-
Notifications
You must be signed in to change notification settings - Fork 13
chore: bump the dependencies group across 1 directory with 14 updates #417
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/github_actions/dependencies-607f651e74
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the dependencies group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `5` | | [azure/setup-helm](https://github.com/azure/setup-helm) | `4.3.0` | `4.3.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.5.0` | `6.0.0` | | [actions/setup-dotnet](https://github.com/actions/setup-dotnet) | `4.3.1` | `5.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.14` | `3.30.3` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.5.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.10.0` | `3.11.1` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.7.0` | `5.8.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `4.7.0` | `5.0.0` | | [checkmarx/kics-github-action](https://github.com/checkmarx/kics-github-action) | `2.1.6` | `2.1.13` | | [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) | `5.5.3` | `6.1.1` | | [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) | `2.9.1` | `2.9.4` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.30.0` | `0.33.1` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.88.23` | `3.90.8` | Updates `actions/checkout` from 4 to 5 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v4...v5) Updates `azure/setup-helm` from 4.3.0 to 4.3.1 - [Release notes](https://github.com/azure/setup-helm/releases) - [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md) - [Commits](Azure/setup-helm@b9e5190...1a275c3) Updates `actions/setup-python` from 5.5.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@8d9ed9a...e797f83) Updates `actions/setup-dotnet` from 4.3.1 to 5.0.0 - [Release notes](https://github.com/actions/setup-dotnet/releases) - [Commits](actions/setup-dotnet@67a3573...d4c9434) Updates `github/codeql-action` from 3.28.14 to 3.30.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@fc7e4a0...192325c) Updates `docker/login-action` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...184bdaa) Updates `docker/setup-buildx-action` from 3.10.0 to 3.11.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@b5ca514...e468171) Updates `docker/metadata-action` from 5.7.0 to 5.8.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@902fa8e...c1e5197) Updates `actions/setup-java` from 4.7.0 to 5.0.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@3a4f6e1...dded088) Updates `checkmarx/kics-github-action` from 2.1.6 to 2.1.13 - [Release notes](https://github.com/checkmarx/kics-github-action/releases) - [Commits](Checkmarx/kics-github-action@09100f0...7145454) Updates `amannn/action-semantic-pull-request` from 5.5.3 to 6.1.1 - [Release notes](https://github.com/amannn/action-semantic-pull-request/releases) - [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md) - [Commits](amannn/action-semantic-pull-request@0723387...48f2562) Updates `marocchino/sticky-pull-request-comment` from 2.9.1 to 2.9.4 - [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases) - [Commits](marocchino/sticky-pull-request-comment@52423e0...7737449) Updates `aquasecurity/trivy-action` from 0.30.0 to 0.33.1 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@6c175e9...b6643a2) Updates `trufflesecurity/trufflehog` from 3.88.23 to 3.90.8 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Changelog](https://github.com/trufflesecurity/trufflehog/blob/main/.goreleaser.yml) - [Commits](trufflesecurity/trufflehog@690e5c7...466da5b) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: azure/setup-helm dependency-version: 4.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: actions/setup-python dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: actions/setup-dotnet dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: github/codeql-action dependency-version: 3.30.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: docker/login-action dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: docker/setup-buildx-action dependency-version: 3.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: docker/metadata-action dependency-version: 5.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: actions/setup-java dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: checkmarx/kics-github-action dependency-version: 2.1.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: amannn/action-semantic-pull-request dependency-version: 6.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: marocchino/sticky-pull-request-comment dependency-version: 2.9.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: aquasecurity/trivy-action dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: trufflesecurity/trufflehog dependency-version: 3.90.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 14 updates in the / directory:
4
5
4.3.0
4.3.1
5.5.0
6.0.0
4.3.1
5.0.0
3.28.14
3.30.3
3.4.0
3.5.0
3.10.0
3.11.1
5.7.0
5.8.0
4.7.0
5.0.0
2.1.6
2.1.13
5.5.3
6.1.1
2.9.1
2.9.4
0.30.0
0.33.1
3.88.23
3.90.8
Updates
actions/checkout
from 4 to 5Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
08c6903
Prepare v5.0.0 release (#2238)9f26565
Update actions checkout to use node 24 (#2226)Updates
azure/setup-helm
from 4.3.0 to 4.3.1Release notes
Sourced from azure/setup-helm's releases.
Changelog
Sourced from azure/setup-helm's changelog.
Commits
1a275c3
build9e7f762
chore(release): v4.3.1 (#208)c096176
Bump@types/node
from 24.1.0 to 24.2.1 in the actions group (#206)5e72872
ci(workflows): update helm version to v3.18.4 and add matrix for tests (#207)fb8fa40
Update default helm version to 3.18.3 (#194)0d09729
chore: remove unnecessary prebuild script (#192)32bc120
chore(tests): Mock arch to make tests pass on arm host (#191)51463d6
Bump the actions group with 2 updates (#205)aff1094
Bump the actions group across 1 directory with 2 updates (#204)a10a524
Update helm version retrieval to use JSON output for latest version (#203)Updates
actions/setup-python
from 5.5.0 to 6.0.0Release notes
Sourced from actions/setup-python's releases.
Commits
e797f83
Upgrade to node 24 (#1164)3d1e2d2
Revert "Enhance cache-dependency-path handling to support files outside the w...65b0712
Clarify pythonLocation behavior for PyPy and GraalPy in environment variables...5b668cf
Bump actions/checkout from 4 to 5 (#1181)f62a0e2
Change missing cache directory error to warning (#1182)9322b3c
Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIn...fbeb884
Bump form-data to fix critical vulnerabilities #182 & #183 (#1163)03bb615
Bump idna from 2.9 to 3.7 in /tests/data (#843)36da51d
Add version parsing from Pipfile (#1067)3c6f142
update documentation (#1156)Updates
actions/setup-dotnet
from 4.3.1 to 5.0.0Release notes
Sourced from actions/setup-dotnet's releases.
Commits
d4c9434
Update to Node.js 24 and modernize async usage (#654)5c125af
Bump actions/checkout from 4 to 5 (#662)87c6e11
Bumps form-data (#652)06a5327
Bump undici from 5.28.5 to 5.29.0 (#641)e8e5b82
Bump eslint-config-prettier from 9.1.0 to 10.1.5 (#639)bf4cd79
Bump@actions/glob
from 0.4.0 to 0.5.0 (#594)4ddad1c
Bump husky from 8.0.3 to 9.1.7 (#591)0f55b45
removes end-of-line dotnet versions (#647)267870a
upgrade actions/cache to 4.0.3 (#622)Updates
github/codeql-action
from 3.28.14 to 3.30.3Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
192325c
Merge pull request #3104 from github/update-v3.30.3-b660efdcfe68956d
Update changelog for v3.30.3b660efd
Merge pull request #3103 from github/mbg/fix/category-checke49458b
FixrunInterpretResultsFor
using the wrongAnalysisConfig
forcategory
fixf374a62
Merge pull request #3098 from github/kaspersv/increase-overlay-base-size-limit5efa438
Merge pull request #3101 from github/mbg/public-repo-notice-in-pr-template8a84a62
Overlay: Increase size limit for cached overlay base databaseeb50a88
Merge pull request #3097 from github/redsun82/only-dump-sarif4c53461
Tweak sarif dump logdae3742
Dump soon to be uploaded SARIF on requestUpdates
docker/login-action
from 3.4.0 to 3.5.0Release notes
Sourced from docker/login-action's releases.
Commits
184bdaa
Merge pull request #878 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...5c6bc94
chore: update generated contentcaf4058
build(deps): bump the aws-sdk-dependencies group with 2 updatesef38ec3
Merge pull request #860 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...d52e8ef
chore: update generated content9644ab7
build(deps): bump the aws-sdk-dependencies group with 2 updates7abd1d5
Merge pull request #875 from docker/dependabot/npm_and_yarn/form-data-2.5.51a81202
Merge pull request #876 from crazy-max/aws-public-dual-stackd1ab30d
chore: update generated contentf25ff28
support dual-stack for aws public ecrUpdates
docker/setup-buildx-action
from 3.10.0 to 3.11.1Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
e468171
Merge pull request #429 from crazy-max/fix-keep-statea3e7502
chore: update generated contentb145473
fix keep-state not being respected18ce135
Merge pull request #425 from docker/dependabot/npm_and_yarn/docker/actions-to...0e198e9
chore: update generated content05f3f3a
build(deps): bump@docker/actions-toolkit
from 0.61.0 to 0.62.16229134
Merge pull request #427 from crazy-max/keep-statec6f6a07
chore: update generated content6c5e29d
skip builder creation if one already exists with the same name548b297
ci: keep-state checkUpdates
docker/metadata-action
from 5.7.0 to 5.8.0Release notes
Sourced from docker/metadata-action's releases.
Commits
c1e5197
Merge pull request #537 from crazy-max/pep440-match89dd65a
chore: update generated content699ee45
allow to match part of the git tag or value for pep440 typee0542a6
Merge pull request #536 from crazy-max/semver-matchb7facdf
chore: update generated content81c60df
allow to match part of the git tag or value for semver typede11195
Merge pull request #535 from crazy-max/not_def_branch2f9c64b
Merge pull request #533 from docker/dependabot/npm_and_yarn/form-data-2.5.5510f746
chore: update generated content2bc3f4e
is_not_default_branch global expressionUpdates
actions/setup-java
from 4.7.0 to 5.0.0Release notes
Sourced from actions/setup-java's releases.
Commits
dded088
Bump actions/checkout from 4 to 5 (#896)0913e9a
Upgrade to node 24 (#888)e9343db
Bumps form-data (#887)ae2b61d
Bump undici from 5.28.5 to 5.29.0 (#833)c190c18
Bump eslint-plugin-jest from 27.9.0 to 29.0.1 (#730)67aec00
Fix: prevent default installation of JetBrains pre-releases (#859)ebb356c
Improve Error Handling for Setup-Java Action to Help Debug Intermittent Failu...f4f1212
Update publish-immutable-actions.yml (#798)c5195ef
actions/cache upgrade to 4.0.3 (#773)dd38875
Bump ts-jest from 29.1.2 to 29.2.5 (#743)Updates
checkmarx/kics-github-action
from 2.1.6 to 2.1.13Release notes
Sourced from checkmarx/kics-github-action's releases.
Commits
7145454
bump kics version to 2-1-13 (#139)cd1f377
bumps kics version to 2.1.12 (#136)3545b74
bump kics version to 2.1.11 (#133)c06a133
Update kics to version 2.1.10 (#132)1141bda
UpdateKicsVersionTo219 (#131)c456d04
Merge pull request #129 from Checkmarx/UpdateKICSVersionTo218d83c04e
update kics version to 2185373b38
Merge pull request #127 from Checkmarx/updateKicsVersionTo217061d0d8
update kics dockerfile version