-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
⬆️ gha: Bump the github-actions group across 1 directory with 12 updates #18
⬆️ gha: Bump the github-actions group across 1 directory with 12 updates #18
Conversation
Bumps the github-actions group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.9.1` | `2.10.1` | | [actions/checkout](https://github.com/actions/checkout) | `4.1.7` | `4.2.2` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.3.4` | `4.4.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.2.0` | `5.3.0` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `6.1.0` | `7.0.5` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.0.2` | `5.1.0` | | [reviewdog/action-alex](https://github.com/reviewdog/action-alex) | `1.13.0` | `1.14.0` | | [reviewdog/action-markdownlint](https://github.com/reviewdog/action-markdownlint) | `0.24.0` | `0.25.0` | | [reviewdog/action-actionlint](https://github.com/reviewdog/action-actionlint) | `1.54.0` | `1.57.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.0.8` | `2.0.9` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.6` | `4.4.3` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.26.6` | `3.27.0` | Updates `step-security/harden-runner` from 2.9.1 to 2.10.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@5c7944e...91182cc) Updates `actions/checkout` from 4.1.7 to 4.2.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@692973e...11bd719) Updates `actions/dependency-review-action` from 4.3.4 to 4.4.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@5a2ce3f...4081bf9) Updates `actions/setup-python` from 5.2.0 to 5.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@f677139...0b93645) Updates `peter-evans/create-pull-request` from 6.1.0 to 7.0.5 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@c5a7806...5e91468) Updates `actions/setup-go` from 5.0.2 to 5.1.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@0a12ed9...41dfa10) Updates `reviewdog/action-alex` from 1.13.0 to 1.14.0 - [Release notes](https://github.com/reviewdog/action-alex/releases) - [Commits](reviewdog/action-alex@f95df9e...73756e0) Updates `reviewdog/action-markdownlint` from 0.24.0 to 0.25.0 - [Release notes](https://github.com/reviewdog/action-markdownlint/releases) - [Commits](reviewdog/action-markdownlint@e9f3ab4...28fb422) Updates `reviewdog/action-actionlint` from 1.54.0 to 1.57.0 - [Release notes](https://github.com/reviewdog/action-actionlint/releases) - [Commits](reviewdog/action-actionlint@4f8f996...7eeec1d) Updates `softprops/action-gh-release` from 2.0.8 to 2.0.9 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@c062e08...e7a8f85) Updates `actions/upload-artifact` from 4.3.6 to 4.4.3 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@834a144...b4b15b8) Updates `github/codeql-action` from 3.26.6 to 3.27.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@4dd1613...6624720) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-python dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-alex dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-markdownlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-actionlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
Scanned Files
|
Superseded by #21. |
Bumps the github-actions group with 12 updates in the / directory:
2.9.1
2.10.1
4.1.7
4.2.2
4.3.4
4.4.0
5.2.0
5.3.0
6.1.0
7.0.5
5.0.2
5.1.0
1.13.0
1.14.0
0.24.0
0.25.0
1.54.0
1.57.0
2.0.8
2.0.9
4.3.6
4.4.3
3.26.6
3.27.0
Updates
step-security/harden-runner
from 2.9.1 to 2.10.1Release notes
Sourced from step-security/harden-runner's releases.
Commits
91182cc
Merge pull request #463 from step-security/rc-1459ec1c6
Update agent1d23703
Merge pull request #461 from step-security/varunsh-coder-patch-1b03bdda
Update README.md3d8dd68
Update README.md446798f
Merge pull request #455 from step-security/rc-12f0d3b1e
Update agentb7880a2
update distdade49e
Merge pull request #456 from h0x0er/arm-supportd6248be
bump enterprise agent versionUpdates
actions/checkout
from 4.1.7 to 4.2.2Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
11bd719
Prepare 4.2.2 Release (#1953)e3d2460
Expand unit test coverage (#1946)163217d
url-helper.ts
now leverages well-known environment variables. (#1941)eef6144
Prepare 4.2.1 release (#1925)6b42224
Add workflow file for publishing releases to immutable action package (#1919)de5a000
Check out other refs/* by commit if provided, fall back to ref (#1924)d632683
Prepare 4.2.0 release (#1878)6d193bf
Bump braces from 3.0.2 to 3.0.3 (#1777)db0cee9
Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)b684943
Add Ref and Commit outputs (#1180)Updates
actions/dependency-review-action
from 4.3.4 to 4.4.0Release notes
Sourced from actions/dependency-review-action's releases.
Commits
4081bf9
Merge pull request #846 from actions/merge-group-bug-fix03e585e
fixing minor typo08b4117
updating dist code9c3441f
updating dist code304a544
updating testse99353b
fixing merge_group schema buga6993e2
Merge pull request #840 from actions/dependabot-updatesd92f08b
Bump eslint-plugin-jest and ts-jest3e334b7
Merge pull request #822 from actions/dependabot/npm_and_yarn/got-14.4.232b7d88
Merge pull request #832 from actions/jonjanego-patch-3Updates
actions/setup-python
from 5.2.0 to 5.3.0Release notes
Sourced from actions/setup-python's releases.
Commits
0b93645
Enhance workflows: Add macOS 13 support, upgrade publish-action, and update d...9c76e71
Bump pillow from 7.2 to 10.2.0 in /tests/data (#956)f4c5a11
ReviseisGhes
logic (#963)19dfb7b
Bump default versions to latest (#905)e9675cc
Merge pull request #943 from actions/Jcambass-patch-13226af6
Upgrade IA publish70dcb22
Merge pull request #941 from actions/Jcambass-patch-165b48c7
Create publish-immutable-actions.yml29a37be
initial commit (#938)Updates
peter-evans/create-pull-request
from 6.1.0 to 7.0.5Release notes
Sourced from peter-evans/create-pull-request's releases.
... (truncated)
Commits
5e91468
fix: support symlinks when commit signing (#3359)2f38cd2
fix: support submodules when commit signing (#3354)7a8aeac
build(deps-dev): bump eslint from 8.57.0 to 8.57.1 (#3344)d39d596
build(deps-dev): bump@types/jest
from 29.5.12 to 29.5.13 (#3343)f6f978f
docs: correct suggestion for bot setup (#3342)6cd32fd
fix: disable abbreviated commit shas in diff (#3337)d121e62
fix: disable diff detection for renames and copies (#3330)f4d66f4
build(deps-dev): bump typescript from 5.5.4 to 5.6.2 (#3319)488c869
build(deps-dev): bump@types/node
from 18.19.48 to 18.19.50 (#3320)5354f85
docs: update readmeUpdates
actions/setup-go
from 5.0.2 to 5.1.0Release notes
Sourced from actions/setup-go's releases.
Commits
41dfa10
Enhance workflows and Upgrade micromatch Dependency (#510)9419772
ReviseisGhes
logic (#511)d60b41a
Merge pull request #502 from actions/Jcambass-patch-1e09f57f
Upgrade IA Publishdf1a117
Merge pull request #500 from actions/Jcambass-patch-149582f6
Add workflow file for publishing releases to immutable action packageb26d402
fix: add arch to cache key (#493)Updates
reviewdog/action-alex
from 1.13.0 to 1.14.0Release notes
Sourced from reviewdog/action-alex's releases.
Commits
73756e0
Merge pull request #33 from reviewdog/depup/reviewdogc099d35
chore(deps): update reviewdog to 0.20.2Updates
reviewdog/action-markdownlint
from 0.24.0 to 0.25.0Release notes
Sourced from reviewdog/action-markdownlint's releases.
Commits
28fb422
Merge pull request #65 from reviewdog/depup/reviewdog0daa209
chore(deps): update reviewdog to 0.20.2Updates
reviewdog/action-actionlint
from 1.54.0 to 1.57.0Release notes
Sourced from reviewdog/action-actionlint's releases.
Commits
7eeec1d
bump v1.57.05382349
Merge branch 'main' into releases/v1053981c
Merge pull request #144 from reviewdog/depup/actionlintc9fe0dc
chore(deps): update actionlint to 1.7.315a7a47
bump v1.56.0a46f3c8
Merge branch 'main' into releases/v10d91f4e
Merge pull request #141 from reviewdog/depup/actionlintfa360de
chore(deps): update actionlint to 1.7.205c9d7b
bump v1.55.0c698e45
Merge branch 'main' into releases/v1Updates
softprops/action-gh-release
from 2.0.8 to 2.0.9Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
e7a8f85
chore: release 2.0.904afa13
chore(deps): bump actions/setup-node from 4.0.4 to 4.1.0 (#535)894468a
chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#534)3bd23aa
chore(deps): bump@types/node
from 22.7.5 to 22.8.2 (#533)21eb2f9
chore(deps): bump@types/jest
from 29.5.13 to 29.5.14 (#532)cd8b57e
remove unused imports (#521)820a5ad
chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 (#522)9d04f90
chore(deps): bump@octokit/plugin-throttling
from 9.3.1 to 9.3.2 (#523)aaf1d5f
chore(deps): bump@actions/core
from 1.10.1 to 1.11.1 (#524)7d33a7e
chore(deps): bump@types/node
from 22.5.5 to 22.7.5 (#525)Updates
actions/upload-artifact
from 4.3.6 to 4.4.3Release notes
Sourced from actions/upload-artifact's releases.
Commits
b4b15b8
Merge pull request #632 from actions/joshmgross/undo-dependency-changes92b01eb
Undo indirect dependency updates from #6278448086
Merge pull request #627 from actions/robherley/v4.4.2b1d4642
add explicit relative and absolute symlinks to workflowd50e660
bump versionaabe6f8
build with@actions/artifact
v2.1.11604373d
Merge pull request #625 from actions/robherley/artifact-2.1.100150148
paste right core versiona009b25
update licenses9f6f6f4
update@actions/core
and@actions/artifact
to latest versionsUpdates
github/codeql-action
from 3.26.6 to 3.27.0Release notes
Sourced from github/codeql-action's releases.