-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(gha)(deps): bump the github-actions group with 10 updates #221
Merged
jmuelbert
merged 1 commit into
main
from
dependabot/github_actions/github-actions-a1851cb24e
Aug 4, 2024
Merged
fix(gha)(deps): bump the github-actions group with 10 updates #221
jmuelbert
merged 1 commit into
main
from
dependabot/github_actions/github-actions-a1851cb24e
Aug 4, 2024
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the github-actions group with 10 updates: | Package | From | To | | --- | --- | --- | | [actions/setup-python](https://github.com/actions/setup-python) | `5.1.0` | `5.1.1` | | [codacy/codacy-analysis-cli-action](https://github.com/codacy/codacy-analysis-cli-action) | `4.4.1` | `4.4.5` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.25.11` | `3.25.15` | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2.1.0` | `2.2.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.3.3` | `4.3.4` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `7.12.0` | `7.13.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `4.3.4` | | [fsfe/reuse-action](https://github.com/fsfe/reuse-action) | `3.0.0` | `4.0.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.3` | `2.4.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.1.7` | `4.1.8` | Updates `actions/setup-python` from 5.1.0 to 5.1.1 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@82c7e63...39cd149) Updates `codacy/codacy-analysis-cli-action` from 4.4.1 to 4.4.5 - [Release notes](https://github.com/codacy/codacy-analysis-cli-action/releases) - [Commits](codacy/codacy-analysis-cli-action@3ff8e64...97bf5df) Updates `github/codeql-action` from 3.25.11 to 3.25.15 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b611370...afb54ba) Updates `dependabot/fetch-metadata` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@5e5f996...dbb049a) Updates `actions/dependency-review-action` from 4.3.3 to 4.3.4 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@72eb03d...5a2ce3f) Updates `oxsecurity/megalinter` from 7.12.0 to 7.13.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@5199c63...bacb5f8) Updates `actions/upload-artifact` from 4.3.3 to 4.3.4 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6546280...0b2256b) Updates `fsfe/reuse-action` from 3.0.0 to 4.0.0 - [Release notes](https://github.com/fsfe/reuse-action/releases) - [Commits](fsfe/reuse-action@a46482c...3ae3c6b) Updates `ossf/scorecard-action` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@dc50aa9...62b2cac) Updates `actions/download-artifact` from 4.1.7 to 4.1.8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@65a9edc...fa0a91b) --- updated-dependencies: - dependency-name: actions/setup-python dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: codacy/codacy-analysis-cli-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: dependabot/fetch-metadata dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: fsfe/reuse-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/download-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
labels
Aug 1, 2024
Merging to
|
Dependency ReviewThe following issues were found:
License Issues.github/workflows/reuse-check.yml
OpenSSF ScorecardScorecard details
Scanned Manifest Files.github/workflows/ci.yml.github/workflows/codacy-analysis.yml.github/workflows/codeql-analysis.yml.github/workflows/dependabot-merge.yml.github/workflows/dependency-review.yml.github/workflows/devskim-analysis.yml.github/workflows/mega-linter.yml.github/workflows/mkdocs-pages.yml.github/workflows/ossar-analysis.yml.github/workflows/reuse-check.yml.github/workflows/scorecard.yml.github/workflows/semgrep.yml |
Here are some friendly prose warnings from
|
jmuelbert
approved these changes
Aug 4, 2024
jmuelbert
deleted the
dependabot/github_actions/github-actions-a1851cb24e
branch
August 4, 2024 12:45
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 10 updates:
5.1.0
5.1.1
4.4.1
4.4.5
3.25.11
3.25.15
2.1.0
2.2.0
4.3.3
4.3.4
7.12.0
7.13.0
4.3.3
4.3.4
3.0.0
4.0.0
2.3.3
2.4.0
4.1.7
4.1.8
Updates
actions/setup-python
from 5.1.0 to 5.1.1Release notes
Sourced from actions/setup-python's releases.
Commits
39cd149
Documentation update for cache (#873)a0d74c0
fix(ci): update all failing workflows (#863)4eb7dbc
Bump braces from 3.0.2 to 3.0.3 (#893)Updates
codacy/codacy-analysis-cli-action
from 4.4.1 to 4.4.5Release notes
Sourced from codacy/codacy-analysis-cli-action's releases.
... (truncated)
Commits
97bf5df
feat: build for release3ad04f4
feat: build for release3987b1d
feat: build for release55bddef
feat: build for releaseUpdates
github/codeql-action
from 3.25.11 to 3.25.15Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
afb54ba
Merge pull request #2391 from github/update-v3.25.15-4b1d7da1057a4b22
Update changelog for v3.25.154b1d7da
Merge pull request #2385 from github/update-bundle/codeql-bundle-v2.18.197e8f69
Merge branch 'main' into update-bundle/codeql-bundle-v2.18.1f8e94f9
Merge pull request #2389 from github/mergeback/v3.25.14-to-main-5cf07d8b9e375a8
Update checked-in dependencies02d73d0
Update changelog and version after v3.25.145cf07d8
Merge pull request #2388 from github/update-v3.25.14-1b214db07ecab108
Update changelog for v3.25.141b214db
Merge pull request #2387 from github/aibaars/remove-set-secretUpdates
dependabot/fetch-metadata
from 2.1.0 to 2.2.0Release notes
Sourced from dependabot/fetch-metadata's releases.
Commits
dbb049a
v2.2.0 (#520)36bf1f9
Merge pull request #532 from dependabot/dependabot/npm_and_yarn/braces-3.0.3a3420b5
Bump braces from 3.0.2 to 3.0.3006e43f
Merge pull request #534 from dependabot/dependabot/github_actions/actions/cre...9c55ebe
Bump actions/create-github-app-token from 1.10.0 to 1.10.2325b863
Merge pull request #523 from dependabot/dependabot/github_actions/actions/cre...aec2f3e
Bump actions/create-github-app-token from 1.9.0 to 1.10.0Updates
actions/dependency-review-action
from 4.3.3 to 4.3.4Release notes
Sourced from actions/dependency-review-action's releases.
Commits
5a2ce3f
Merge pull request #791 from actions/juxtin/update-versionac6a6ad
Prepare even more for v4.3.43e2b917
Merge pull request #790 from actions/juxtin/update-versiond9ab9c8
Update version in package.json8c152c7
Merge pull request #769 from actions/dependabot/npm_and_yarn/zod-3.23.80085d30
Update dist08b5bf2
Bump zod from 3.22.4 to 3.23.8986fce9
Merge pull request #784 from actions/dependabot/npm_and_yarn/got-14.4.128743f8
Merge pull request #719 from actions/change-spdx-parserd6f34c3
Merge pull request #789 from actions/dependabot/npm_and_yarn/braces-3.0.3Updates
oxsecurity/megalinter
from 7.12.0 to 7.13.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
bacb5f8
Release MegaLinter v7.13.072065d9
[automation] Auto-update linters version, help and documentation (#3746)1b22656
chore(deps): update ghcr.io/terraform-linters/tflint docker tag to v0.52.0 (#...9d76a95
[automation] Auto-update linters version, help and documentation (#3744)350fd81
add SARIF support (v2) for PHP linters (#3745)8d1ea78
chore(deps): update dependency sfdx-hardis to v4.42.0 (#3732)a6a08f4
[automation] Auto-update linters version, help and documentation (#3742)fae7d18
chore(deps): update dependency@salesforce/sfdx-scanner
to v4 (#3702)1a904bb
[automation] Auto-update linters version, help and documentation (#3740)7ed4677
chore(deps): update mstruebing/editorconfig-checker docker tag to v3.0.3 (#3735)Updates
actions/upload-artifact
from 4.3.3 to 4.3.4Release notes
Sourced from actions/upload-artifact's releases.
Commits
0b2256b
Merge pull request #584 from actions/robherley/bump-pkgs488dcef
licensed cache04c51f5
ncc32a9e27
bump@actions/artifact
and npm audit552bf37
new version79616d2
Merge pull request #565 from actions/eggyhead/use-artifact-v2.1.6Updates
fsfe/reuse-action
from 3.0.0 to 4.0.0Release notes
Sourced from fsfe/reuse-action's releases.
Commits
3ae3c6b
Merge pull request #32 from carmenbianca/bump-v4f807a9c
Bump to v400117e7
Merge pull request #29 from jsoref/spelling910515a
spelling: githubcfe1368
activate v3 workflow testUpdates
ossf/scorecard-action
from 2.3.3 to 2.4.0Release notes
Sourced from ossf/scorecard-action's releases.
Commits
62b2cac
bump docker tag to v2.4.0 for release (#1414)c09630c
lower license score alert threshold to 9 (#1411)cf8594c
🌱 Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.3.0 (#1413)de5fcb9
🌱 Bump the github-actions group with 2 updates (#1412)a46b90b
bump scorecard to v5.0.0 release (#1410)9fc518d
🌱 Bump golang in the docker-images group (#1407)a8eaa1b
🌱 Bump the github-actions group with 2 updates (#1408)873d5fd
🌱 Bump the github-actions group across 1 directory with 2 updates (#...54cc1fe
🌱 Bump the docker-images group with 2 updates (#1401)82bcb91
🌱 Bump golang.org/x/net from 0.26.0 to 0.27.0 (#1400)Updates
actions/download-artifact
from 4.1.7 to 4.1.8Release notes
Sourced from actions/download-artifact's releases.
Commits
fa0a91b
Merge pull request #341 from actions/robherley/bump-pkgsb54d088
Update@actions/artifact
version, bump dependenciesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions