-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ci(deps): bump the github-actions group with 6 updates #600
ci(deps): bump the github-actions group with 6 updates #600
Conversation
Bumps the github-actions group with 6 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.0` | `4.2.1` | | [actions/cache](https://github.com/actions/cache) | `4.1.0` | `4.1.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.17.2` | `0.17.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.0` | `4.4.3` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `8.0.0` | `8.1.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.26.11` | `3.26.12` | Updates `actions/checkout` from 4.2.0 to 4.2.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@d632683...eef6144) Updates `actions/cache` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@2cdf405...3624ceb) Updates `anchore/sbom-action` from 0.17.2 to 0.17.3 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@61119d4...f5e124a) Updates `actions/upload-artifact` from 4.4.0 to 4.4.3 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@5076954...b4b15b8) Updates `oxsecurity/megalinter` from 8.0.0 to 8.1.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@c217fe8...b38cdf1) Updates `github/codeql-action` from 3.26.11 to 3.26.12 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@6db8d63...c36620d) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/cache dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Quality Gate passedIssues Measures |
Compressed layer size comparisonComparing
|
Compressed layer size comparisonComparing
|
🦙 MegaLinter status: ✅ SUCCESS
See detailed report in MegaLinter reports You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
|
Pull Request Report (#600)Static measures
Time related measures
Status check related measures
|
🎉 Hooray! The changes in this pull request went live with the release of v5.3.2 🎉 |
Bumps the github-actions group with 6 updates:
4.2.0
4.2.1
4.1.0
4.1.1
0.17.2
0.17.3
4.4.0
4.4.3
8.0.0
8.1.0
3.26.11
3.26.12
Updates
actions/checkout
from 4.2.0 to 4.2.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
eef6144
Prepare 4.2.1 release (#1925)6b42224
Add workflow file for publishing releases to immutable action package (#1919)de5a000
Check out other refs/* by commit if provided, fall back to ref (#1924)Updates
actions/cache
from 4.1.0 to 4.1.1Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
3624ceb
Restore original behavior ofcache-hit
output (#1467)Updates
anchore/sbom-action
from 0.17.2 to 0.17.3Release notes
Sourced from anchore/sbom-action's releases.
Commits
f5e124a
chore(deps): bump peter-evans/create-pull-request from 6.1.0 to 7.0.5 (#493)eff08d0
chore: configure changelog-ignore label (#499)18f9bde
chore: remove snapshot tests; fix deprecation errors for outdated packages (#...2e87236
add release docs (#500)4a914bc
chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 (#497)8cb9966
chore(deps): update Syft to v1.14.0 (#498)beb779b
Update README to include bit about permissions near the top (#496)87b3137
chore(deps): update Syft to v1.13.0 (#488)5cc1a40
chore(deps): bump actions/checkout from 4.1.7 to 4.2.0 (#495)dbef896
add awaiting response management (#494)Updates
actions/upload-artifact
from 4.4.0 to 4.4.3Release notes
Sourced from actions/upload-artifact's releases.
Commits
b4b15b8
Merge pull request #632 from actions/joshmgross/undo-dependency-changes92b01eb
Undo indirect dependency updates from #6278448086
Merge pull request #627 from actions/robherley/v4.4.2b1d4642
add explicit relative and absolute symlinks to workflowd50e660
bump versionaabe6f8
build with@actions/artifact
v2.1.11604373d
Merge pull request #625 from actions/robherley/artifact-2.1.100150148
paste right core versiona009b25
update licenses9f6f6f4
update@actions/core
and@actions/artifact
to latest versionsUpdates
oxsecurity/megalinter
from 8.0.0 to 8.1.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
b38cdf1
Release MegaLinter v8.1.034e6e89
chore(deps): update dependency@salesforce/plugin-packaging
to v2.8.12 (#4108)af5b600
chore(deps): update dependency@salesforce/cli
to v2.61.8 (#4105)ff75bda
fix(deps): update dependency mem-fs to v4.1.1 (#4111)3611a99
[automation] Auto-update linters version, help and documentation (#4117)7e0f487
Update renovate configuration, schedule and groups (#4116)eca1d16
chore(deps): update dependency sfdx-hardis to v5.1.0 (#4115)40d8b26
chore(deps): update trufflesecurity/trufflehog docker tag to v3.82.8 (#4109)be4d2ce
chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.4.20 (#4102)fdd83ef
chore(deps): update dependency psscriptanalyzer to 1.23.0 (#4106)Updates
github/codeql-action
from 3.26.11 to 3.26.12Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
c36620d
Merge pull request #2529 from github/update-v3.26.12-c9a70ff45570aecb
Update changelog for v3.26.12c9a70ff
Merge pull request #2526 from github/henrymercer/check-zstd-on-pathd65a176
Rebuildbf2e624
Update src/tar.ts56d1975
Merge pull request #2489 from github/redsun82/rust7cf65a5
Merge pull request #2518 from github/dependabot/npm_and_yarn/npm-88156698cd8a56dd2
Update to@actions/core
1.11.11532671
Update default bundle to 2.19.1 (#2519)64871a8
Merge branch 'main' into update-bundle/codeql-bundle-v2.19.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions