Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update github-actions #67

Merged
merged 4 commits into from
Sep 1, 2023
Merged

chore(deps): update github-actions #67

merged 4 commits into from
Sep 1, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 1, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v3.1.0 -> v3.6.0
actions/checkout action digest 2541b12 -> f43a0e5
actions/download-artifact action patch v3.0.0 -> v3.0.2
actions/upload-artifact action patch v3.1.0 -> v3.1.2
amannn/action-semantic-pull-request action minor v5.0.2 -> v5.2.0
benchmark-action/github-action-benchmark action minor v1.14.0 -> v1.18.0
bufbuild/buf-lint-action action patch v1.0.2 -> v1.0.3
bufbuild/buf-setup-action action minor v1.8.0 -> v1.26.1
docker/build-push-action action digest c84f382 -> 1104d47
docker/login-action action digest 49ed152 -> 465a078
docker/metadata-action action digest 69f6fc9 -> 818d4b7
docker/setup-buildx-action action digest dc7b971 -> 885d146
docker/setup-qemu-action action digest 8b12248 -> 2b82ce8
github/codeql-action action pinDigest -> 00e563e
github/codeql-action action minor v2.1.27 -> v2.21.5
google-github-actions/release-please-action action minor v3.5.1 -> v3.7.11
helm/kind-action action minor v1.4.0 -> v1.8.0
iter8-tools/iter8 action minor v0.13.17 -> v0.16.6
marocchino/sticky-pull-request-comment action minor v2.2.0 -> v2.8.0
ossf/scorecard-action action minor v2.0.6 -> v2.2.0
oxsecurity/megalinter action minor v6.18.0 -> v6.22.2
sigstore/cosign-installer action digest 9becc61 -> c85d0e2
slsa-framework/slsa-github-generator action minor v1.4.0 -> v1.9.0

Release Notes

actions/checkout (actions/checkout)

v3.6.0

Compare Source

v3.5.3

Compare Source

v3.5.2

Compare Source

v3.5.1

Compare Source

v3.5.0

Compare Source

v3.4.0

Compare Source

v3.3.0

Compare Source

v3.2.0

Compare Source

actions/download-artifact (actions/download-artifact)

v3.0.2

Compare Source

v3.0.1

Compare Source

actions/upload-artifact (actions/upload-artifact)

v3.1.2

Compare Source

  • Update all @actions/* NPM packages to their latest versions- #​374
  • Update all dev dependencies to their most recent versions - #​375

v3.1.1

Compare Source

  • Update actions/core package to latest version to remove set-output deprecation warning #​351
amannn/action-semantic-pull-request (amannn/action-semantic-pull-request)

v5.2.0

Compare Source

Features

v5.1.0

Compare Source

Features
  • Add regex support to scope and disallowScopes configuration (#​226) (403a6f8)
benchmark-action/github-action-benchmark (benchmark-action/github-action-benchmark)

v1.18.0

Compare Source

  • feat getServerUrl refers to the GITHUB_SERVER_URL environment variable (#​169)
  • feat extract multiple metrics from Golang benchmarks (#​177)
  • fix getCommitFromGitHubAPIRequest to refer to GITHUB_API_URL (#​171)
  • chore Remove unreachable code from extract.ts (#​153)

v1.17.0

Compare Source

  • feat support for JMH parameters (as separate charts) (#​161)
  • feat enable user to specify the ref being tested (#​163)
  • feat allow more characters in Golang bench outputs (#​131)

v1.16.2

Compare Source

  • Fix use commit.id over commit object (#​155)

v1.16.1

Compare Source

  • Fix action.yml missing summary-always input

v1.16.0

Compare Source

  • Feat Support pr summary for benchmark output (#​138)

v1.15.0

Compare Source

bufbuild/buf-lint-action (bufbuild/buf-lint-action)

v1.0.3

Compare Source

  • Upgrade dependencies.
  • No other major changes.
bufbuild/buf-setup-action (bufbuild/buf-setup-action)

v1.26.1

Compare Source

v1.26.0

Compare Source

v1.25.1

Compare Source

v1.25.0

Compare Source

v1.24.0

Compare Source

v1.23.1

Compare Source

v1.23.0

Compare Source

v1.22.0

Compare Source

v1.21.0

Compare Source

v1.20.0

Compare Source

v1.19.0

Compare Source

v1.18.0

Compare Source

v1.17.0

Compare Source

v1.16.0

Compare Source

v1.15.1

Compare Source

v1.15.0

Compare Source

v1.14.0

Compare Source

v1.13.1

Compare Source

v1.13.0

Compare Source

v1.12.0

Compare Source

v1.11.0

Compare Source

Set the default buf version to v1.10.0

v1.10.0

Compare Source

Set the default buf version to v1.10.0

v1.9.0

Compare Source

  • Set the default buf version to v1.9.0
github/codeql-action (github/codeql-action)

v2.21.5

Compare Source

v2.21.4

Compare Source

v2.21.3

Compare Source

v2.21.2

Compare Source

v2.21.1

Compare Source

v2.21.0

Compare Source

v2.20.4

Compare Source

v2.20.3

Compare Source

v2.20.2

Compare Source

v2.20.1

Compare Source

v2.20.0

Compare Source

v2.3.6

Compare Source

v2.3.5

Compare Source

v2.3.4

Compare Source

v2.3.3

Compare Source

v2.3.2

Compare Source

v2.3.1

Compare Source

v2.3.0

Compare Source

v2.2.12

Compare Source

v2.2.11

Compare Source

v2.2.10

Compare Source

v2.2.9

Compare Source

v2.2.8

Compare Source

v2.2.7

Compare Source

v2.2.6

Compare Source

v2.2.5

Compare Source

v2.2.4

Compare Source

v2.2.3

Compare Source

v2.2.2

Compare Source

v2.2.1

Compare Source

v2.2.0

Compare Source

v2.1.39

Compare Source

v2.1.38

Compare Source

v2.1.37

Compare Source

v2.1.36

Compare Source

v2.1.35

Compare Source

v2.1.34

Compare Source

v2.1.33

Compare Source

v2.1.32

Compare Source

v2.1.31

Compare Source

v2.1.30

Compare Source

v2.1.29

Compare Source

v2.1.28

Compare Source

google-github-actions/release-please-action (google-github-actions/release-please-action)

v3.7.11

Compare Source

Bug Fixes

v3.7.10

Compare Source

Bug Fixes

v3.7.9

Compare Source

Bug Fixes

v3.7.8

Compare Source

Bug Fixes

v3.7.7

Compare Source

Bug Fixes

v3.7.6

Compare Source

Bug Fixes

v3.7.5

Compare Source

Bug Fixes

v3.7.4

Compare Source

Bug Fixes

v3.7.3

Compare Source

Bug Fixes

v3.7.2

Compare Source

Bug Fixes

v3.7.1

Compare Source

Bug Fixes

v3.7.0

Compare Source

Features
Bug Fixes

v3.6.1

Compare Source

Bug Fixes

v3.6.0

Compare Source

Features
Bug Fixes
helm/kind-action (helm/kind-action)

v1.8.0

Compare Source

What's Changed

New Contributors

Full Changelog: helm/kind-action@v1.7.0...v1.8.0

v1.7.0

Compare Source

What's Changed

Full Changelog: helm/kind-action@v1.6.0...v1.7.0

v1.6.0

Compare Source

What's Changed

New Contributors

Full Changelog: helm/kind-action@v1.5.0...v1.6.0

v1.5.0

Compare Source

What's Changed

New Contributors

Full Changelog: helm/kind-action@v1...v1.5.0

iter8-tools/iter8 (iter8-tools/iter8)

v0.16.6: Version 0.16.6 of Iter8

Compare Source

What’s Changed

v0.16.5: Version 0.16.5 of Iter8

Compare Source

What’s Changed

  • #​1609: Remove exp from report for notify template
  • #​1608: Fix Slack payload template

v0.16.4: Version 0.16.4 of Iter8

Compare Source

What’s Changed

v0.16.3: Version 0.16.3 of Iter8

Compare Source

What’s Changed

v0.16.2: Version 0.16.2 of Iter8

Compare Source

What’s Changed

  • #​1602: Change name of abn Grafana
  • #​1601: Fix title
  • #​1597: Fix readiness test with namespace
  • #​1596: Add namespace to other iter8 commands in workflow tests
  • #​1595: Add longer readiness check

v0.16.1: Version 0.16.1 of Iter8

Compare Source

What’s Changed

  • #​1593: Bump versions and add verifyuserexperience workflow
  • #​1594: Bump version of iter8 chart
  • #​1590: Update charts for v0.16

v0.16.0: Version 0.16.0 of Iter8

Compare Source

What’s Changed

  • #​1565: HTTP and gRPC reports using Grafana and removal of extraneous parts

v0.15.8: Version 0.15.8 of Iter8

Compare Source

What’s Changed

v0.15.7: Version 0.15.7 of Iter8

Compare Source

What’s Changed

v0.15.6: Version 0.15.6 of Iter8

Compare Source

What’s Changed

  • #​1585: Add Grafana dashboards
  • #​1578: Add http payload and http/grpc multiple tests to workflow
  • #​1574: support deployment; template renaming

🐛 Bug Fixes

v0.15.5: Version 0.15.5 of Iter8

Compare Source

What’s Changed

  • #​1560: update routing charts to include kserve in addition to kserve-modelmesh

v0.15.4: Version 0.15.4 of Iter8

Compare Source

What’s Changed

v0.15.3: Version 0.15.3 of Iter8

Compare Source

What’s Changed

v0.15.2: Version 0.15.2 of Iter8

Compare Source

What’s Changed

v0.15.1: Version 0.15.1 of Iter8

Compare Source

What’s Changed

  • #​1543: update tests and chart images to v0.15

v0.15.0: Version 0.15.0 of Iter8

Compare Source

What’s Changed

v0.14.10: Version 0.14.10 of Iter8

Compare Source

What’s Changed

🚀 Features

v0.14.9

Compare Source

v0.14.8

Compare Source

v0.14.7: Version 0.14.7 of Iter8

Compare Source

What’s Changed

v0.14.6: Version 0.14.6 of Iter8

Compare Source

What’s Changed

  • #​1472: Update contributing and add link and spell check workflows

v0.14.5: Version 0.14.5 of Iter8

Compare Source

What’s Changed

v0.14.4: Version 0.14.4 of Iter8

Compare Source

What’s Changed

  • #​1470: Revert Dockerfile to use binaries

v0.14.3: Version 0.14.3 of Iter8

Compare Source

What’s Changed

v0.14.2: Version 0.14.2 of Iter8

Compare Source

What’s Changed

v0.14.1: Version 0.14.1 of Iter8

Compare Source

What’s Changed

v0.14.0: Version 0.14.0 of Iter8

Compare Source

What’s Changed

v0.13.18: Version 0.13.18 of Iter8

Compare Source

What’s Changed

  • #​1461: Update charts
  • #​1463: Bump github.com/docker/distribution from 2.8.1+incompatible to 2.8.2+incompatible
marocchino/sticky-pull-request-comment (marocchino/sticky-pull-request-comment)

v2.8.0

Compare Source

  • Add skip_unchanged input
  • Update deps

v2.7.0

Compare Source

Update deps.
Add two output.

  • previous_comment_id: "ID of previous comment, if found"
  • created_comment_id: "ID of newly created comment, if any"

v2.6.2

Compare Source

Reverted changes in version 2.6. As a result, the base_url has been removed.

v2.6.1

Compare Source

Change base_url default to ${{ env.GITHUB_API_URL }}

v2.6.0

Compare Source

v2.5.0

Compare Source

  • Update deps
  • Add only_update option.
  • Add owner option.

v2.4.0

Compare Source

  • Update deps
  • Add only_create option.

v2.3.1

Compare Source

  • Update deps
  • Change ignore empty default from true to false (This change will fix bug delete or hide comment not works)

v2.3.0

Compare Source

  • Support glob path
  • Add follow_symbolic_links for path
  • Add ignore_empty for skip empty body
  • Update README for new output syntax

v2.2.1: Update deps

Compare Source

  • Use node 16
  • Update npm deps
ossf/scorecard-action (ossf/scorecard-action)

v2.2.0

Compare Source

What's Changed

Scorecard Result Viewer

Thanks to contributions from @​cynthia-sg and @​tegioz at CLOMonitor, there is a new Scorecard Result visualization page at https://securityscorecards.dev/viewer/?uri=<project-url>.

As an example, you can see our own score visualized here
Checkout our README to learn how to link your README badge to the new visualization page.

Publishing Results

This release contains two fixes which will improve the user experience when publish_results is true

Docs

New Contributors

Full Changelog: ossf/scorecard-action@v2.1.3...v2.2.0

v2.1.3

Compare Source

What's Changed

Bug Fixes
  • Invalid SARIF files from a bug in scorecard
  • Vulnerabilities check crashes if a vulnerable dependency is found via OSVScanner
  • Scorecard action not reporting binary artifacts in the repo

Full Scorecard Changelog: ossf/scorecard@v4.10.2...v4.10.5

Full Changelog: ossf/scorecard-action@v2.1.2...v2.1.3

v2.1.2

Compare Source

What's Changed

Fixes

Full Changelog: ossf/scorecard-action@v2.1.1...v2.1.2

v2.1.1

Compare Source

Scorecard version

This release use Scorecard's v4.10.1

Full Changelog: ossf/scorecard-action@v2.1.0...v2.1.1

v2.1.0

Compare Source

What's Changed

Scorecard version

This release uses scorecard v4.10.0.

Improvements
Documentation

New Contributors

Full Changelog: ossf/scorecard-action@v2.0.6...v2.1.0

oxsecurity/megalinter (oxsecurity/megalinter)

v6.22.2

Compare Source

  • Core

    • Fix failure of AzureCommentReporter when there is no pull request found in ENV vars
    • Fix HTML comment appearing in Azure Pull Request mail notifications
  • Linter versions upgrades


Configuration

📅 Schedule: Branch creation - "before 4am on the first day of the month" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@github-actions
Copy link

github-actions bot commented Sep 1, 2023

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 11 0 0.29s
✅ EDITORCONFIG editorconfig-checker 13 0 0.1s
✅ PROTOBUF protolint 2 0 0.2s
✅ REPOSITORY checkov yes no 13.96s
✅ REPOSITORY dustilock yes no 0.03s
✅ REPOSITORY gitleaks yes no 0.31s
✅ REPOSITORY git_diff yes no 0.01s
✅ REPOSITORY secretlint yes no 0.98s
✅ REPOSITORY syft yes no 0.39s
✅ REPOSITORY trivy yes no 11.56s
✅ YAML prettier 11 0 0.96s
✅ YAML v8r 11 0 5.66s
✅ YAML yamllint 11 0 0.4s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from 6fc2a0a to 5e2feee Compare September 1, 2023 12:33
@renovate
Copy link
Contributor Author

renovate bot commented Sep 1, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

@github-actions
Copy link

github-actions bot commented Sep 1, 2023

Code Coverage

Package Line Rate Branch Rate Health
Vfps 93% 60%
Vfps.Tests 99% 100%
Summary 94% (444 / 471) 66% (33 / 50)

Minimum allowed line rate is 60%


ghz run statistics

Summary:
  Count:	5000
  Total:	9.98 s
  Slowest:	622.01 ms
  Fastest:	16.61 ms
  Average:	96.30 ms
  Requests/sec:	501.10

Response time histogram:
  16.608  [1]    |
  77.148  [1097] |∎∎∎∎∎∎∎∎∎∎∎∎
  137.688 [3731] |∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎∎
  198.228 [117]  |∎
  258.768 [4]    |
  319.308 [0]    |
  379.848 [0]    |
  440.388 [0]    |
  500.928 [0]    |
  561.468 [6]    |
  622.008 [44]   |

Latency distribution:
  10 % in 64.75 ms 
  25 % in 79.93 ms 
  50 % in 91.44 ms 
  75 % in 102.97 ms 
  90 % in 117.99 ms 
  95 % in 128.90 ms 
  99 % in 205.66 ms 

Status code distribution:
  [OK]   5000 responses   

iter8 report

Experiment summary:
*******************

  Experiment completed: true
  No task failures: true
  Total number of tasks: 6
  Number of completed tasks: 6
  Number of completed loops: 1

Whether or not service level objectives (SLOs) are satisfied:
*************************************************************

  SLO Conditions                 | Satisfied
  --------------                 | ---------
  grpc/error-rate <= 0           | true
  grpc/latency/mean (msec) <= 50 | true
  grpc/latency/p99 (msec) <= 100 | true
  

Latest observed values for metrics:
***********************************

  Metric                   | value
  -------                  | -----
  grpc/error-count         | 0.00
  grpc/error-rate          | 0.00
  grpc/latency/mean (msec) | 32.29
  grpc/latency/p99 (msec)  | 72.00
  grpc/request-count       | 50000.00
  

@chgl chgl merged commit 5f51f70 into master Sep 1, 2023
13 checks passed
@miracum-bot miracum-bot mentioned this pull request Sep 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant