Skip to content

Commit 37f5662

Browse files
Bump the gh-minor group with 10 updates
Bumps the gh-minor group with 10 updates: | Package | From | To | | --- | --- | --- | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.10.0` | `3.11.1` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.5.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.15.0` | `6.18.0` | | [actions/cache](https://github.com/actions/cache) | `4.2.2` | `4.3.0` | | [fluxcd/flux2](https://github.com/fluxcd/flux2) | `2.5.1` | `2.6.4` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.11` | `3.30.5` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.8.1` | `3.10.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.18.0` | `0.20.6` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.2.1` | `6.4.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.30.0` | `0.33.1` | Updates `docker/setup-buildx-action` from 3.10.0 to 3.11.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@b5ca514...e468171) Updates `docker/login-action` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...184bdaa) Updates `docker/build-push-action` from 6.15.0 to 6.18.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@471d1dc...2634353) Updates `actions/cache` from 4.2.2 to 4.3.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@d4323d4...0057852) Updates `fluxcd/flux2` from 2.5.1 to 2.6.4 - [Release notes](https://github.com/fluxcd/flux2/releases) - [Changelog](https://github.com/fluxcd/flux2/blob/main/.goreleaser.yml) - [Commits](fluxcd/flux2@8d5f40d...6bf37f6) Updates `github/codeql-action` from 3.28.11 to 3.30.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@6bb031a...3599b3b) Updates `sigstore/cosign-installer` from 3.8.1 to 3.10.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@d7d6bc7...d7543c9) Updates `anchore/sbom-action` from 0.18.0 to 0.20.6 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f325610...f8bdd1d) Updates `goreleaser/goreleaser-action` from 6.2.1 to 6.4.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@90a3faa...e435ccd) Updates `aquasecurity/trivy-action` from 0.30.0 to 0.33.1 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@6c175e9...b6643a2) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: 3.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: docker/login-action dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: docker/build-push-action dependency-version: 6.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: actions/cache dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: fluxcd/flux2 dependency-version: 2.6.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: github/codeql-action dependency-version: 3.30.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: sigstore/cosign-installer dependency-version: 3.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: anchore/sbom-action dependency-version: 0.20.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: goreleaser/goreleaser-action dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor - dependency-name: aquasecurity/trivy-action dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-minor ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 13c7438 commit 37f5662

File tree

8 files changed

+33
-33
lines changed

8 files changed

+33
-33
lines changed

.github/workflows/build-and-publish.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -62,17 +62,17 @@ jobs:
6262
platforms: all
6363
- name: Setup Docker Buildx
6464
id: buildx
65-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
65+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
6666
with:
6767
buildkitd-flags: "--debug"
6868
- name: Login to GitHub Container Registry
69-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
69+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
7070
with:
7171
registry: ghcr.io
7272
username: ${{ github.actor }}
7373
password: ${{ secrets.GITHUB_TOKEN }}
7474
- name: Publish multi-arch tf-controller container image
75-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
75+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
7676
with:
7777
push: true
7878
builder: ${{ steps.buildx.outputs.name }}
@@ -91,7 +91,7 @@ jobs:
9191
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
9292
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
9393
- name: Build multi-arch tf-runner base image
94-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
94+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
9595
with:
9696
push: true
9797
builder: ${{ steps.buildx.outputs.name }}
@@ -112,7 +112,7 @@ jobs:
112112
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
113113
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
114114
- name: Publish multi-arch tf-runner container image
115-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
115+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
116116
with:
117117
push: true
118118
builder: ${{ steps.buildx.outputs.name }}
@@ -131,7 +131,7 @@ jobs:
131131
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
132132
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
133133
- name: Publish multi-arch branch-planner container image
134-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
134+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
135135
with:
136136
push: true
137137
builder: ${{ steps.buildx.outputs.name }}

.github/workflows/e2e.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
**/go.sum
3535
**/go.mod
3636
- name: Cache Docker layers
37-
uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
37+
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
3838
id: cache
3939
with:
4040
path: /tmp/.buildx-cache

.github/workflows/helm-release.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
with:
2020
token: ${{ secrets.GITHUB_TOKEN }}
2121
- name: Login to GitHub Container Registry
22-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
22+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
2323
with:
2424
registry: ghcr.io
2525
username: ${{ github.actor }}

.github/workflows/helm-test.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ jobs:
7272
if: steps.list-changed.outputs.changed == 'true'
7373

7474
- name: Install Flux CLI
75-
uses: fluxcd/flux2/action@8d5f40dca5aa5d3c0fc3414457dda15a0ac92fa4 # main
75+
uses: fluxcd/flux2/action@6bf37f6a560fd84982d67f853162e4b3c2235edb # main
7676
if: steps.list-changed.outputs.changed == 'true'
7777

7878
- name: Install Source controller

.github/workflows/ossf.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,6 @@ jobs:
4242

4343
# required for Code scanning alerts
4444
- name: "Upload SARIF results to code scanning"
45-
uses: github/codeql-action/upload-sarif@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
45+
uses: github/codeql-action/upload-sarif@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
4646
with:
4747
sarif_file: results.sarif

.github/workflows/release-runners.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -36,17 +36,17 @@ jobs:
3636
platforms: all
3737
- name: Setup Docker Buildx
3838
id: buildx
39-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
39+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
4040
with:
4141
buildkitd-flags: "--debug"
4242
- name: Login to Docker Registry
43-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
43+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
4444
with:
4545
registry: ghcr.io
4646
username: ${{ github.actor }}
4747
password: ${{ secrets.GITHUB_TOKEN }}
4848
- name: Publish multi-arch tf-runner base image
49-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
49+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
5050
with:
5151
push: true
5252
no-cache: true
@@ -85,17 +85,17 @@ jobs:
8585
platforms: all
8686
- name: Setup Docker Buildx
8787
id: buildx
88-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
88+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
8989
with:
9090
buildkitd-flags: "--debug"
9191
- name: Login to Docker Registry
92-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
92+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
9393
with:
9494
registry: ghcr.io
9595
username: ${{ github.actor }}
9696
password: ${{ secrets.GITHUB_TOKEN }}
9797
- name: Publish multi-arch tf-runner MPL images
98-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
98+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
9999
with:
100100
push: true
101101
no-cache: true

.github/workflows/release.yaml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,9 @@ jobs:
3434
- name: Setup Kustomize
3535
uses: fluxcd/pkg/actions/kustomize@30c101fc7c9fac4d84937ff4890a3da46a9db2dd # main
3636
- name: Setup Cosign
37-
uses: sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
37+
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
3838
- name: Setup Syft
39-
uses: anchore/sbom-action/download-syft@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
39+
uses: anchore/sbom-action/download-syft@f8bdd1d8ac5e901a77a92f111440fdb1b593736b # v0.20.6
4040
- name: Prepare
4141
id: prep
4242
run: |
@@ -52,17 +52,17 @@ jobs:
5252
platforms: all
5353
- name: Setup Docker Buildx
5454
id: buildx
55-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
55+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
5656
with:
5757
buildkitd-flags: "--debug"
5858
- name: Login to GitHub Container Registry
59-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
59+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
6060
with:
6161
registry: ghcr.io
6262
username: ${{ github.actor }}
6363
password: ${{ secrets.GITHUB_TOKEN }}
6464
- name: Publish multi-arch tofu-controller container image
65-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
65+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
6666
with:
6767
push: true
6868
no-cache: true
@@ -83,7 +83,7 @@ jobs:
8383
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
8484
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
8585
- name: Publish multi-arch tf-runner base image
86-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
86+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
8787
with:
8888
push: true
8989
builder: ${{ steps.buildx.outputs.name }}
@@ -102,7 +102,7 @@ jobs:
102102
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
103103
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
104104
- name: Publish multi-arch tf-runner container image
105-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
105+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
106106
with:
107107
push: true
108108
no-cache: true
@@ -123,7 +123,7 @@ jobs:
123123
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
124124
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
125125
- name: Publish multi-arch tf-runner-azure container image
126-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
126+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
127127
with:
128128
push: true
129129
no-cache: true
@@ -144,7 +144,7 @@ jobs:
144144
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
145145
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
146146
- name: Publish multi-arch branch-planner container image
147-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15.0
147+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
148148
with:
149149
push: true
150150
no-cache: true
@@ -201,7 +201,7 @@ jobs:
201201
go-version-file: go.mod
202202
- name: Create release
203203
if: startsWith(github.ref, 'refs/tags/v')
204-
uses: goreleaser/goreleaser-action@90a3faa9d0182683851fbfa97ca1a2cb983bfca3 # v6.2.1
204+
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
205205
with:
206206
version: '~> v2'
207207
args: release --release-notes=./config/release/notes.md --skip=validate

.github/workflows/scan.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -39,13 +39,13 @@ jobs:
3939
**/go.sum
4040
**/go.mod
4141
- name: Initialize CodeQL
42-
uses: github/codeql-action/init@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
42+
uses: github/codeql-action/init@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
4343
with:
4444
languages: go
4545
- name: Autobuild
46-
uses: github/codeql-action/autobuild@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
46+
uses: github/codeql-action/autobuild@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
48+
uses: github/codeql-action/analyze@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
4949

5050
trivy:
5151
name: Trivy
@@ -57,7 +57,7 @@ jobs:
5757
run: |
5858
make docker-buildx
5959
- name: Run Trivy vulnerability scanner on controller image
60-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
60+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
6161
with:
6262
image-ref: 'ghcr.io/flux-iac/tofu-controller:latest'
6363
format: 'table'
@@ -66,7 +66,7 @@ jobs:
6666
vuln-type: 'os,library'
6767
severity: 'CRITICAL,HIGH'
6868
- name: Run Trivy vulnerability scanner on runner image
69-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
69+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
7070
with:
7171
image-ref: 'ghcr.io/flux-iac/tf-runner:latest'
7272
format: 'table'
@@ -76,7 +76,7 @@ jobs:
7676
severity: 'CRITICAL,HIGH'
7777
skip-files: '/usr/local/bin/terraform' # false positive
7878
- name: Run Trivy vulnerability scanner on runner image
79-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
79+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
8080
with:
8181
image-ref: 'ghcr.io/flux-iac/tf-runner-azure:latest'
8282
format: 'table'
@@ -86,7 +86,7 @@ jobs:
8686
severity: 'CRITICAL,HIGH'
8787
skip-files: '/usr/local/bin/terraform' # false positive
8888
- name: Run Trivy vulnerability scanner on planner image
89-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
89+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
9090
with:
9191
image-ref: 'ghcr.io/flux-iac/branch-planner:latest'
9292
format: 'table'

0 commit comments

Comments
 (0)