-
Notifications
You must be signed in to change notification settings - Fork 0
Doc-only: true Bump the gha-versions group across 1 directory with 8 updates #140
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: release/2.6
Are you sure you want to change the base?
Doc-only: true Bump the gha-versions group across 1 directory with 8 updates #140
Conversation
Bump the gha-versions group across 1 directory with 8 updates Bumps the gha-versions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `5` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `5` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `6` | | [codespell-project/actions-codespell](https://github.com/codespell-project/actions-codespell) | `fad9339798e1ee3fe979ae0a022c931786a408b8` | `8d1a4b1bd974b8082be0842c2e7e57c8bf6b9b63` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.3` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.8` | `4.31.0` | | [dorny/test-reporter](https://github.com/dorny/test-reporter) | `1` | `2` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.29.0` | `0.33.1` | Updates `actions/checkout` from 4 to 5 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v4...v5) Updates `actions/upload-artifact` from 4 to 5 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v5) Updates `actions/setup-python` from 5 to 6 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v6) Updates `codespell-project/actions-codespell` from fad9339798e1ee3fe979ae0a022c931786a408b8 to 8d1a4b1bd974b8082be0842c2e7e57c8bf6b9b63 - [Release notes](https://github.com/codespell-project/actions-codespell/releases) - [Commits](codespell-project/actions-codespell@fad9339...8d1a4b1) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@62b2cac...4eaacf0) Updates `github/codeql-action` from 3.28.8 to 4.31.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@dd74661...4e94bd1) Updates `dorny/test-reporter` from 1 to 2 - [Release notes](https://github.com/dorny/test-reporter/releases) - [Changelog](https://github.com/dorny/test-reporter/blob/main/CHANGELOG.md) - [Commits](dorny/test-reporter@v1...v2) Updates `aquasecurity/trivy-action` from 0.29.0 to 0.33.1 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@18f2510...b6643a2) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-versions - dependency-name: actions/upload-artifact dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-versions - dependency-name: actions/setup-python dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-versions - dependency-name: codespell-project/actions-codespell dependency-version: 8d1a4b1bd974b8082be0842c2e7e57c8bf6b9b63 dependency-type: direct:production dependency-group: gha-versions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gha-versions - dependency-name: github/codeql-action dependency-version: 4.31.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-versions - dependency-name: dorny/test-reporter dependency-version: '2' dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-versions - dependency-name: aquasecurity/trivy-action dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gha-versions ... Signed-off-by: dependabot[bot] <[email protected]>
AssigneesThe following users could not be added as assignees: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Scorecard found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
Bumps the gha-versions group with 8 updates in the / directory:
454556fad9339798e1ee3fe979ae0a022c931786a408b88d1a4b1bd974b8082be0842c2e7e57c8bf6b9b632.4.02.4.33.28.84.31.0120.29.00.33.1Updates
actions/checkoutfrom 4 to 5Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)Updates
actions/upload-artifactfrom 4 to 5Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.mdUpdates
actions/setup-pythonfrom 5 to 6Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
e797f83Upgrade to node 24 (#1164)3d1e2d2Revert "Enhance cache-dependency-path handling to support files outside the w...65b0712Clarify pythonLocation behavior for PyPy and GraalPy in environment variables...5b668cfBump actions/checkout from 4 to 5 (#1181)f62a0e2Change missing cache directory error to warning (#1182)9322b3cUpgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIn...fbeb884Bump form-data to fix critical vulnerabilities #182 & #183 (#1163)03bb615Bump idna from 2.9 to 3.7 in /tests/data (#843)36da51dAdd version parsing from Pipfile (#1067)3c6f142update documentation (#1156)Updates
codespell-project/actions-codespellfrom fad9339798e1ee3fe979ae0a022c931786a408b8 to 8d1a4b1bd974b8082be0842c2e7e57c8bf6b9b63Commits
8d1a4b1Bump actions/setup-python from 5 to 6 (#92)71286cbBump actions/checkout from 4 to 5 (#91)Updates
ossf/scorecard-actionfrom 2.4.0 to 2.4.3Release notes
Sourced from ossf/scorecard-action's releases.
Commits
4eaacf0bump docker to ghcr v2.4.3 (#1587)42e3a01🌱 Bump the github-actions group with 3 updates (#1585)88c07ac🌱 Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)6c690f2Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)92083b5📖 Fix recommended command to test the image in development (#1583)7975ea6🌱 Bump the docker-images group across 1 directory with 2 updates (#1...0d1a743🌱 Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)46e6e0c🌱 Bump the github-actions group with 2 updates (#1580)c3f1350🌱 Improve printing options (#1584)43e475b🌱 Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)Updates
github/codeql-actionfrom 3.28.8 to 4.31.0Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
4e94bd1Merge pull request #3235 from github/update-v4.31.0-1d36546c18f11182Update changelog for v4.31.01d36546Merge pull request #3234 from github/mbg/changelog/post-processing08ada26Add changelog entry for post-processing changeb843cbeMerge pull request #3233 from github/mbg/getOptionalEnvVar1ecd563UsegetOptionalEnvVarinwritePostProcessedFilese576807Merge pull request #3223 from github/henrymercer/bump-minimumad35676AddgetOptionalEnvVarfunctiond75645bMerge pull request #3222 from github/mbg/upload-lib/post-process710606cCheck thatoutputPathis non-emptyUpdates
dorny/test-reporterfrom 1 to 2Release notes
Sourced from dorny/test-reporter's releases.
... (truncated)
Changelog
Sourced from dorny/test-reporter's changelog.
... (truncated)
Commits
dc3a926test-reporter release v2.1.1e8e2736test-reporter release v2.1.1ec9d9d2Merge pull request #623 from 0xced/xunitv3-trxbe36461Fix code formatting in thedotnet-trx.tests.tsfile8dd7047Merge pull request #628 from dorny/chore/update_packages71814aeUpdate development dependencies4128d36Use "Unclassified" when no class name is availabled1504eaAdd test on a trx report where the className attribute of TestMethod is missing18430dbMerge pull request #615 from dboriichuk/trx-stack-trace-summaryae8bd19Add stack tracke to summaryUpdates
aquasecurity/trivy-actionfrom 0.29.0 to 0.33.1Release notes
Sourced from aquasecurity/trivy-action's releases.