From 1bc14dd470e2389c2a4a3ca47240fa67e0ab1419 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 23 Jul 2026 20:43:35 +0000 Subject: [PATCH] Bump the github-actions-updates group with 3 updates Bumps the github-actions-updates group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [1password/load-secrets-action](https://github.com/1password/load-secrets-action) and [lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml](https://github.com/lfit/releng-reusable-workflows). Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `1password/load-secrets-action` from 4.0.1 to 4.1.1 - [Release notes](https://github.com/1password/load-secrets-action/releases) - [Commits](https://github.com/1password/load-secrets-action/compare/3a12b0ab99d9cd590a3e9b5a90ea017210ed9556...eb2efd0703da22a93c467f2d1ffbb6826c11e19c) Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.7.4 to 0.9.1 - [Release notes](https://github.com/lfit/releng-reusable-workflows/releases) - [Commits](https://github.com/lfit/releng-reusable-workflows/compare/5fa62e396473e823e2bb0f45b744e94c4f842faa...973bba87aa9cc4ab43242ba9afac37d70c72f134) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: 1password/load-secrets-action dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml dependency-version: 0.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/gerrit-clm.yaml | 4 ++-- .github/workflows/open-ssf-scorecard.yaml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/gerrit-clm.yaml b/.github/workflows/gerrit-clm.yaml index a5709d809..c920630aa 100644 --- a/.github/workflows/gerrit-clm.yaml +++ b/.github/workflows/gerrit-clm.yaml @@ -153,7 +153,7 @@ jobs: # yamllint disable-line rule:line-length if: github.event_name == 'schedule' || github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && inputs.GERRIT_DISABLED == true) # yamllint disable-line rule:line-length - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # Gerrit-aware checkout for workflow_dispatch with Gerrit context - name: 'Checkout Gerrit change' @@ -189,7 +189,7 @@ jobs: - name: Load secret from 1Password if: steps.check-pom-xml.outputs.exists == 'true' - uses: 1password/load-secrets-action@3a12b0ab99d9cd590a3e9b5a90ea017210ed9556 # v4.0.1 + uses: 1password/load-secrets-action@eb2efd0703da22a93c467f2d1ffbb6826c11e19c # v4.1.1 with: export-env: true env: diff --git a/.github/workflows/open-ssf-scorecard.yaml b/.github/workflows/open-ssf-scorecard.yaml index 4311e6fce..871b8c4a9 100644 --- a/.github/workflows/open-ssf-scorecard.yaml +++ b/.github/workflows/open-ssf-scorecard.yaml @@ -39,7 +39,7 @@ jobs: openssf-scorecard: name: "OpenSSF Scorecard" # yamllint disable-line rule:line-length - uses: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml@5fa62e396473e823e2bb0f45b744e94c4f842faa # v0.7.4 + uses: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml@973bba87aa9cc4ab43242ba9afac37d70c72f134 # v0.9.1 permissions: # Needed to upload the results to code-scanning dashboard. security-events: write