Bump the github-actions-updates group with 2 updates#36
Conversation
Bumps the github-actions-updates group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml](https://github.com/lfit/releng-reusable-workflows). Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@9c091bb...3d3c42e) Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.7.4 to 0.9.1 - [Release notes](https://github.com/lfit/releng-reusable-workflows/releases) - [Commits](lfit/releng-reusable-workflows@5fa62e3...973bba8) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml dependency-version: 0.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #36 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/drools-pdp/+/146566 |
Bumps the github-actions-updates group with 2 updates: actions/checkout and lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml. Updates `actions/checkout` from 7.0.0 to 7.0.1 ## Release notes Sourced from actions/checkout's releases. v7.0.1 What's Changed skip running unsafe pr check if input is default by @aiqiaoy in actions/checkout#2518 trim only ascii whitespace for branch by @aiqiaoy in actions/checkout#2521 escape values passed to --unset by @aiqiaoy in actions/checkout#2530 Various dependency updates Full Changelog: actions/checkout@v7...v7.0.1 ## Changelog Sourced from actions/checkout's changelog. Changelog v7.0.1 Skip running unsafe pr check if input is default by @aiqiaoy in actions/checkout#2518 Trim only ascii whitespace for branch by @aiqiaoy in actions/checkout#2521 Escape values passed to --unset by @aiqiaoy in actions/checkout#2530 Various dependency updates v7.0.0 Block checking out fork PR for pull_request_target and workflow_run by @aiqiaoy in actions/checkout#2454 Various dependency updates v6.0.3 Fix checkout init for SHA-256 repositories by @yaananth in actions/checkout#2439 fix: expand merge commit SHA regex and add SHA-256 test cases by @yaananth in actions/checkout#2414 v6.0.2 Fix tag handling: preserve annotations and explicit fetch-tags by @ericsciple in actions/checkout#2356 v6.0.1 Add worktree support for persist-credentials includeIf by @ericsciple in actions/checkout#2327 v6.0.0 Persist creds to a separate file by @ericsciple in actions/checkout#2286 Update README to include Node.js 24 support details and requirements by @salmanmkc in actions/checkout#2248 v5.0.1 Port v6 cleanup to v5 by @ericsciple in actions/checkout#2301 v5.0.0 Update actions checkout to use node 24 by @salmanmkc in actions/checkout#2226 v4.3.1 Port v6 cleanup to v4 by @ericsciple in actions/checkout#2305 v4.3.0 docs: update README.md by @motss in actions/checkout#1971 Add internal repos for checking out multiple repositories by @mouismail in actions/checkout#1977 Documentation update - add recommended permissions to Readme by @benwells in actions/checkout#2043 Adjust positioning of user email note and permissions heading by @joshmgross in actions/checkout#2044 Update README.md by @nebuk89 in actions/checkout#2194 Update CODEOWNERS for actions by @TingluoHuang in actions/checkout#2224 Update package dependencies by @salmanmkc in actions/checkout#2236 v4.2.2 url-helper.ts now leverages well-known environment variables by @jww3 in actions/checkout#1941 Expand unit test coverage for isGhes by @jww3 in actions/checkout#1946 v4.2.1 Check out other refs/* by commit if provided, fall back to ref by @orhantoy in actions/checkout#1924 ... (truncated) ## Commits 3d3c42e prep v7.0.1 release (#2531) 2880268 escape values passed to --unset (#2530) 12cd223 trim only ascii whitespace for branch (#2521) 62661c4 skip running unsafe pr check if input is default (#2518) e8d4307 Bump the minor-actions-dependencies group with 2 updates (#2499) 631c942 eslint 9 (#2474) 4f1f4ae Bump actions/upload-artifact from 4 to 7 (#2476) ba09753 Bump actions/checkout from 6 to 7 (#2488) b9e0990 Bump docker/login-action from 3.3.0 to 4.2.0 (#2479) e8cb398 Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478) Additional commits viewable in compare view Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.7.4 to 0.9.1 ## Release notes Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases. v0.9.1 🔧 Maintenance 🔧 Chore: Bump sonarqube-cloud-scan-action to v1.2.1 @ModeSevenIndustrialSolutions (#810) Links Submit bugs/feature requests v0.9.0 ✨ New Features ✨ Feat: Add build stage to Sonatype Lifecycle scan @ModeSevenIndustrialSolutions (#809) Feat: Add PARALLEL input to rtdv3 verify workflow @ModeSevenIndustrialSolutions (#811) 🔧 Maintenance 🔧 Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#793) Chore: Bump actions/setup-java from 5.5.0 to 5.6.0 @dependabot[bot] (#796) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-jjb-verify.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#794) Chore: Bump lfreleng-actions/zizmor-scan-action from 0.4.0 to 0.5.0 @dependabot[bot] (#795) Chore: Bump github/codeql-action/analyze from 4.37.0 to 4.37.1 @dependabot[bot] (#798) Chore: Bump release-drafter/release-drafter/autolabeler from 7.5.1 to 7.6.0 @dependabot[bot] (#799) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#797) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/gerrit-compose-required-tox-verify.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#801) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-verify-github-actions.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#800) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-sonatype-lifecycle.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#802) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#803) Chore: Bump actions/setup-go from 6.5.0 to 7.0.0 @dependabot[bot] (#804) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-packer-verify.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#805) Chore: Bump github/codeql-action/init from 4.37.0 to 4.37.1 @dependabot[bot] (#806) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-repo-linting.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#807) Chore: pre-commit linting updates @pre-commit-ci[bot] (#808) Links Submit bugs/feature requests v0.8.1 🔧 Maintenance 🔧 Chore: Bump egress allow-list pin to v0.6.0 @ModeSevenIndustrialSolutions (#792) Links Submit bugs/feature requests ... (truncated) ## Commits 973bba8 Merge pull request #810 from modeseven-lfit/chore/bump-sonarqube-scan-v1.2.1 eb97ae4 Merge pull request #811 from modeseven-lfit/docs-parallel-toggle a7985cf Feat: Add PARALLEL input to rtdv3 verify workflow 05bf980 Merge pull request #809 from modeseven-lfit/feat/sonatype-lifecycle-build-stage fb765b8 Merge pull request #808 from lfit/pre-commit-ci-update-config bbc6947 Merge pull request #807 from lfit/dependabot/github_actions/lfit/releng-reusa a46b638 Merge pull request #806 from lfit/dependabot/github_actions/github/codeql-act d642a61 Merge pull request #805 from lfit/dependabot/github_actions/lfit/releng-reusa 8a255ea Merge pull request #804 from lfit/dependabot/github_actions/actions/setup-go- dae7013 Merge pull request #803 from lfit/dependabot/github_actions/actions/checkout- Additional commits viewable in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Ic3e4c5fc687dc50705a0ae033d89d7f0cdb47f31 GitHub-PR: #36 GitHub-Hash: dfe6c8ceccc991d6 Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 2 updates: actions/checkout and lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml.
Updates
actions/checkoutfrom 7.0.0 to 7.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yamlfrom 0.7.4 to 0.9.1Release notes
Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases.
... (truncated)
Commits
973bba8Merge pull request #810 from modeseven-lfit/chore/bump-sonarqube-scan-v1.2.1eb97ae4Merge pull request #811 from modeseven-lfit/docs-parallel-togglea7985cfFeat: Add PARALLEL input to rtdv3 verify workflow05bf980Merge pull request #809 from modeseven-lfit/feat/sonatype-lifecycle-build-stagefb765b8Merge pull request #808 from lfit/pre-commit-ci-update-configbbc6947Merge pull request #807 from lfit/dependabot/github_actions/lfit/releng-reusa...a46b638Merge pull request #806 from lfit/dependabot/github_actions/github/codeql-act...d642a61Merge pull request #805 from lfit/dependabot/github_actions/lfit/releng-reusa...8a255eaMerge pull request #804 from lfit/dependabot/github_actions/actions/setup-go-...dae7013Merge pull request #803 from lfit/dependabot/github_actions/actions/checkout-...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions