-
Notifications
You must be signed in to change notification settings - Fork 594
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump the ci group with 12 updates #4696
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dependabot
bot
added
area/ci
CI related issues and pull requests
dependencies
Pull requests that update a dependency
labels
Apr 1, 2024
Bumps the ci group with 12 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.1.1` | `4.1.2` | | [korthout/backport-action](https://github.com/korthout/backport-action) | `2.4.1` | `2.5.0` | | [Azure/login](https://github.com/azure/login) | `1.6.1` | `2.0.0` | | [helm/kind-action](https://github.com/helm/kind-action) | `1.8.0` | `1.9.0` | | [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.0` | `2.1.2` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.0.0` | `3.2.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.0.0` | `3.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.0` | `4.3.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.15.8` | `0.15.10` | | [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) | `1.9.0` | `1.10.0` | | [EndBug/label-sync](https://github.com/endbug/label-sync) | `2.3.2` | `2.3.3` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `6.0.0` | `6.0.2` | Updates `actions/checkout` from 4.1.1 to 4.1.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@b4ffde6...9bb5618) Updates `korthout/backport-action` from 2.4.1 to 2.5.0 - [Release notes](https://github.com/korthout/backport-action/releases) - [Commits](korthout/backport-action@e8161d6...ef20d86) Updates `Azure/login` from 1.6.1 to 2.0.0 - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@cb79c77...8c334a1) Updates `helm/kind-action` from 1.8.0 to 1.9.0 - [Release notes](https://github.com/helm/kind-action/releases) - [Commits](helm/kind-action@dda0770...99576bf) Updates `google-github-actions/auth` from 2.1.0 to 2.1.2 - [Release notes](https://github.com/google-github-actions/auth/releases) - [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md) - [Commits](google-github-actions/auth@5a50e58...55bd3a7) Updates `docker/setup-buildx-action` from 3.0.0 to 3.2.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@f95db51...2b51285) Updates `docker/login-action` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@343f7c4...e92390c) Updates `actions/upload-artifact` from 4.3.0 to 4.3.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@26f96df...5d5d22a) Updates `anchore/sbom-action` from 0.15.8 to 0.15.10 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Commits](anchore/sbom-action@b6a39da...ab5d7b5) Updates `slsa-framework/slsa-github-generator` from 1.9.0 to 1.10.0 - [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases) - [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md) - [Commits](slsa-framework/slsa-github-generator@v1.9.0...v1.10.0) Updates `EndBug/label-sync` from 2.3.2 to 2.3.3 - [Release notes](https://github.com/endbug/label-sync/releases) - [Commits](EndBug/label-sync@da00f2c...5207415) Updates `peter-evans/create-pull-request` from 6.0.0 to 6.0.2 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@b1ddad2...70a41ab) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: korthout/backport-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: Azure/login dependency-type: direct:production update-type: version-update:semver-major dependency-group: ci - dependency-name: helm/kind-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: google-github-actions/auth dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: anchore/sbom-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: slsa-framework/slsa-github-generator dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: EndBug/label-sync dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
bot
force-pushed
the
dependabot/github_actions/ci-5a961a13fe
branch
from
April 3, 2024 06:31
8fa9cc7
to
f63385a
Compare
stefanprodan
approved these changes
Apr 3, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the ci group with 12 updates:
4.1.1
4.1.2
2.4.1
2.5.0
1.6.1
2.0.0
1.8.0
1.9.0
2.1.0
2.1.2
3.0.0
3.2.0
3.0.0
3.1.0
4.3.0
4.3.1
0.15.8
0.15.10
1.9.0
1.10.0
2.3.2
2.3.3
6.0.0
6.0.2
Updates
actions/checkout
from 4.1.1 to 4.1.2Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9bb5618
Prep for release of v4.1.2 (#1649)8eb1f6a
Bump@babel/traverse
from 7.20.5 to 7.24.0 (#1642)556e4c3
Bump tough-cookie from 4.0.0 to 4.1.3 (#1406)b32f140
Warn on attempts to publishtest-ubuntu-git
from non-main branch. (#1623)2650dbd
Givetest-ubuntu-git
its ownREADME
(#1620)aadec89
Explicitly disable sparse checkout unless asked for (#1598)df0bcdd
Refine workflow for generatingtest-ubuntu-git
(#1617)473055b
Createtest-ubuntu-git
Docker Container for Proxy Tests (#1616)Updates
korthout/backport-action
from 2.4.1 to 2.5.0Release notes
Sourced from korthout/backport-action's releases.
Commits
ef20d86
dist: release 2.5.0891b4f5
Merge pull request #416 from AlexVermette-Eaton/feature/branch_namee0ada12
dist: build new versionc36b5ac
style: auto format34d8598
added to ReadMe1126229
sorted alphanum new input.b3fef5a
revert package-lock.jsone7b873b
Update action.ymlcd13022
Added branch name input. Upgraded vulnerable packages.1081c49
dist: build new artifactsUpdates
Azure/login
from 1.6.1 to 2.0.0Release notes
Sourced from Azure/login's releases.
Commits
8c334a1
prepare release v281e1d9f
Update README.md forazure/login@v2
(#423)c847559
Bump dependencies versions (#419)332d569
Update Action to use Node.js v20 (#411)dcaef12
Temp change ci test for a bug in azps (#416)3d449ed
Fix CodeQL error: Resource not accessible by integration & Update CodeQL vers...Updates
helm/kind-action
from 1.8.0 to 1.9.0Release notes
Sourced from helm/kind-action's releases.
Commits
99576bf
docs: bump outdated action version in README (#92)0ca85d0
docs: fix default version in action.yml (#91)fc8d4ed
Fix arch detection in non-Debian distros (#93)4be822c
chore: Bump node version to node20 (#102)100421e
Bump actions/checkout from 4.1.0 to 4.1.1 (#99)5adb538
Bump actions/checkout from 4.0.0 to 4.1.0 (#98)49375a6
Bump actions/checkout from 3.6.0 to 4.0.0 (#97)2d498b1
Bump actions/checkout from 3.5.3 to 3.6.0 (#96)77db130
Bump actions/checkout from 3.3.0 to 3.5.3 (#90)Updates
google-github-actions/auth
from 2.1.0 to 2.1.2Release notes
Sourced from google-github-actions/auth's releases.
Commits
55bd3a7
Release: v2.1.2 (#399)bf02f20
Reduce warnings to info level with a warning icon (#397)51342a1
security: bump undici from 5.28.2 to 5.28.3 (#394)ee1c1b6
Add security considerations for Attribute Conditions (#393)ec485ac
Remove documentation on retries (deprecated) (#392)a6e2e39
Release: v2.1.1 (#390)b4f4057
Use an OAuth 2.0 access token for Domain-Wide Delegation (#388)39c96a3
Remove retry logic (#389)Updates
docker/setup-buildx-action
from 3.0.0 to 3.2.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
2b51285
Merge pull request #306 from docker/dependabot/npm_and_yarn/docker/actions-to...0f00370
chore: update generated content11c9683
build(deps): bump@docker/actions-toolkit
from 0.18.0 to 0.19.056a16b8
Merge pull request #303 from crazy-max/fix-inputsc23f46e
chore: update generated contentf876da6
rename and align config inputsb7cf918
Merge pull request #304 from crazy-max/rm-docs-dir0150f0e
chore: remove docs dird89f1f9
Merge pull request #302 from docker/dependabot/npm_and_yarn/docker/actions-to...12d65f6
chore: update generated contentUpdates
docker/login-action
from 3.0.0 to 3.1.0Release notes
Sourced from docker/login-action's releases.
Commits
e92390c
Merge pull request #685 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...1e752e2
chore: update generated content51c6097
build(deps): bump the aws-sdk-dependencies group with 2 updates8f079fb
Merge pull request #676 from docker/dependabot/npm_and_yarn/proxy-agent-depen...16fa768
chore: update generated content46d1619
build(deps): bump the proxy-agent-dependencies group with 2 updates8c291c5
Merge pull request #682 from docker/dependabot/npm_and_yarn/docker/actions-to...ec726f4
build(deps): bump@docker/actions-toolkit
from 0.14.0 to 0.18.05139682
Merge pull request #677 from docker/dependabot/npm_and_yarn/undici-5.28.36d4e2ba
chore: update generated contentUpdates
actions/upload-artifact
from 4.3.0 to 4.3.1Release notes
Sourced from actions/upload-artifact's releases.
Commits
5d5d22a
Merge pull request #515 from actions/eggyhead/update-artifact-v2.1.1f1e993d
update artifact license4881bfd
updating dist:a30777e
@eggyhead
3a80482
Merge pull request #511 from actions/robherley/migration-docs-typo9d63e3f
Merge branch 'main' into robherley/migration-docs-typodfa1ab2
fix typo with v3 artifact downloads in migration guided00351b
Merge pull request #509 from markmssd/patch-1707f5a7
Update limitation of10
artifacts upload to500
Updates
anchore/sbom-action
from 0.15.8 to 0.15.10Release notes
Sourced from anchore/sbom-action's releases.
Commits
ab5d7b5
chore(deps): update Syft to v1.1.0 (#454)6e7f9d7
chore(deps): bump release-drafter/release-drafter from 5.25.0 to 6.0.0 (#450)2d906a3
chore(deps): bump peter-evans/create-or-update-comment (#452)691c762
chore(deps): bump peter-evans/create-pull-request from 5.0.2 to 6.0.2 (#453)f0dafef
chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 (#451)c6d7b2a
chore: add dependabot configuration for actions (#449)31e2bb2
chore(deps): update@types/node
to Node 20 (#443)670514f
chore: Bump Node to v20 on download-syft/publish-sbom actions (#448)a5afbb1
chore(deps): update Syft to v1.0.1 (#444)9fece9e
fix: reduce syft debug level (#446)Updates
slsa-framework/slsa-github-generator
from 1.9.0 to 1.10.0Release notes
Sourced from slsa-framework/slsa-github-generator's releases.
Changelog
Sourced from slsa-framework/slsa-github-generator's changelog.
Commits
c747fe7
chore: Update ref for v1.10.0 release (#3420)d97d88e
chore: v1.10.0-rc.0 (#3418)6ff2c75
chore: Amend readme text before release (#3402)2cf77fa
chore: Revert "fix: remove attestation-name input and output" (#3399)5c347c0
chore: ref builders at main (#3417)e4fc9a0
chore: fix release workflow (#3414)6953299
chore: v1.9.1-rc.0 (#3413)a2540a1
chore: Update changelog for #3350 (#3401)90f2eb1
chore: Revert "fix: upload-artifact and download-artifact v4" (#3398)1fee7c6
fix: Bump Cosign to latest v2.2.3 (#3355)Updates
EndBug/label-sync
from 2.3.2 to 2.3.3Release notes
Sourced from EndBug/label-sync's releases.
... (truncated)
Commits
5207415
2.3.306c7db9
chore: update build8b2e827
docs: add reece as a contributor for maintenance (#270)c7b590a
fix: update action.yml (#269)b09d94f
chore(deps-dev): bump@typescript-eslint/eslint-plugin
(#268)a464ca4
chore(deps-dev): bump prettier from 3.1.1 to 3.2.4 (#264)60024a7
chore(deps): bump axios from 1.6.3 to 1.6.7 (#267)4ddbbec
chore(deps-dev): bump@typescript-eslint/parser
from 6.18.1 to 6.20.0 (#266)0039e3c
chore(deps-dev): bump husky from 8.0.3 to 9.0.7 (#265)cca8d68
docs: mention description limitations (#261)Updates
peter-evans/create-pull-request
from 6.0.0 to 6.0.2Release notes
Sourced from peter-evans/create-pull-request's releases.