-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Bump the github-actions group across 1 directory with 9 updates #3830
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
master
Choose a base branch
from
dependabot/github_actions/github-actions-856d6d6612
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Bump the github-actions group across 1 directory with 9 updates #3830
dependabot
wants to merge
1
commit into
master
from
dependabot/github_actions/github-actions-856d6d6612
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
3429053 to
aa860f4
Compare
aa860f4 to
c6ffcbd
Compare
c6ffcbd to
617040f
Compare
617040f to
7b042b9
Compare
7b042b9 to
1d103d0
Compare
1d103d0 to
9a8ae95
Compare
Bumps the github-actions group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.5.1` | `2.11.0` | | [actions/checkout](https://github.com/actions/checkout) | `2.7.0` | `4.2.2` | | [arduino/setup-protoc](https://github.com/arduino/setup-protoc) | `1.3.0` | `3.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `2.21.3` | `3.28.10` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `3.0.7` | `4.5.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `3.12.0` | `4.7.0` | | [google/osv-scanner-action](https://github.com/google/osv-scanner-action) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `e6898c9042613f73c90501bfa535f3c2c73b9140` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.3` | `2.4.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `4.6.1` | Updates `step-security/harden-runner` from 2.5.1 to 2.11.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@8ca2b8b...4d991eb) Updates `actions/checkout` from 2.7.0 to 4.2.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v2.7.0...11bd719) Updates `arduino/setup-protoc` from 1.3.0 to 3.0.0 - [Release notes](https://github.com/arduino/setup-protoc/releases) - [Commits](arduino/setup-protoc@149f6c8...c65c819) Updates `github/codeql-action` from 2.21.3 to 3.28.10 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v2.21.3...b56ba49) Updates `actions/dependency-review-action` from 3.0.7 to 4.5.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@7d90b4f...3b139cf) Updates `actions/setup-java` from 3.12.0 to 4.7.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@cd89f46...3a4f6e1) Updates `google/osv-scanner-action` from 8bd1ce1c4be9d98053ffd9e6e14585276a36762c to e6898c9042613f73c90501bfa535f3c2c73b9140 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@8bd1ce1...e6898c9) Updates `ossf/scorecard-action` from 2.3.3 to 2.4.1 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@dc50aa9...f49aabe) Updates `actions/upload-artifact` from 4.3.3 to 4.6.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6546280...4cec3d8) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: arduino/setup-protoc dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-java dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action dependency-type: direct:production dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
9a8ae95 to
4cd8e02
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 9 updates in the / directory:
2.5.12.11.02.7.04.2.21.3.03.0.02.21.33.28.103.0.74.5.03.12.04.7.08bd1ce1c4be9d98053ffd9e6e14585276a36762ce6898c9042613f73c90501bfa535f3c2c73b91402.3.32.4.14.3.34.6.1Updates
step-security/harden-runnerfrom 2.5.1 to 2.11.0Release notes
Sourced from step-security/harden-runner's releases.
... (truncated)
Commits
4d991ebMerge pull request #498 from step-security/rc-184ea872fUpdate README.md65d6f6eAdd workflows1034c9aUpdate package-lock.jsonab221e2Update agent7cb6c2fUpdate agentcb605e5Merge pull request #496 from step-security/fix-enobufs61144ddUpdate log statementb8be370Add try catch block6f6fa07Fix ENOBUFS issueUpdates
actions/checkoutfrom 2.7.0 to 4.2.2Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
11bd719Prepare 4.2.2 Release (#1953)e3d2460Expand unit test coverage (#1946)163217durl-helper.tsnow leverages well-known environment variables. (#1941)eef6144Prepare 4.2.1 release (#1925)6b42224Add workflow file for publishing releases to immutable action package (#1919)de5a000Check out other refs/* by commit if provided, fall back to ref (#1924)d632683Prepare 4.2.0 release (#1878)6d193bfBump braces from 3.0.2 to 3.0.3 (#1777)db0cee9Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)b684943Add Ref and Commit outputs (#1180)Updates
arduino/setup-protocfrom 1.3.0 to 3.0.0Release notes
Sourced from arduino/setup-protoc's releases.
Commits
c65c819Upgrade to node 20 (#95)52a53b4Merge pull request #93 from arduino/dependabot/npm_and_yarn/babel/traverse-7....cf7ab7fBump@babel/traversefrom 7.22.1 to 7.23.2e2995baCorrectconvetiontypo in README (#91)a8b67babump semver to 7.5.3 (#90)1530d62Bump semver from 7.5.1 to 7.5.2 (#87)0fbeb49Exposepathandversioninoutputs(#89)9b1ee5bv2 release note (#82)28fd3e5Support only the new protobuf versioning scheme (#78)Updates
github/codeql-actionfrom 2.21.3 to 3.28.10Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
b56ba49Merge pull request #2778 from github/update-v3.28.10-9856c48b160c9c77Update changelog for v3.28.109856c48Merge pull request #2773 from github/redsun82/rust9572e09Rust: fix log string1a52936Rust: special case default setupcf7e909Merge pull request #2772 from github/update-bundle/codeql-bundle-v2.20.5b7006aaMerge branch 'main' into update-bundle/codeql-bundle-v2.20.5cfedae7Rust: throw configuration errors if requested and not correctly enabled3971ed2Merge branch 'main' into redsun82/rustd38c6e6Merge pull request #2775 from github/angelapwen/bump-octokitUpdates
actions/dependency-review-actionfrom 3.0.7 to 4.5.0Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
3b139cfMerge pull request #851 from actions/ahmed3lmallah/prepare-for-4.5.0-released6807b6updating generated codec89b41faddressing lint issueseee97d8incrementing project version9d10182Merge pull request #827 from ebickle/fix/comment-warn-only9192be9Merge pull request #850 from actions/ahmed3lmallah/adressing-CVE-2024-215382fc8e23Using cross-spawn safe versionfb86db2fix: resolve race conditions in async core.group calls0a198abfix: replace integer failureCount with booleanfc499fcMerge branch 'main' into fix/comment-warn-onlyUpdates
actions/setup-javafrom 3.12.0 to 4.7.0Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
3a4f6e1Bump@types/jestfrom 29.5.12 to 29.5.14 (#729)25f376eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 (#727)d4e4b6bBump@actions/http-clientfrom 2.2.1 to 2.2.3 (#728)28b532bCreate dependabot.yml (#722)51ab6d2Update cache from 3.2.4 to 4.0.0 (#724)99d3141Update README.md (#723)7a6d8a8Add Support for JetBrains Runtime (#637)7136edcFix sbt and x86 CI failures on Ubuntu-24 (#693)8df1039RefineisGheslogic (#697)870c199Update workflows for GraalVM and Version Enhancements (#699)Updates
google/osv-scanner-actionfrom 8bd1ce1c4be9d98053ffd9e6e14585276a36762c to e6898c9042613f73c90501bfa535f3c2c73b9140Commits
e6898c9Merge pull request #57 from mullvad/support-checking-out-submodulesab8175fExpose workflow input to allow checking out git submodulesb291b69Merge pull request #52 from GeoDerp/mainadb15caMerge pull request #55 from renovate-bot/renovate/workflowsefbfc13chore(deps): update github/codeql-action action to v3.28.81266768Merge pull request #50 from renovate-bot/renovate/workflowsc10cec9chore(deps): update workflowsb49eaf1Merge branch 'main' into main764c918Merge pull request #53 from google/update-to-v1.9.2af3118aUpdate unified workflow example to point to v1.9.2 reusable workflowsUpdates
ossf/scorecard-actionfrom 2.3.3 to 2.4.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
f49aabebump docker to ghcr v2.4.1 (#1478)30a595b🌱 Bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 (#1515)69ae593omit vcs info from build (#1514)6a62a1cadd input for specifying--file-mode(#1509)2722664🌱 Bump the github-actions group with 2 updates (#1510)ae0ef31🌱 Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 (#1512)3676bbc🌱 Bump golang from 1.23.6 to 1.24.0 in the docker-images group (#1513)ae7548aLimit codeQL push trigger to main branch (#1507)9165624upgrade scorecard to v5.1.0 (#1508)620fd28🌱 Bump the github-actions group with 2 updates (#1505)Updates
actions/upload-artifactfrom 4.3.3 to 4.6.1Release notes
Sourced from actions/upload-artifact's releases.