Bump the github-actions group across 1 directory with 5 updates #15565
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 5 updates in the / directory:
44451.0.01.4.32.3.32.4.03.25.113.26.102.0.62.0.8Updates
tj-actions/changed-filesfrom 44 to 45Release notes
Sourced from tj-actions/changed-files's releases.
... (truncated)
Changelog
Sourced from tj-actions/changed-files's changelog.
... (truncated)
Commits
48d8f15chore(deps): update peter-evans/create-pull-request action to v7.0.3f4e0652chore(deps): lock file maintenance9b5f7d7chore(deps): update dependency@types/nodeto v22.5.580dc584chore(deps): update dependency@types/jestto v29.5.13f9216b6chore(deps): update peter-evans/create-pull-request action to v7.0.2fef272dchore(deps): update dependency eslint-plugin-github to v5.0.2a236bf5chore(deps): update dependency typescript to v5.6.20cb58dechore(deps): lock file maintenance44f3356chore(deps): lock file maintenance1d9fddachore(deps): update peter-evans/create-pull-request action to v7.0.1Updates
actions/attest-build-provenancefrom 1.0.0 to 1.4.3Release notes
Sourced from actions/attest-build-provenance's releases.
... (truncated)
Commits
1c608d1bump predicate from 1.1.2 to 1.1.3 (#226)f1185f1bump@actions/attestfrom 1.4.1 to 1.4.2 (#225)d438876add sigstore prober (#224)8f30a5cBump the npm-development group with 3 updates (#218)13f0f0dBump@actions/attestfrom 1.3.1 to 1.4.1 (#212)a950611Bump the npm-development group with 2 updates (#211)814a778Bump the npm-development group with 3 updates (#206)6149ea5bump actions/attest from 1.4.0 to 1.4.1 (#209)3eb3242Bump super-linter/super-linter from 6 to 7 (#205)399bb17Bump@types/nodefrom 22.2.0 to 22.4.0 in the npm-development group (#203)Updates
ossf/scorecard-actionfrom 2.3.3 to 2.4.0Release notes
Sourced from ossf/scorecard-action's releases.
Commits
62b2cacbump docker tag to v2.4.0 for release (#1414)c09630clower license score alert threshold to 9 (#1411)cf8594c🌱 Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.3.0 (#1413)de5fcb9🌱 Bump the github-actions group with 2 updates (#1412)a46b90bbump scorecard to v5.0.0 release (#1410)9fc518d🌱 Bump golang in the docker-images group (#1407)a8eaa1b🌱 Bump the github-actions group with 2 updates (#1408)873d5fd🌱 Bump the github-actions group across 1 directory with 2 updates (#...54cc1fe🌱 Bump the docker-images group with 2 updates (#1401)82bcb91🌱 Bump golang.org/x/net from 0.26.0 to 0.27.0 (#1400)Updates
github/codeql-actionfrom 3.25.11 to 3.26.10Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
e2b3eafMerge pull request #2507 from github/update-v3.26.10-2617ff2d37dbbf6dUpdate changelog for v3.26.102617ff2Merge pull request #2502 from github/henrymercer/zstd-experiment46e0c78Merge pull request #2504 from github/mergeback/v3.26.9-to-main-461ef6c7da7be78Update checked-in dependenciesae1c6a2Update changelog and version after v3.26.9461ef6cMerge pull request #2503 from github/update-v3.26.9-f861efb2b00b1146Update changelog for v3.26.9f861efbMerge pull request #2498 from github/dependabot/npm_and_yarn/npm-9874b37b586b2f7e7Run PR checks using JS onlyUpdates
softprops/action-gh-releasefrom 2.0.6 to 2.0.8Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
c062e08release 2.0.8380635cchore(deps): bump@actions/githubfrom 5.1.1 to 6.0.0 (#470)20adb42refactor: write jest config in ts (#485)f808f15chore(deps): bump glob from 10.4.2 to 11.0.0 (#477)6145241chore(deps): bump@octokit/plugin-throttlingfrom 9.3.0 to 9.3.1 (#484)4ac522dchore(deps): bump@types/nodefrom 20.14.9 to 20.14.11 (#483)25849b1chore(deps): bump prettier from 2.8.0 to 3.3.3 (#480)6206056chore: update dependabot commit msg39aadf1chore: runfrizbee actions .github/workflows/6f3ab65chore: update dist fileDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions