Bump the gh-minor group with 10 updates #1607
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the gh-minor group with 10 updates:
3.10.0
3.11.1
3.4.0
3.5.0
6.15.0
6.18.0
4.2.2
4.3.0
2.5.1
2.6.4
3.28.11
3.30.5
3.8.1
3.10.0
0.18.0
0.20.6
6.2.1
6.4.0
0.30.0
0.33.1
Updates
docker/setup-buildx-action
from 3.10.0 to 3.11.1Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
e468171
Merge pull request #429 from crazy-max/fix-keep-statea3e7502
chore: update generated contentb145473
fix keep-state not being respected18ce135
Merge pull request #425 from docker/dependabot/npm_and_yarn/docker/actions-to...0e198e9
chore: update generated content05f3f3a
build(deps): bump@docker/actions-toolkit
from 0.61.0 to 0.62.16229134
Merge pull request #427 from crazy-max/keep-statec6f6a07
chore: update generated content6c5e29d
skip builder creation if one already exists with the same name548b297
ci: keep-state checkUpdates
docker/login-action
from 3.4.0 to 3.5.0Release notes
Sourced from docker/login-action's releases.
Commits
184bdaa
Merge pull request #878 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...5c6bc94
chore: update generated contentcaf4058
build(deps): bump the aws-sdk-dependencies group with 2 updatesef38ec3
Merge pull request #860 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...d52e8ef
chore: update generated content9644ab7
build(deps): bump the aws-sdk-dependencies group with 2 updates7abd1d5
Merge pull request #875 from docker/dependabot/npm_and_yarn/form-data-2.5.51a81202
Merge pull request #876 from crazy-max/aws-public-dual-stackd1ab30d
chore: update generated contentf25ff28
support dual-stack for aws public ecrUpdates
docker/build-push-action
from 6.15.0 to 6.18.0Release notes
Sourced from docker/build-push-action's releases.
Commits
2634353
Merge pull request #1381 from docker/dependabot/npm_and_yarn/docker/actions-t...c0432d2
chore: update generated content0bb1f27
set builder driver and endpoint attributes for dbc summary support5f9dbf9
chore(deps): Bump@docker/actions-toolkit
from 0.61.0 to 0.62.10788c44
Merge pull request #1375 from crazy-max/remove-gcraa179ca
e2e: remove GCR1dc7386
Merge pull request #1364 from crazy-max/history-export-cmd9c9803f
chore: update generated contentdb1f6c4
DOCKER_BUILD_EXPORT_LEGACY env var to opt-in for legacy export721e8c7
Bump@docker/actions-toolkit
from 0.59.0 to 0.61.0Updates
actions/cache
from 4.2.2 to 4.3.0Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
0057852
Merge pull request #1655 from actions/Link-/prepare-4.3.04f5ea67
Update licensed cache9fcad95
Upgrade actions/cache to 4.1.0 and prepare 4.3.0 release638ed79
Merge pull request #1642 from actions/GhadimiR-patch-13862dcc
Add note on runner versions0400d5f
Merge pull request #1636 from actions/Link-/release-4.2.4374a27f
Prepare release 4.2.4358a730
Merge pull request #1634 from actions/Link-/optimise-deps2ee706e
Fix with another approach94f7b5d
Fix bundle execUpdates
fluxcd/flux2
from 2.5.1 to 2.6.4Release notes
Sourced from fluxcd/flux2's releases.
... (truncated)
Commits
6bf37f6
Merge pull request #5444 from fluxcd/backport-5443-to-release/v2.6.x8b21911
Update toolkit componentsbda4c81
Merge pull request #5427 from fluxcd/backport-5426-to-release/v2.6.x3f281da
Fix: Prioritize sha2-512 and sha2-256 for ssh-rsa host keys963e991
Update toolkit componentsa48f81a
Merge pull request #5410 from fluxcd/backport-5409-to-release/v2.6.x55104dc
Update toolkit componentse771ff2
Merge pull request #5405 from fluxcd/backport-5404-to-release/v2.6.x998fe11
Upgrade dependenciesa6ac4c5
Merge pull request #5396 from fluxcd/backport-5390-to-release/v2.6.xUpdates
github/codeql-action
from 3.28.11 to 3.30.5Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
3599b3b
Merge pull request #3161 from github/update-v3.30.5-0a67bd46a2ca0085
Update changelog for v3.30.50a67bd4
Merge pull request #3160 from github/mbg/fix/upload-sarif8e34f2f
Add changelog0b7fc56
Fixupload-sarif
not uploading non-.sarif
files94a9b7a
Merge pull request #3155 from github/mbg/node/no-install-in-actionsa0ae9ba
Log what the script is doingb27a8ef
Exit if running in an Actions workflow6592567
Merge pull request #3139 from github/henrymercer/fix-log-messagefa64a7d
Merge pull request #3154 from github/mbg/node/check-up-to-date-depsUpdates
sigstore/cosign-installer
from 3.8.1 to 3.10.0Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
d7543c9
Bump default Cosign to v2.6.0 (#200)920f20f
Bump actions/setup-go from 5.5.0 to 6.0.0 (#199)bb9dfc1
Bump actions/github-script from 7.0.1 to 8.0.0 (#198)074636b
Bump actions/checkout from 4.2.2 to 5.0.0 (#197)d58896d
Update default to v2.5.3 (#196)e40248c
drop old unsupported versions <v2.0.0 (#192)d9374b9
not fail fast and setup permissions (#195)398d4b0
default cosign to v2.5.2 (#194)84f54a2
default action install to use release v2.5.1 (#193)fb28c2b
bump cosign install to use release v2.5.0 as default (#191)Updates
anchore/sbom-action
from 0.18.0 to 0.20.6Release notes
Sourced from anchore/sbom-action's releases.
Commits
f8bdd1d
chore(deps): update Syft to v1.33.0 (#537)c2c9a6d
chore: update actions library to resolve critical sec (#536)039eeb2
chore(deps): update Syft to v1.32.0 (#533)da167ea
chore(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#532)0d72d6e
chore(deps): update Syft to v1.31.0 (#531)7b36ad6
chore(deps): update Syft to v1.29.0 (#529)9e07fd7
fix: strip emoji from correlator names (#527)cee1b8e
chore(deps): update Syft to v1.28.0 (#526)9246b90
chore(deps): update Syft to v1.27.1 (#525)5f8d644
chore(deps): update Syft to v1.26.1 (#524)Updates
goreleaser/goreleaser-action
from 6.2.1 to 6.4.0Release notes
Sourced from goreleaser/goreleaser-action's releases.
Commits
e435ccd
feat: retry downloading releases json (#503)2ff5850
chore(deps): bump undici from 5.28.5 to 5.29.0 (#496)9a6cd01
fix: do not get releases.json if version is specific (#502)a386515
chore(deps): bump brace-expansion from 1.1.11 to 1.1.12 (#498)ca48102
chore(deps): bump semver from 7.7.1 to 7.7.2 (#495)0931acf
fix: support .config directory for goreleaser config files (#500)90c43f2
ci: set contents read as default workflow permissions (#494)9c156ee
ci: update bake-action to v6 (#493)73c477b
chore(deps): bump undici from 5.28.3 to 5.28.5 (#488)19c00a9
chore(deps): bump codecov/codecov-action from 4 to 5 (#481)Updates
aquasecurity/trivy-action
from 0.30.0 to 0.33.1Release notes
Sourced from aquasecurity/trivy-action's releases.
Commits
b6643a2
Update setup-trivy action to version v0.2.4 (#486)f9424c1
Merge pull request #481 from aquasecurity/bump-trivy-175589825185abccb
dev: delete fanal.db before testsa169870
ci: update golden files on Trivy bump71f6a8f
dev: add update-golden goalbf330b1
test: update golden files644762e
Merge pull request #482 from aquasecurity/fix-gh-actionsf2e2851
chore(ci): Add oras to correctly setup sync jobs636fd3c
fix: update tests7c0244b
chore(deps): Update trivy to v0.65.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions