-
Notifications
You must be signed in to change notification settings - Fork 29
chore(deps): bump the actions-deps group with 15 updates #377
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
Bumps the actions-deps group with 15 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.13.0` | `2.13.1` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `212f9a7760ad2b8eb511185b841f3725a62c2ae0` | `d03a93c0dbfac6d6dd6a0d8a5e7daff992b07449` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.4.3` | `5.5.1` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.0.0` | `7.0.2` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.15` | `4.30.8` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `5.0.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `97d42c1b50f585f357413698aa1b779307aa0d52` | `5434409c2b6457c050f109d68b2547fcbf1db07b` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.7.0` | `5.8.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.6.0` | | [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description) | `a701644270a123c7b02b318a8e4fe71e15a8f3cb` | `31b7155ea9926ec41d93d6c52a18d3022bfd128a` | | [googleapis/release-please-action](https://github.com/googleapis/release-please-action) | `4.2.0` | `4.3.0` | | [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `1.5.2` | `2.0.3` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.20.6` | `0.20.8` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.3` | Updates `step-security/harden-runner` from 2.13.0 to 2.13.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@ec9f2d5...f4a75cf) Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) Updates `tj-actions/changed-files` from 212f9a7760ad2b8eb511185b841f3725a62c2ae0 to d03a93c0dbfac6d6dd6a0d8a5e7daff992b07449 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@212f9a7...d03a93c) Updates `codecov/codecov-action` from 5.4.3 to 5.5.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@18283e0...5a10915) Updates `anchore/scan-action` from 7.0.0 to 7.0.2 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@f660128...a5605eb) Updates `github/codeql-action` from 3.28.15 to 4.30.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3.28.15...f443b60) Updates `actions/download-artifact` from 4.3.0 to 5.0.0 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@d3f86a1...634f93c) Updates `softprops/action-gh-release` from 97d42c1b50f585f357413698aa1b779307aa0d52 to 5434409c2b6457c050f109d68b2547fcbf1db07b - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@97d42c1...5434409) Updates `docker/metadata-action` from 5.7.0 to 5.8.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@902fa8e...c1e5197) Updates `docker/login-action` from 3.4.0 to 3.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...5e57cd1) Updates `peter-evans/dockerhub-description` from a701644270a123c7b02b318a8e4fe71e15a8f3cb to 31b7155ea9926ec41d93d6c52a18d3022bfd128a - [Release notes](https://github.com/peter-evans/dockerhub-description/releases) - [Commits](peter-evans/dockerhub-description@a701644...31b7155) Updates `googleapis/release-please-action` from 4.2.0 to 4.3.0 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@a02a34c...c2a5a2b) Updates `iarekylew00t/verified-bot-commit` from 1.5.2 to 2.0.3 - [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases) - [Commits](IAreKyleW00t/verified-bot-commit@cd576ea...400b5d3) Updates `anchore/sbom-action` from 0.20.6 to 0.20.8 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f8bdd1d...aa0e114) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@f49aabe...4eaacf0) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: tj-actions/changed-files dependency-version: d03a93c0dbfac6d6dd6a0d8a5e7daff992b07449 dependency-type: direct:production dependency-group: actions-deps - dependency-name: codecov/codecov-action dependency-version: 5.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: anchore/scan-action dependency-version: 7.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: github/codeql-action dependency-version: 4.30.8 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/download-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: softprops/action-gh-release dependency-version: 5434409c2b6457c050f109d68b2547fcbf1db07b dependency-type: direct:production dependency-group: actions-deps - dependency-name: docker/metadata-action dependency-version: 5.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: docker/login-action dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: peter-evans/dockerhub-description dependency-version: 31b7155ea9926ec41d93d6c52a18d3022bfd128a dependency-type: direct:production dependency-group: actions-deps - dependency-name: googleapis/release-please-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: iarekylew00t/verified-bot-commit dependency-version: 2.0.3 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: anchore/sbom-action dependency-version: 0.20.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <[email protected]>
04018a9 to
f9dc69f
Compare
|
Let's wait for a few more days on this. I'm changing the dependabot configuration to add a delay for this type of updates in case if there is a supply chain issue. |
|
@dependabot rebase |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the actions-deps group with 15 updates:
2.13.02.13.14.2.25.0.0212f9a7760ad2b8eb511185b841f3725a62c2ae0d03a93c0dbfac6d6dd6a0d8a5e7daff992b074495.4.35.5.17.0.07.0.23.28.154.30.84.3.05.0.097d42c1b50f585f357413698aa1b779307aa0d525434409c2b6457c050f109d68b2547fcbf1db07b5.7.05.8.03.4.03.6.0a701644270a123c7b02b318a8e4fe71e15a8f3cb31b7155ea9926ec41d93d6c52a18d3022bfd128a4.2.04.3.01.5.22.0.30.20.60.20.82.4.12.4.3Updates
step-security/harden-runnerfrom 2.13.0 to 2.13.1Release notes
Sourced from step-security/harden-runner's releases.
Commits
f4a75cfMerge pull request #588 from step-security/rc-2695503d0ci: remove code-review workflow4b250a0ci: add job to confirm dist is as expected5b0ab6aupdate dependenciesd11f2c1fix bug where status code was not being preservedb3fc98eimprove error handling for policy store sceanrio92fc5d4update error messageb61b0a4policy store improvementse3d3f2buse GitHub release instead of packages646ac01update agentUpdates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
tj-actions/changed-filesfrom 212f9a7760ad2b8eb511185b841f3725a62c2ae0 to d03a93c0dbfac6d6dd6a0d8a5e7daff992b07449Changelog
Sourced from tj-actions/changed-files's changelog.
... (truncated)
Commits
d03a93cchore(deps): bump github/codeql-action from 3.30.5 to 3.30.6 (#2680)df9aabcchore(deps-dev): bump@types/nodefrom 24.6.1 to 24.6.2 (#2681)d6f020bchore(deps-dev): bump@types/nodefrom 24.5.2 to 24.6.1 (#2679)Updates
codecov/codecov-actionfrom 5.4.3 to 5.5.1Release notes
Sourced from codecov/codecov-action's releases.
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)a4803c1build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)3139621build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)fdcc847chore(release): 5.5.0 (#1865)Updates
anchore/scan-actionfrom 7.0.0 to 7.0.2Release notes
Sourced from anchore/scan-action's releases.
Commits
a5605ebchore(deps): update Grype to v0.101.1 (#532)9e84288chore(deps): update Grype to v0.101.0 (#530)109c104chore(deps): bump@actions/cachefrom 4.0.3 to 4.1.0 (#522)c455b6fchore(deps-dev): bump eslint from 9.36.0 to 9.37.0 (#526)cdad80achore(deps-dev): bump jest from 30.1.3 to 30.2.0 (#525)45eec0dchore(deps-dev): bump lint-staged from 16.2.1 to 16.2.4 (#528)a20799dchore(deps): bump actions/setup-node from 5.0.0 to 6.0.0 (#529)56e320fchore(deps-dev): bump@vercel/nccfrom 0.38.3 to 0.38.4 (#517)05c485fchore(deps-dev): bump eslint from 9.35.0 to 9.36.0 (#519)0c215f8chore(deps-dev): bump tar from 7.4.3 to 7.5.1 (#521)Updates
github/codeql-actionfrom 3.28.15 to 4.30.8Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
f443b60Merge pull request #3198 from github/update-v4.30.8-527f0f3247a2cb62Update changelog for v4.30.8527f0f3Merge pull request #3195 from github/dependabot/npm_and_yarn/npm-minor-37415c...f402506Merge pull request #3196 from github/dependabot/github_actions/dot-github/wor...f5e53f9Merge pull request #3197 from github/dependabot/github_actions/dot-github/wor...4e90a42Merge pull request #3193 from github/mbg/ff/tools-toolcache413a4a4Rebuild4521864Bump github/codeql-action from 3 to 4 in /.github/workflowseadf14bBump ruby/setup-rubye1257b6RebuildUpdates
actions/download-artifactfrom 4.3.0 to 5.0.0Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
634f93cMerge pull request #416 from actions/single-artifact-id-download-pathb19ff43refactor: resolve download path correctly in artifact download tests (mainly ...e262cbebundle distbff23f9update docsfff8c14fix download path logic when downloading a single artifact by id448e3f8Merge pull request #407 from actions/nebuk89-patch-147225c4Update README.mdUpdates
softprops/action-gh-releasefrom 97d42c1b50f585f357413698aa1b779307aa0d52 to 5434409c2b6457c050f109d68b2547fcbf1db07bChangelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
5434409chore(deps): bump@types/nodefrom 20.19.19 to 20.19.21 in the npm group (#679)6da8fa9release 2.4.1f38efdefix: gracefully fallback to body when body_path cannot be read (#671)cec1a11fix(util): support brace expansion globs containing commas in parseInputFiles...aec2ec5release 2.4.04db716bfeat: respect working_directory for files globs; add input and tests (#667)14820f2chore(deps): bump the npm group with 2 updates (#668)62c96d0release 2.3.47dc9b8afix(action): handle 422 already_exists race condition (#665)0f0e0b9chore(deps): bump the npm group with 3 updates (#666)Updates
docker/metadata-actionfrom 5.7.0 to 5.8.0Release notes
Sourced from docker/metadata-action's releases.
Commits
c1e5197Merge pull request #537 from crazy-max/pep440-match89dd65achore: update generated content699ee45allow to match part of the git tag or value for pep440 typee0542a6Merge pull request #536 from crazy-max/semver-match