chore(deps): bump the actions-deps-minor-patch group across 1 directory with 8 updates #14
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the actions-deps-minor-patch group with 8 updates in the / directory:
5.3.0
5.4.0
6.2.0
6.3.0
6.1.0
6.3.0
2.4.0
2.4.1
4.6.0
4.6.2
3.28.5
3.28.13
6.2.0
7.0.0
0.29.0
0.30.0
Updates
actions/setup-go
from 5.3.0 to 5.4.0Release notes
Sourced from actions/setup-go's releases.
Commits
0aaccfd
Bump undici from 5.28.4 to 5.28.5 (#541)c4c1141
upgrade actions/cache to 4.0.2 (#568)5a083d0
Bump eslint-config-prettier from 8.10.0 to 10.0.1 (#536)1d82324
Bump semver from 7.6.0 to 7.6.3 (#535)Updates
crazy-max/ghaction-import-gpg
from 6.2.0 to 6.3.0Release notes
Sourced from crazy-max/ghaction-import-gpg's releases.
Commits
e89d409
Merge pull request #215 from crazy-max/dependabot/npm_and_yarn/openpgp-6.1.09239589
fix README177db9d
chore: update generated content78b11f3
build(deps): bump openpgp from 5.11.2 to 6.1.0bc96911
Merge pull request #218 from crazy-max/bake-v6b70aa9b
ci: update bake-action to v6d690cc9
Merge pull request #212 from crazy-max/dependabot/npm_and_yarn/cross-spawn-7.0.69e887f4
Merge pull request #211 from crazy-max/dependabot/github_actions/codecov/code...442980b
ci: fix deprecated codecov inputa0098b6
Merge pull request #217 from crazy-max/gha-permsUpdates
goreleaser/goreleaser-action
from 6.1.0 to 6.3.0Release notes
Sourced from goreleaser/goreleaser-action's releases.
Commits
9c156ee
ci: update bake-action to v6 (#493)73c477b
chore(deps): bump undici from 5.28.3 to 5.28.5 (#488)19c00a9
chore(deps): bump codecov/codecov-action from 4 to 5 (#481)90a3faa
chore(deps): bake vendor0262998
test: fixes450d3a4
test: fix configs25b92ab
chore(deps): update semver and tool-cachebc0ac76
chore(deps): update actions842e7cc
feat: update for goreleaser v2.7d28c982
chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 (#482)Updates
ossf/scorecard-action
from 2.4.0 to 2.4.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
f49aabe
bump docker to ghcr v2.4.1 (#1478)30a595b
🌱 Bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 (#1515)69ae593
omit vcs info from build (#1514)6a62a1c
add input for specifying--file-mode
(#1509)2722664
🌱 Bump the github-actions group with 2 updates (#1510)ae0ef31
🌱 Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 (#1512)3676bbc
🌱 Bump golang from 1.23.6 to 1.24.0 in the docker-images group (#1513)ae7548a
Limit codeQL push trigger to main branch (#1507)9165624
upgrade scorecard to v5.1.0 (#1508)620fd28
🌱 Bump the github-actions group with 2 updates (#1505)Updates
actions/upload-artifact
from 4.6.0 to 4.6.2Release notes
Sourced from actions/upload-artifact's releases.
Commits
ea165f8
Merge pull request #685 from salmanmkc/salmanmkc/3-new-upload-artifacts-release0839620
Prepare for new release of actions/upload-artifact with new toolkit cache ver...4cec3d8
Merge pull request #673 from actions/yacaovsnc/artifact_2.2.2e9fad96
license cache update for artifactb26fd06
Update to use artifact 2.2.2 packageUpdates
github/codeql-action
from 3.28.5 to 3.28.13Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
1b549b9
Merge pull request #2819 from github/update-v3.28.13-e0ea1410282630c8
Update changelog for v3.28.13e0ea141
Merge pull request #2818 from github/cklin/empty-pr-diff-rangeb361a91
Diff-informed analysis: fix empty PR handlingbd1d9ab
Merge pull request #2816 from github/cklin/overlay-file-listb98ae6c
Add overlay-database-utils tests9825184
Add getFileOidsUnderPath() testsac67cff
Merge pull request #2817 from github/cklin/default-setup-diff-informed9c674ba
build: refresh js filesd109dd5
Detect PR branches for Default SetupUpdates
golangci/golangci-lint-action
from 6.2.0 to 7.0.0Release notes
Sourced from golangci/golangci-lint-action's releases.
... (truncated)
Commits
1481404
7.0.0dec74fa
feat: golangci-lint v2 support (#1198)1f07148
build(deps-dev): bump the dev-dependencies group with 3 updates (#1207)9938e10
docs: fix checks permissions for annotations (#1204)b91d580
docs: update annotation permissions (#1203)55c2c14
6.5.2911ec56
fix: update max version (#1201)eb5c0cc
build(deps-dev): bump the dev-dependencies group with 2 updates (#1199)4696ba8
6.5.12ee514f
feat: restrict action v6 on golangci-lint v1 (#1194)Updates
aquasecurity/trivy-action
from 0.29.0 to 0.30.0Release notes
Sourced from aquasecurity/trivy-action's releases.
Commits
6c175e9
chore: bump trivy to v0.60.0 (#453)53e8848
Improve README/SBOM (#439)ef1b561
fix: typo in description of an input for action.yaml (#452)a11da62
fix: Update default trivy version in README (#444)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions