chore(deps): bump the github-actions group with 7 updates - #795
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions group with 7 updates: | Package | From | To | | --- | --- | --- | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.8` | `4.37.9` | | [azure/login](https://github.com/azure/login) | `3.0.1` | `3.0.2` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.8` | `4.37.9` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.37.8` | `4.37.9` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.8` | `4.37.9` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.24.0` | `0.24.2` | | [chainguard-dev/actions/setup-gitsign](https://github.com/chainguard-dev/actions) | `1.6.33` | `1.6.34` | Updates `github/codeql-action/upload-sarif` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) Updates `azure/login` from 3.0.1 to 3.0.2 - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@f5d393a...7ddb5af) Updates `github/codeql-action/init` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) Updates `github/codeql-action/autobuild` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) Updates `github/codeql-action/analyze` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) Updates `anchore/sbom-action` from 0.24.0 to 0.24.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@e22c389...3ad7283) Updates `chainguard-dev/actions/setup-gitsign` from 1.6.33 to 1.6.34 - [Release notes](https://github.com/chainguard-dev/actions/releases) - [Commits](chainguard-dev/actions@0ffab11...a9d4aa7) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: azure/login dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/autobuild dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: chainguard-dev/actions/setup-gitsign dependency-version: 1.6.34 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #795 +/- ##
=======================================
Coverage 31.79% 31.79%
=======================================
Files 40 40
Lines 6017 6017
=======================================
Hits 1913 1913
Misses 4104 4104
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
Marcel Bindseil (bindsi)
left a comment
There was a problem hiding this comment.
Thanks for the pinned action updates. Reviewed all 12 workflow files, verified the new SHAs against official release tags, and checked action inputs, runtime compatibility, and unchanged permission boundaries. Actionlint passed on head and base; the current required gate and relevant CI checks pass. No introduced blocker found. Code approval only: the branch must satisfy the up-to-date validation gate before merge.
|
Dependabot (@dependabot) rebase |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the github-actions group with 7 updates:
4.37.84.37.93.0.13.0.24.37.84.37.94.37.84.37.94.37.84.37.90.24.00.24.21.6.331.6.34Updates
github/codeql-action/upload-sariffrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
azure/loginfrom 3.0.1 to 3.0.2Release notes
Sourced from azure/login's releases.
Commits
7ddb5afprepare release v3.0.2d90bae5Cap@actions/execand@actions/corebelow the ESM-only 3.x majors (#628)ff48d59Bump uuid and@actions/core(#589)a26a331Bump brace-expansion from 1.1.12 to 1.1.18 (#616)ca06f43Refactor PS login to use a static param()-bound script (#607)905554eAdd admin-gated Release workflow (#610)1029b1aBump the github-actions group across 1 directory with 7 updates (#621)ae37a0dHarden Dependabot config for the CommonJS ncc build (#622)43c6847Docs uplift (#620)cf887bbBump picomatch from 2.3.1 to 2.3.2 (#582)Updates
github/codeql-action/initfrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/autobuildfrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/autobuild's releases.
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/analyzefrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
anchore/sbom-actionfrom 0.24.0 to 0.24.2Release notes
Sourced from anchore/sbom-action's releases.
Commits
3ad7283ops: update write permissions for release (#723)31f5287chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#724)aa80c8cchore(deps): update Syft to latest release (#722)74b54e9chore(deps): bump lodash from 4.17.23 to 4.18.1 (#623)6b92ff5chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#721)4f8983bchore(deps-dev): bump typescript-eslint from 8.65.0 to 8.67.0 (#719)10f27f4chore(deps-dev): bump eslint from 10.5.0 to 10.8.1 (#720)249403achore(deps-dev): bump@types/nodefrom 26.1.0 to 26.2.0 (#718)cbf8daachore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#693)6afc793fix: pin syft install.sh to the release tag being installed (#716)Updates
chainguard-dev/actions/setup-gitsignfrom 1.6.33 to 1.6.34Release notes
Sourced from chainguard-dev/actions/setup-gitsign's releases.
Commits
a9d4aa7fix(melange-build-pkg): fix --source-dir (#991)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions