-
Notifications
You must be signed in to change notification settings - Fork 1
⬆️ gha: Bump the github-actions group with 14 updates #145
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
⬆️ gha: Bump the github-actions group with 14 updates #145
Conversation
Bumps the github-actions group with 14 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.12.1` | `2.13.1` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.5.0` | `6.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.29.0` | `4.31.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.7.1` | `4.8.1` | | [reviewdog/action-tflint](https://github.com/reviewdog/action-tflint) | `1.24.2` | `1.25.0` | | [reviewdog/action-trivy](https://github.com/reviewdog/action-trivy) | `1.13.10` | `1.14.0` | | [reviewdog/action-misspell](https://github.com/reviewdog/action-misspell) | `1.26.3` | `1.27.0` | | [reviewdog/action-actionlint](https://github.com/reviewdog/action-actionlint) | `1.65.2` | `1.68.0` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.0.1` | | [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `5.3.1` | `6.0.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.3.2` | `2.4.1` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.2` | `2.4.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `5.0.0` | Updates `step-security/harden-runner` from 2.12.1 to 2.13.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@002fdce...f4a75cf) Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) Updates `actions/setup-go` from 5.5.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@d35c59a...4469467) Updates `github/codeql-action` from 3.29.0 to 4.31.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ce28f5b...4e94bd1) Updates `actions/dependency-review-action` from 4.7.1 to 4.8.1 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@da24556...40c09b7) Updates `reviewdog/action-tflint` from 1.24.2 to 1.25.0 - [Release notes](https://github.com/reviewdog/action-tflint/releases) - [Commits](reviewdog/action-tflint@41b4770...54a5e5a) Updates `reviewdog/action-trivy` from 1.13.10 to 1.14.0 - [Release notes](https://github.com/reviewdog/action-trivy/releases) - [Commits](reviewdog/action-trivy@0cab87b...a1e6d7d) Updates `reviewdog/action-misspell` from 1.26.3 to 1.27.0 - [Release notes](https://github.com/reviewdog/action-misspell/releases) - [Commits](reviewdog/action-misspell@9daa94a...d642941) Updates `reviewdog/action-actionlint` from 1.65.2 to 1.68.0 - [Release notes](https://github.com/reviewdog/action-actionlint/releases) - [Commits](reviewdog/action-actionlint@a5524e1...f00ad06) Updates `actions/labeler` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...634933e) Updates `mikepenz/release-changelog-builder-action` from 5.3.1 to 6.0.0 - [Release notes](https://github.com/mikepenz/release-changelog-builder-action/releases) - [Commits](mikepenz/release-changelog-builder-action@5fb6e51...d702b5b) Updates `softprops/action-gh-release` from 2.3.2 to 2.4.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@72f2c25...6da8fa9) Updates `ossf/scorecard-action` from 2.4.2 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@05b42c6...4eaacf0) Updates `actions/upload-artifact` from 4.6.2 to 5.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...330a01c) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.31.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-tflint dependency-version: 1.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-trivy dependency-version: 1.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-misspell dependency-version: 1.27.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-actionlint dependency-version: 1.68.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: mikepenz/release-changelog-builder-action dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 2.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
simply may be insensitive, try not to use it simple retext-equality
| # For most projects, this workflow file will not need changing; you simply need |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the github-actions group with 14 updates:
2.12.12.13.14.2.25.0.05.5.06.0.03.29.04.31.04.7.14.8.11.24.21.25.01.13.101.14.01.26.31.27.01.65.21.68.05.0.06.0.15.3.16.0.02.3.22.4.12.4.22.4.34.6.25.0.0Updates
step-security/harden-runnerfrom 2.12.1 to 2.13.1Release notes
Sourced from step-security/harden-runner's releases.
Commits
f4a75cfMerge pull request #588 from step-security/rc-2695503d0ci: remove code-review workflow4b250a0ci: add job to confirm dist is as expected5b0ab6aupdate dependenciesd11f2c1fix bug where status code was not being preservedb3fc98eimprove error handling for policy store sceanrio92fc5d4update error messageb61b0a4policy store improvementse3d3f2buse GitHub release instead of packages646ac01update agentUpdates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
actions/setup-gofrom 5.5.0 to 6.0.0Release notes
Sourced from actions/setup-go's releases.
Commits
4469467Bump actions/checkout from 4 to 5 (#631)e093d1eNode 24 upgrade (#624)1d76b95Improve toolchain handling (#460)e75c3e8Bumpform-datato bring in fix for critical vulnerability (#618)8e57b58Bump eslint-plugin-jest from 28.11.0 to 29.0.1 (#603)7c0b336Bump typescript from 5.4.2 to 5.8.3 (#538)6f26dccBump undici from 5.28.5 to 5.29.0 (#594)8d4083aBump@typescript-eslint/parserfrom 5.62.0 to 8.32.0 (#590)fa96338Bump@actions/tool-cachefrom 2.0.1 to 2.0.2 (#591)4de67c0Bump@types/jestfrom 29.5.12 to 29.5.14 (#589)Updates
github/codeql-actionfrom 3.29.0 to 4.31.0Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
4e94bd1Merge pull request #3235 from github/update-v4.31.0-1d36546c18f11182Update changelog for v4.31.01d36546Merge pull request #3234 from github/mbg/changelog/post-processing08ada26Add changelog entry for post-processing changeb843cbeMerge pull request #3233 from github/mbg/getOptionalEnvVar1ecd563UsegetOptionalEnvVarinwritePostProcessedFilese576807Merge pull request #3223 from github/henrymercer/bump-minimumad35676AddgetOptionalEnvVarfunctiond75645bMerge pull request #3222 from github/mbg/upload-lib/post-process710606cCheck thatoutputPathis non-emptyUpdates
actions/dependency-review-actionfrom 4.7.1 to 4.8.1Release notes
Sourced from actions/dependency-review-action's releases.
Commits
40c09b7Merge pull request #1001 from actions/ahpook/v4.8.1-release4552948Bump version for 4.8.1 releasee63da9aMerge pull request #1000 from actions/ahpook/deprecation-redux71365c7(bug) Fix spamming link test in deprecation warning (again)56339e5Merge pull request #988 from actions/brrygrdn/rc-4.8.01688b74Bump to a 4.8.031c9f17Merge pull request #987 from actions/rc-4.7.4eacde78Update version8151009Merge pull request #986 from actions/brrygrdn/rc-4.7.4b472ec9Add a quick regression test for the artefact summaryUpdates
reviewdog/action-tflintfrom 1.24.2 to 1.25.0Release notes
Sourced from reviewdog/action-tflint's releases.
Commits
54a5e5achore(deps): update reviewdog/reviewdog to 0.21.0 (#101)92ecd5bREADME: Pin GitHub Actions with commit SHA using pinact (#108)4e022bbchore(deps): update reviewdog/action-misspell action to v1.26.3 (#106)1848510chore(deps): update reviewdog/action-depup action to v1.6.4 (#104)f1101e4chore(deps): update reviewdog/action-misspell action to v1.26.2 (#105)Updates
reviewdog/action-trivyfrom 1.13.10 to 1.14.0Release notes
Sourced from reviewdog/action-trivy's releases.
Commits
a1e6d7dMerge pull request #104 from reviewdog/depup/reviewdog20b6816chore(deps): update reviewdog to 0.21.0a1a479dMerge pull request #94 from reviewdog/renovate/azurerm-4.x7a02290chore(deps): update terraform azurerm to ~> 4.26.0590ac69Merge pull request #93 from reviewdog/renovate/aws-5.xf895ad5chore(deps): update terraform aws to ~> 5.94.05392bccMerge pull request #92 from reviewdog/renovate/azurerm-4.x0e5f775chore(deps): update terraform azurerm to ~> 4.25.090be6baMerge pull request #91 from reviewdog/renovate/aws-5.x536d9aachore(deps): update terraform aws to ~> 5.93.0Updates
reviewdog/action-misspellfrom 1.26.3 to 1.27.0Release notes
Sourced from reviewdog/action-misspell's releases.
Commits
d642941Merge pull request #86 from jml/bump-reviewdog-version3ec4ec5chore: Bump reviewdog version1d5fb16Merge pull request #81 from reviewdog/pinact-readme-20250319-0319573c33d77README: Pin GitHub Actions with commit SHA using pinact5c476d5Merge pull request #80 from reviewdog/renovate/haya14busa-action-depup-1.xf8d22a7chore(deps): update haya14busa/action-depup action to v1.6.4Updates
reviewdog/action-actionlintfrom 1.65.2 to 1.68.0Release notes
Sourced from reviewdog/action-actionlint's releases.
Commits
f00ad06bump v1.68.0cc60a5aMerge branch 'main' into releases/v18e1a350Merge pull request #177 from reviewdog/depup/actionlint56a8e90chore(deps): update actionlint to 1.7.85b9cd2aMerge pull request #176 from reviewdog/renovate/python-3.x734cdfechore(deps): update python docker tag to v3.140b71b30Merge pull request #174 from reviewdog/renovate/shogo82148-actions-create-rel...36e24a5chore(deps): update shogo82148/actions-create-release action to v1.7.995395aabump v1.67.0af47a90Merge branch 'main' into releases/v1Updates
actions/labelerfrom 5.0.0 to 6.0.1Release notes
Sourced from actions/labeler's releases.