses: goreleaser/goreleaser-action@286f3b13b1b49da4ac219696163fb8c1c93e1200 # v6.0.0
204+
uses: goreleaser/goreleaser-action@90a3faa9d0182683851fbfa97ca1a2cb983bfca3 # v6.2.1
205205
with:
206206
version: '~> v2'
207207
args: release --release-notes=./config/release/notes.md --skip=validate

.github/workflows/scan.yaml

+8-8
Original file line numberDiff line numberDiff line change
@@ -32,20 +32,20 @@ jobs:
3232
- name: Checkout repository
3333
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
3434
- name: Setup Go
35-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
35+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
3636
with:
3737
go-version-file: go.mod
3838
cache-dependency-path: |
3939
**/go.sum
4040
**/go.mod
4141
- name: Initialize CodeQL
42-
uses: github/codeql-action/init@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
42+
uses: github/codeql-action/init@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
4343
with:
4444
languages: go
4545
- name: Autobuild
46-
uses: github/codeql-action/autobuild@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
46+
uses: github/codeql-action/autobuild@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
48+
uses: github/codeql-action/analyze@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
4949

5050
trivy:
5151
name: Trivy
@@ -57,7 +57,7 @@ jobs:
5757
run: |
5858
make docker-buildx
5959
- name: Run Trivy vulnerability scanner on controller image
60-
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
60+
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
6161
with:
6262
image-ref: 'ghcr.io/flux-iac/tofu-controller:latest'
6363
format: 'table'
@@ -66,7 +66,7 @@ jobs:
6666
vuln-type: 'os,library'
6767
severity: 'CRITICAL,HIGH'
6868
- name: Run Trivy vulnerability scanner on runner image
69-
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
69+
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
7070
with:
7171
image-ref: 'ghcr.io/flux-iac/tf-runner:latest'
7272
format: 'table'
@@ -76,7 +76,7 @@ jobs:
7676
severity: 'CRITICAL,HIGH'
7777
skip-files: '/usr/local/bin/terraform' # false positive
7878
- name: Run Trivy vulnerability scanner on runner image
79-
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
79+
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
8080
with:
8181
image-ref: 'ghcr.io/flux-iac/tf-runner-azure:latest'
8282
format: 'table'
@@ -86,7 +86,7 @@ jobs:
8686
severity: 'CRITICAL,HIGH'
8787
skip-files: '/usr/local/bin/terraform' # false positive
8888
- name: Run Trivy vulnerability scanner on planner image
89-
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
89+
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
9090
with:
9191
image-ref: 'ghcr.io/flux-iac/branch-planner:latest'
9292
format: 'table'

.github/workflows/targeted-test.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
- name: Checkout
1616
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
1717
- name: Setup Go
18-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
18+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
1919
with:
2020
go-version-file: go.mod
2121
cache-dependency-path: |

.github/workflows/test.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ jobs:
6060
- name: Checkout
6161
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
6262
- name: Setup Go
63-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
63+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
6464
with:
6565
go-version-file: go.mod
6666
cache-dependency-path: |
@@ -87,7 +87,7 @@ jobs:
8787
- name: Checkout
8888
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
8989
- name: Setup Go
90-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
90+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
9191
with:
9292
go-version-file: go.mod
9393
cache-dependency-path: |

.github/workflows/verify.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
- name: Checkout
2222
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.0.0
2323
- name: Setup Go
24-
uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
24+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2525
with:
2626
go-version-file: go.mod
2727
cache-dependency-path: |

0 commit comments

Comments
 (0)