Repository navigation
Bump the github-actions-updates group with 2 updates - #35
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions-updates group with 2 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) and [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows). Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.2.1 to 2.4.0 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](lfreleng-actions/github2gerrit-action@eda09b8...df12d7f) Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.7.0 to 0.9.0 - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@bdcf7d8...76ea523) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #35 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/distribution/+/147957 |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml. Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.2.1 to 2.4.0 ## Release notes Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases. v2.4.0 ✨ New Features ✨ Feat: Sweep approved fork PRs on a schedule @ModeSevenIndustrialSolutions (#455) Links Submit bugs/feature requests v2.3.0 ✨ New Features ✨ Feat: Fan out bulk sweeps and skip transferred forks @ModeSevenIndustrialSolutions (#454) Links Submit bugs/feature requests v2.2.2 🐛 Bug Fixes 🐛 Fix: Settle one effective Gerrit host in derivation @ModeSevenIndustrialSolutions (#446) Fix: Give the Gerrit port its own precedence @ModeSevenIndustrialSolutions (#449) 🔧 Maintenance 🔧 Chore: Bump astral-sh/setup-uv from 10.0.1 to 10.1.0 @dependabot[bot] (#450) Chore: Bump ruff from 0.16.6 to 0.16.7 @dependabot[bot] (#451) Build: Sync mypy hook pins from uv.lock instead of testing them @ModeSevenIndustrialSolutions (#447) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#453) 🎓 Code Quality 🎓 Test: Assert the whole no-change message, not the host @ModeSevenIndustrialSolutions (#452) Links Submit bugs/feature requests ## Commits df12d7f Merge pull request #455 from modeseven-lfreleng-actions/feat/scheduled-sweep 56d3246 Feat: Sweep approved fork PRs on a schedule 2fbfa39 Test: Share the reusable workflow test harness a483c25 Merge pull request #454 from modeseven-lfreleng-actions/feat/sweep-fan-out-id edb2d7b Fix: Address Copilot review feedback bced4e6 Feat: Fan bulk dispatch out to a job per PR 48bbc46 Feat: Record fork transfers so sweeps skip them 5f84610 Merge pull request #453 from lfreleng-actions/pre-commit-ci-update-config e6edf55 Chore: pre-commit autoupdate 047f4cd Merge pull request #449 from modeseven-lfreleng-actions/fix/gerrit-port-prece Additional commits viewable in compare view Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.7.0 to 0.9.0 ## Release notes Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases. v0.9.0 ✨ New Features ✨ Feat: Test lane steps per PR and add Python CLM @ModeSevenIndustrialSolutions (#113) 🔧 Maintenance 🔧 CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.1 to 0.5.2 @dependabot[bot] (#108) CI(actions): Bump github/codeql-action/analyze from 4.37.9 to 4.38.0 @dependabot[bot] (#109) CI(actions): Bump lfreleng-actions/go-test-action from 0.1.0 to 0.1.1 @dependabot[bot] (#110) CI(actions): Bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0 @dependabot[bot] (#111) CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0 @dependabot[bot] (#112) Links Submit bugs/feature requests v0.8.0 ✨ New Features ✨ Feat: Settle the migration-audit input regressions @ModeSevenIndustrialSolutions (#99) 🔧 Maintenance 🔧 CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#101) CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#102) CI(actions): Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#103) CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.0 to 0.5.1 @dependabot[bot] (#104) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#80) Chore: Default Maven to 3.9.11 on the build lanes @ModeSevenIndustrialSolutions (#106) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#107) 🎓 Code Quality 🎓 CI: Adopt the self-repository reference syntax @ModeSevenIndustrialSolutions (#105) Links Submit bugs/feature requests ## Commits 76ea523 Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness 3bd6689 Docs: Name Python among scan_targets exceptions ab0f5c6 Feat: Add a python build_type to the CLM lane 4c88685 Test: Run the lanes' validation steps on every PR 37d4e67 Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu 430b1ba Merge pull request #111 from lfreleng-actions/dependabot/github_actions/githu bb7e758 Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel 95377d3 Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu a12865c Merge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel 9d6aa08 CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0 Additional commits viewable in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: I7ce149527c6e115ed28f69cc5ab78c7dbff8f32b GitHub-PR: #35 GitHub-Hash: 0dfc094c1fb2060e Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml.
Updates
lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yamlfrom 2.2.1 to 2.4.0Release notes
Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.
Commits
df12d7fMerge pull request #455 from modeseven-lfreleng-actions/feat/scheduled-sweep56d3246Feat: Sweep approved fork PRs on a schedule2fbfa39Test: Share the reusable workflow test harnessa483c25Merge pull request #454 from modeseven-lfreleng-actions/feat/sweep-fan-out-id...edb2d7bFix: Address Copilot review feedbackbced4e6Feat: Fan bulk dispatch out to a job per PR48bbc46Feat: Record fork transfers so sweeps skip them5f84610Merge pull request #453 from lfreleng-actions/pre-commit-ci-update-confige6edf55Chore: pre-commit autoupdate047f4cdMerge pull request #449 from modeseven-lfreleng-actions/fix/gerrit-port-prece...Updates
lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yamlfrom 0.7.0 to 0.9.0Release notes
Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.
Commits
76ea523Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness3bd6689Docs: Name Python among scan_targets exceptionsab0f5c6Feat: Add a python build_type to the CLM lane4c88685Test: Run the lanes' validation steps on every PR37d4e67Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu...430b1baMerge pull request #111 from lfreleng-actions/dependabot/github_actions/githu...bb7e758Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel...95377d3Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu...a12865cMerge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel...9d6aa08CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions