-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
⬆️ gha: Bump the github-actions group across 1 directory with 11 updates #42
base: main
Are you sure you want to change the base?
⬆️ gha: Bump the github-actions group across 1 directory with 11 updates #42
Conversation
Bumps the github-actions group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.9.1` | `2.10.2` | | [actions/checkout](https://github.com/actions/checkout) | `4.1.7` | `4.2.2` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.0.2` | `5.1.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.26.6` | `3.27.5` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.3.4` | `4.5.0` | | [reviewdog/action-trivy](https://github.com/reviewdog/action-trivy) | `1.11.0` | `1.12.3` | | [reviewdog/action-alex](https://github.com/reviewdog/action-alex) | `1.13.0` | `1.14.0` | | [reviewdog/action-markdownlint](https://github.com/reviewdog/action-markdownlint) | `0.24.0` | `0.25.0` | | [reviewdog/action-actionlint](https://github.com/reviewdog/action-actionlint) | `1.54.0` | `1.57.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.0.8` | `2.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.0` | `4.4.3` | Updates `step-security/harden-runner` from 2.9.1 to 2.10.2 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@5c7944e...0080882) Updates `actions/checkout` from 4.1.7 to 4.2.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@692973e...11bd719) Updates `actions/setup-go` from 5.0.2 to 5.1.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@0a12ed9...41dfa10) Updates `github/codeql-action` from 3.26.6 to 3.27.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@4dd1613...f09c1c0) Updates `actions/dependency-review-action` from 4.3.4 to 4.5.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@5a2ce3f...3b139cf) Updates `reviewdog/action-trivy` from 1.11.0 to 1.12.3 - [Release notes](https://github.com/reviewdog/action-trivy/releases) - [Commits](reviewdog/action-trivy@14e16b3...5f1fa7b) Updates `reviewdog/action-alex` from 1.13.0 to 1.14.0 - [Release notes](https://github.com/reviewdog/action-alex/releases) - [Commits](reviewdog/action-alex@f95df9e...73756e0) Updates `reviewdog/action-markdownlint` from 0.24.0 to 0.25.0 - [Release notes](https://github.com/reviewdog/action-markdownlint/releases) - [Commits](reviewdog/action-markdownlint@e9f3ab4...28fb422) Updates `reviewdog/action-actionlint` from 1.54.0 to 1.57.0 - [Release notes](https://github.com/reviewdog/action-actionlint/releases) - [Commits](reviewdog/action-actionlint@4f8f996...7eeec1d) Updates `softprops/action-gh-release` from 2.0.8 to 2.1.0 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@c062e08...01570a1) Updates `actions/upload-artifact` from 4.4.0 to 4.4.3 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@5076954...b4b15b8) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-trivy dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-alex dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-markdownlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-actionlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Here's the code health analysis summary for commits Analysis Summary
|
💰 Infracost reportMonthly estimate generatedThis comment will be updated when code changes. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
Scanned Files
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
simply
may be insensitive, try not to use it simple retext-equality
# For most projects, this workflow file will not need changing; you simply need |
Bumps the github-actions group with 11 updates in the / directory:
2.9.1
2.10.2
4.1.7
4.2.2
5.0.2
5.1.0
3.26.6
3.27.5
4.3.4
4.5.0
1.11.0
1.12.3
1.13.0
1.14.0
0.24.0
0.25.0
1.54.0
1.57.0
2.0.8
2.1.0
4.4.0
4.4.3
Updates
step-security/harden-runner
from 2.9.1 to 2.10.2Release notes
Sourced from step-security/harden-runner's releases.
Commits
0080882
Merge pull request #476 from step-security/rc-164a3a88b
Update dist556aae6
Merge pull request #480 from h0x0er/jatin/cleanup6c39b84
chore: clean the code40401cf
Update for isdocker806ab1c
Update check for isdocker2846811
update distdf8a07c
Merge pull request #475 from h0x0er/fix-execSync30636fb
bug fixes91182cc
Merge pull request #463 from step-security/rc-14Updates
actions/checkout
from 4.1.7 to 4.2.2Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
11bd719
Prepare 4.2.2 Release (#1953)e3d2460
Expand unit test coverage (#1946)163217d
url-helper.ts
now leverages well-known environment variables. (#1941)eef6144
Prepare 4.2.1 release (#1925)6b42224
Add workflow file for publishing releases to immutable action package (#1919)de5a000
Check out other refs/* by commit if provided, fall back to ref (#1924)d632683
Prepare 4.2.0 release (#1878)6d193bf
Bump braces from 3.0.2 to 3.0.3 (#1777)db0cee9
Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)b684943
Add Ref and Commit outputs (#1180)Updates
actions/setup-go
from 5.0.2 to 5.1.0Release notes
Sourced from actions/setup-go's releases.
Commits
41dfa10
Enhance workflows and Upgrade micromatch Dependency (#510)9419772
ReviseisGhes
logic (#511)d60b41a
Merge pull request #502 from actions/Jcambass-patch-1e09f57f
Upgrade IA Publishdf1a117
Merge pull request #500 from actions/Jcambass-patch-149582f6
Add workflow file for publishing releases to immutable action packageb26d402
fix: add arch to cache key (#493)Updates
github/codeql-action
from 3.26.6 to 3.27.5Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
f09c1c0
Merge pull request #2616 from github/update-v3.27.5-a6c8729a567b73ea
Update changelog for v3.27.5a6c8729
Merge pull request #2614 from github/marcogario/per-platform-proxy8f3b487
Start-proxy: Fetch OS specific binarycba5fb5
Merge pull request #2613 from github/dependabot/npm_and_yarn/npm_and_yarn-018...e782c3a
Merge pull request #2612 from github/angelapwen/report-linux-runner-releasedb67881
Update checked-in dependenciesecde4d2
Bump cross-spawn from 7.0.3 to 7.0.6 in the npm_and_yarn groupe3c67a0
Merge pull request #2610 from github/dependabot/npm_and_yarn/npm-d2ca52e617f9ada54
Telemetry: report OS release for GitHub-hosted Linux runnersUpdates
actions/dependency-review-action
from 4.3.4 to 4.5.0Release notes
Sourced from actions/dependency-review-action's releases.
Commits
3b139cf
Merge pull request #851 from actions/ahmed3lmallah/prepare-for-4.5.0-released6807b6
updating generated codec89b41f
addressing lint issueseee97d8
incrementing project version9d10182
Merge pull request #827 from ebickle/fix/comment-warn-only9192be9
Merge pull request #850 from actions/ahmed3lmallah/adressing-CVE-2024-215382fc8e23
Using cross-spawn safe versionfb86db2
fix: resolve race conditions in async core.group calls0a198ab
fix: replace integer failureCount with booleanfc499fc
Merge branch 'main' into fix/comment-warn-onlyUpdates
reviewdog/action-trivy
from 1.11.0 to 1.12.3Release notes
Sourced from reviewdog/action-trivy's releases.
Commits
5f1fa7b
Merge pull request #62 from reviewdog/renovate/aws-5.xc8947de
chore(deps): update terraform aws to ~> 5.77.09b2b39f
Merge pull request #63 from h-matsuo/patch-113dc903
Support aarch648c5d7eb
Merge pull request #58 from reviewdog/renovate/aws-5.xb04ff88
chore(deps): update terraform aws to ~> 5.72.0eec5058
Merge pull request #35 from nayuta/add_fs_supportd2ec6d5
Merge branch 'main' into add_fs_support63c13a0
Merge pull request #60 from reviewdog/depup/reviewdogc5eebf3
chore(deps): update reviewdog to 0.20.2Updates
reviewdog/action-alex
from 1.13.0 to 1.14.0Release notes
Sourced from reviewdog/action-alex's releases.
Commits
73756e0
Merge pull request #33 from reviewdog/depup/reviewdogc099d35
chore(deps): update reviewdog to 0.20.2Updates
reviewdog/action-markdownlint
from 0.24.0 to 0.25.0Release notes
Sourced from reviewdog/action-markdownlint's releases.
Commits
28fb422
Merge pull request #65 from reviewdog/depup/reviewdog0daa209
chore(deps): update reviewdog to 0.20.2Updates
reviewdog/action-actionlint
from 1.54.0 to 1.57.0Release notes
Sourced from reviewdog/action-actionlint's releases.
Commits
7eeec1d
bump v1.57.05382349
Merge branch 'main' into releases/v1053981c
Merge pull request #144 from reviewdog/depup/actionlintc9fe0dc
chore(deps): update actionlint to 1.7.315a7a47
bump v1.56.0a46f3c8
Merge branch 'main' into releases/v10d91f4e
Merge pull request #141 from reviewdog/depup/actionlintfa360de
chore(deps): update actionlint to 1.7.205c9d7b
bump v1.55.0c698e45
Merge branch 'main' into releases/v1Updates
softprops/action-gh-release
from 2.0.8 to 2.1.0Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
01570a1
chore: release 2.1.0d5f028c
feature: preserve upload order (#500)98daca2
feat: add support for release assets with multiple spaces within the name (#518)b019a5b
chore: bump@types/node
to 22.9.073e673b
chore(deps): bump@types/node
from 22.8.2 to 22.8.7 (#539)e7a8f85
chore: release 2.0.904afa13
chore(deps): bump actions/setup-node from 4.0.4 to 4.1.0 (#535)894468a
chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#534)3bd23aa
chore(deps): bump@types/node
from 22.7.5 to 22.8.2 (#533)21eb2f9
chore(deps): bump@types/jest
from 29.5.13 to 29.5.14 (#532)Updates
actions/upload-artifact
from 4.4.0 to 4.4.3Release notes
Sourced from actions/upload-artifact's releases.
Commits
b4b15b8
Merge pull request #632 from actions/joshmgross/undo-dependency-changes92b01eb
Undo indirect dependency updates from #6278448086
Merge pull request #627 from actions/robherley/v4.4.2b1d4642
add explicit relative and absolute symlinks to workflowd50e660
bump versionaabe6f8
build with@actions/artifact
v2.1.11604373d
Merge pull request #625 from actions/robherley/artifact-2.1.10Description has been truncated