-
Notifications
You must be signed in to change notification settings - Fork 6
chore(deps): bump the actions-deps-minor-patch group across 1 directory with 10 updates #31
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
chore(deps): bump the actions-deps-minor-patch group across 1 directory with 10 updates #31
Conversation
92174b6 to
8ef9d8e
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
8ef9d8e to
7f7a90d
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
1 similar comment
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
7f7a90d to
4ba92a0
Compare
…ry with 10 updates Bumps the actions-deps-minor-patch group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.3.0` | `5.5.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.18.0` | `0.20.4` | | [crazy-max/ghaction-import-gpg](https://github.com/crazy-max/ghaction-import-gpg) | `6.2.0` | `6.3.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.1.0` | `6.3.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.2` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.0` | `4.6.2` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.5` | `3.29.8` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `6.2.0` | `8.0.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.29.0` | `0.32.0` | Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) Updates `actions/setup-go` from 5.3.0 to 5.5.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@f111f33...d35c59a) Updates `anchore/sbom-action` from 0.18.0 to 0.20.4 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f325610...7b36ad6) Updates `crazy-max/ghaction-import-gpg` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/crazy-max/ghaction-import-gpg/releases) - [Commits](crazy-max/ghaction-import-gpg@cb9bde2...e89d409) Updates `goreleaser/goreleaser-action` from 6.1.0 to 6.3.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@9ed2f89...9c156ee) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.2 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@62b2cac...05b42c6) Updates `actions/upload-artifact` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@65c4c4a...ea165f8) Updates `github/codeql-action` from 3.28.5 to 3.29.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@f6091c0...76621b6) Updates `golangci/golangci-lint-action` from 6.2.0 to 8.0.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@ec5d184...4afd733) Updates `aquasecurity/trivy-action` from 0.29.0 to 0.32.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@18f2510...dc5a429) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps-minor-patch - dependency-name: actions/setup-go dependency-version: 5.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch - dependency-name: anchore/sbom-action dependency-version: 0.20.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch - dependency-name: crazy-max/ghaction-import-gpg dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch - dependency-name: goreleaser/goreleaser-action dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch - dependency-name: ossf/scorecard-action dependency-version: 2.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps-minor-patch - dependency-name: actions/upload-artifact dependency-version: 4.6.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps-minor-patch - dependency-name: github/codeql-action dependency-version: 3.29.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch - dependency-name: golangci/golangci-lint-action dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps-minor-patch - dependency-name: aquasecurity/trivy-action dependency-version: 0.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
4ba92a0 to
e8dfc68
Compare
Bumps the actions-deps-minor-patch group with 10 updates in the / directory:
4.2.25.0.05.3.05.5.00.18.00.20.46.2.06.3.06.1.06.3.02.4.02.4.24.6.04.6.23.28.53.29.86.2.08.0.00.29.00.32.0Updates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
actions/setup-gofrom 5.3.0 to 5.5.0Release notes
Sourced from actions/setup-go's releases.
Commits
d35c59achore: update discussions url (#527)29694d7Add manifest validation and improve error handling (#586)78535ddBump eslint-plugin-jest from 27.9.0 to 28.11.0 (#537)bb65d88Bump ts-jest from 29.1.2 to 29.3.2 (#582)7f17e83Bump@actions/globfrom 0.4.0 to 0.5.0 (#573)dca8468Update self-hosted environment validation and bump undici version (#556)691cc35upgrade actions/cache to 4.0.3 (#574)0aaccfdBump undici from 5.28.4 to 5.28.5 (#541)c4c1141upgrade actions/cache to 4.0.2 (#568)5a083d0Bump eslint-config-prettier from 8.10.0 to 10.0.1 (#536)Updates
anchore/sbom-actionfrom 0.18.0 to 0.20.4Release notes
Sourced from anchore/sbom-action's releases.
Commits
7b36ad6chore(deps): update Syft to v1.29.0 (#529)9e07fd7fix: strip emoji from correlator names (#527)cee1b8echore(deps): update Syft to v1.28.0 (#526)9246b90chore(deps): update Syft to v1.27.1 (#525)5f8d644chore(deps): update Syft to v1.26.1 (#524)e11c554chore(deps): update Syft to v1.24.0 (#522)9f73021chore(deps): update Syft to v1.23.0 (#521)a669da5chore(deps): update Syft to v1.22.0 (#517)5aeee89chore(deps): bump peter-evans/create-pull-request from 7.0.6 to 7.0.8 (#519)79202aechore(deps): bump cross-spawn (#514)Updates
crazy-max/ghaction-import-gpgfrom 6.2.0 to 6.3.0Release notes
Sourced from crazy-max/ghaction-import-gpg's releases.
Commits
e89d409Merge pull request #215 from crazy-max/dependabot/npm_and_yarn/openpgp-6.1.09239589fix README177db9dchore: update generated content78b11f3build(deps): bump openpgp from 5.11.2 to 6.1.0bc96911Merge pull request #218 from crazy-max/bake-v6b70aa9bci: update bake-action to v6d690cc9Merge pull request #212 from crazy-max/dependabot/npm_and_yarn/cross-spawn-7.0.69e887f4Merge pull request #211 from crazy-max/dependabot/github_actions/codecov/code...442980bci: fix deprecated codecov inputa0098b6Merge pull request #217 from crazy-max/gha-permsUpdates
goreleaser/goreleaser-actionfrom 6.1.0 to 6.3.0Release notes
Sourced from goreleaser/goreleaser-action's releases.
Commits
9c156eeci: update bake-action to v6 (#493)73c477bchore(deps): bump undici from 5.28.3 to 5.28.5 (#488)19c00a9chore(deps): bump codecov/codecov-action from 4 to 5 (#481)90a3faachore(deps): bake vendor0262998test: fixes450d3a4test: fix configs25b92abchore(deps): update semver and tool-cachebc0ac76chore(deps): update actions842e7ccfeat: update for goreleaser v2.7d28c982chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 (#482)Updates
ossf/scorecard-actionfrom 2.4.0 to 2.4.2Release notes
Sourced from ossf/scorecard-action's releases.
Commits
05b42c6🌱 bump docker to ghcr v2.4.2 (#1548)b225da6Bump github.com/ossf/scorecard/v5 from v5.2.0 to v5.2.1 (#1550)9399f6f🌱 Bump the docker-images group across 1 directory with 2 updates (#1...e1daa8c🌱 Bump the github-actions group across 1 directory with 5 updates (#...9fe6511🌱 Bump golang.org/x/net from 0.39.0 to 0.40.0 (#1542)25b9cd9🌱 Bump github.com/ossf/scorecard/v5 from v5.1.1 to v5.2.0 (#1547)18cc9b8🌱 Bump golang.org/x/net from 0.38.0 to 0.39.0 (#1536)db78142🌱 Bump the github-actions group with 2 updates (#1538)de386ed🌱 Bump golang from 1.24.1 to 1.24.2 in the docker-images group (#1534)5b7cedb🌱 Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 (#1537)Updates
actions/upload-artifactfrom 4.6.0 to 4.6.2Release notes
Sourced from actions/upload-artifact's releases.
Commits
ea165f8Merge pull request #685 from salmanmkc/salmanmkc/3-new-upload-artifacts-release0839620Prepare for new release of actions/upload-artifact with new toolkit cache ver...4cec3d8Merge pull request #673 from actions/yacaovsnc/artifact_2.2.2e9fad96license cache update for artifactb26fd06Update to use artifact 2.2.2 packageUpdates
github/codeql-actionfrom 3.28.5 to 3.29.8Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
76621b6Merge pull request #3019 from github/update-v3.29.8-679a40d3329ac3ceAdd release notes for 3.29.7737cfdeUpdate changelog for v3.29.8679a40dMerge pull request #3014 from github/henrymercer/rebuild-dispatch6fe50b2Merge pull request #3015 from github/henrymercer/language-autodetection-worka...6bc91d6Add changelog note6b4fedcBump Action patch version5794ffcFix auto-detection of extractors that aren't languagesbd62bf4Finish in-progress merges2afb4e6Avoid specifying branch unnecessarilyUpdates
golangci/golangci-lint-actionfrom 6.2.0 to 8.0.0Release notes
Sourced from golangci/golangci-lint-action's releases.
... (truncated)
Commits
4afd7338.0.07774f98feat: use absolute paths by default when using working-directory option (#1231)9fae48a7.0.116ece5edocs: clarify that ’args: --path-mode=abs’ is needed for working-directory (...a3942e2build(deps-dev): bump the dev-dependencies group with 2 updates (#1227)7ecb048build(deps): bump@types/nodefrom 22.14.0 to 22.14.1 in the dependencies gro...63a0d0ebuild(deps-dev): bump the dev-dependencies group with 3 updates (#1224)c2427fedocs: update problem matchers section642f8eebuild(deps): bump@types/nodefrom 22.13.14 to 22.14.0 in the dependencies gr...d84be92build(deps-dev): bump the dev-dependencies group with 4 updates (#1220)Updates
aquasecurity/trivy-actionfrom 0.29.0 to 0.32.0Release notes
Sourced from aquasecurity/trivy-action's releases.
Commits
dc5a429chore(deps): Update trivy to v0.64.1 (#474)76071efchore(deps): Update trivy to v0.63.0 (#467)4844d82ci: fix workflow to bump Trivy (#466)26d71e6refactor: use ubuntu 24.04 (#465)b3dafe5Bump Trivy version to fix GitHub actions (#460)99baf0dPin aquasecuriy/setup-trivy to hash instead of tag (#456)7aca5acfix: Trivy action inputs leaking bet...Description has been truncated