chore(deps): Bump the github-actions group across 1 directory with 12 updates - #586
chore(deps): Bump the github-actions group across 1 directory with 12 updates#586dependabot[bot] wants to merge 1 commit into
Conversation
… updates Bumps the github-actions group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.21.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.24.0` | `0.24.2` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.1` | `4.2.2` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.1` | `3.0.2` | | [restyled-io/actions/setup](https://github.com/restyled-io/actions) | `4.4.27` | `4.4.28` | | [restyled-io/actions/run](https://github.com/restyled-io/actions) | `4.4.27` | `4.4.28` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.9` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.37.0` | `4.37.9` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.0` | `4.37.9` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.0` | `4.37.9` | | [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `8.2.0` | `8.2.1` | Updates `step-security/harden-runner` from 2.20.0 to 2.21.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@bf7454d...05e3151) Updates `anchore/sbom-action` from 0.24.0 to 0.24.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@e22c389...3ad7283) Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@0f67c3f...4d10147) Updates `softprops/action-gh-release` from 3.0.1 to 3.0.2 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@718ea10...3d0d988) Updates `restyled-io/actions/setup` from 4.4.27 to 4.4.28 - [Release notes](https://github.com/restyled-io/actions/releases) - [Commits](restyled-io/actions@bce8886...67eaade) Updates `restyled-io/actions/run` from 4.4.27 to 4.4.28 - [Release notes](https://github.com/restyled-io/actions/releases) - [Commits](restyled-io/actions@bce8886...67eaade) Updates `github/codeql-action/init` from 4.37.0 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...cdf488f) Updates `github/codeql-action/autobuild` from 4.37.0 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...cdf488f) Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...cdf488f) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@4eaacf0...2d11466) Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...cdf488f) Updates `SonarSource/sonarqube-scan-action` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@7138816...2291811) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: restyled-io/actions/setup dependency-version: 4.4.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: restyled-io/actions/run dependency-version: 4.4.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/autobuild dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
VEX Assessment:
|
🐰 Mimi's Validation Report ✅All checks are looking good! Great job! 🎉 ⏳ Some checks are still running. I will keep watching!
This report was carefully prepared by nullvariant-mimi[bot] |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
🕊️ Ciel's Mediation 💤*~~ drifting lazily through still air ~~ The zoo is napping today...* 1 zoo member has reviewed this PR.
😴 A quiet day at the zoo. Only one member peeked at this PR.
This mediation was peacefully delivered by nullvariant-ciel[bot] |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Bumps the github-actions group with 12 updates in the / directory:
2.20.02.21.00.24.00.24.24.1.14.2.23.0.13.0.24.4.274.4.284.4.274.4.284.37.04.37.94.37.04.37.94.37.04.37.92.4.32.4.44.37.04.37.98.2.08.2.1Updates
step-security/harden-runnerfrom 2.20.0 to 2.21.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
05e3151Merge pull request #684 from step-security/rc-420f37afafix: ignore denied-endpoints on non-enterprise tier93b58eefix: resolve cache host read-first and never downgrade egress policye7399ddfix: align deny-list mode detection with agent and log when both endpoint inp...c16689ftest: add denied_endpoints to Configuration fixtures and cover deny-list merge40b99cfMerge pull request #682 from rohan-stepsecurity/rp/feat/codebuild-self-v2fedec02Merge branch 'rc-42' into rp/feat/codebuild-self-v25361fb1feat: add build artifacts286474ffeat: Support Bravo agent install on CodeBuild runners051ec05Merge pull request #683 from h0x0er/jatin/deny-listUpdates
anchore/sbom-actionfrom 0.24.0 to 0.24.2Release notes
Sourced from anchore/sbom-action's releases.
Commits
3ad7283ops: update write permissions for release (#723)31f5287chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#724)aa80c8cchore(deps): update Syft to latest release (#722)74b54e9chore(deps): bump lodash from 4.17.23 to 4.18.1 (#623)6b92ff5chore(deps-dev): bump tsx from 4.23.11 to 4.23.12 (#721)4f8983bchore(deps-dev): bump typescript-eslint from 8.65.0 to 8.67.0 (#719)10f27f4chore(deps-dev): bump eslint from 10.5.0 to 10.8.1 (#720)249403achore(deps-dev): bump@types/nodefrom 26.1.0 to 26.2.0 (#718)cbf8daachore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#693)6afc793fix: pin syft install.sh to the release tag being installed (#716)Updates
actions/attest-build-provenancefrom 4.1.1 to 4.2.2Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)Updates
softprops/action-gh-releasefrom 3.0.1 to 3.0.2Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
3d0d988release 3.0.2 (#818)7e13ed4fix: clarify release creation 404 errors (#817)e6c70a5fix: replace existing release assets on Gitea (#816)f345337fix: publish existing draft releases as prereleases (#801)d8a89a2fix: upload small checksum assets reliably (#815)45ece40chore(deps): remove unused TypeScript tooling (#814)f6b913cfeat: improve release error reporting and test coverage (#813)15f193dchore(deps): upgrade TypeScript to 7 (#812)cc8268dchore(deps): bump actions/checkout in the github-actions group (#810)fd0ed1echore(deps): bump the npm group with 3 updates (#811)Updates
restyled-io/actions/setupfrom 4.4.27 to 4.4.28Release notes
Sourced from restyled-io/actions/setup's releases.
Commits
67eaadefix(deps): bump postcss650ec7achore(deps-dev): bump globals from 17.7.0 to 17.8.0 in /run8037b9echore(deps-dev): bump@types/nodefrom 26.1.1 to 26.1.2 in /run5068d52chore(deps-dev): bump jsdom from 29.1.1 to 30.0.0 in /run6be918cchore(deps-dev): bump eslint from 10.7.0 to 10.8.0 in /run6255470chore(deps-dev): bump ts-jest from 29.4.11 to 29.4.12 in /run3613ddcchore(deps-dev): bump prettier from 3.9.5 to 3.9.6 in /runecf0b39chore(deps-dev): bump typescript-eslint from 8.64.0 to 8.65.0 in /runee2fc83chore(deps): bump actions/setup-node from 6 to 7b87d2eechore(deps-dev): bump eslint from 10.6.0 to 10.7.0 in /runUpdates
restyled-io/actions/runfrom 4.4.27 to 4.4.28Release notes
Sourced from restyled-io/actions/run's releases.
Commits
67eaadefix(deps): bump postcss650ec7achore(deps-dev): bump globals from 17.7.0 to 17.8.0 in /run8037b9echore(deps-dev): bump@types/nodefrom 26.1.1 to 26.1.2 in /run5068d52chore(deps-dev): bump jsdom from 29.1.1 to 30.0.0 in /run6be918cchore(deps-dev): bump eslint from 10.7.0 to 10.8.0 in /run6255470chore(deps-dev): bump ts-jest from 29.4.11 to 29.4.12 in /run3613ddcchore(deps-dev): bump prettier from 3.9.5 to 3.9.6 in /runecf0b39chore(deps-dev): bump typescript-eslint from 8.64.0 to 8.65.0 in /runee2fc83chore(deps): bump actions/setup-node from 6 to 7b87d2eechore(deps-dev): bump eslint from 10.6.0 to 10.7.0 in /runUpdates
github/codeql-action/initfrom 4.37.0 to 4.37.9Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/autobuildfrom 4.37.0 to 4.37.9Release notes
Sourced from github/codeql-action/autobuild's releases.
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/analyzefrom 4.37.0 to 4.37.9Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
ossf/scorecard-actionfrom 2.4.3 to 2.4.4Release notes
Sourced from ossf/scorecard-action's releases.
Commits
2d11466Bump action tag for v2.4.4 release (#1688)