Repository navigation
Bump the github-actions-updates group with 6 updates - #28
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions-updates group with 6 updates: | Package | From | To | | --- | --- | --- | | [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) | `1.4.4` | `2.0.0` | | [lfreleng-actions/gerrit-review-action](https://github.com/lfreleng-actions/gerrit-review-action) | `1.1.2` | `1.1.3` | | [lfreleng-actions/checkout-gerrit-change-action](https://github.com/lfreleng-actions/checkout-gerrit-change-action) | `1.0.2` | `1.1.0` | | [lfreleng-actions/path-check-action](https://github.com/lfreleng-actions/path-check-action) | `0.2.1` | `0.2.2` | | [1password/load-secrets-action](https://github.com/1password/load-secrets-action) | `5.0.0` | `5.0.1` | | [lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml](https://github.com/lfit/releng-reusable-workflows) | `0.10.1` | `0.10.2` | Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.4 to 2.0.0 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](lfreleng-actions/github2gerrit-action@e06d6a2...f44ab26) Updates `lfreleng-actions/gerrit-review-action` from 1.1.2 to 1.1.3 - [Release notes](https://github.com/lfreleng-actions/gerrit-review-action/releases) - [Commits](lfreleng-actions/gerrit-review-action@a1c036a...1e3eae7) Updates `lfreleng-actions/checkout-gerrit-change-action` from 1.0.2 to 1.1.0 - [Release notes](https://github.com/lfreleng-actions/checkout-gerrit-change-action/releases) - [Commits](lfreleng-actions/checkout-gerrit-change-action@f87b90a...298f53b) Updates `lfreleng-actions/path-check-action` from 0.2.1 to 0.2.2 - [Release notes](https://github.com/lfreleng-actions/path-check-action/releases) - [Commits](lfreleng-actions/path-check-action@b51f099...fae378d) Updates `1password/load-secrets-action` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/1password/load-secrets-action/releases) - [Commits](1Password/load-secrets-action@e544b78...70062d7) Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.10.1 to 0.10.2 - [Release notes](https://github.com/lfit/releng-reusable-workflows/releases) - [Commits](lfit/releng-reusable-workflows@f7aae21...dd7e7f1) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: lfreleng-actions/gerrit-review-action dependency-version: 1.1.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: lfreleng-actions/checkout-gerrit-change-action dependency-version: 1.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/path-check-action dependency-version: 0.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: 1password/load-secrets-action dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml dependency-version: 0.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #28 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/models/+/147195 |
Bumps the github-actions-updates group with 6 updates: | Package | From | To | | --- | --- | --- | | lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml | `1.4.4` | `2.0.0` | | lfreleng-actions/gerrit-review-action | `1.1.2` | `1.1.3` | | lfreleng-actions/checkout-gerrit-change-action | `1.0.2` | `1.1.0` | | lfreleng-actions/path-check-action | `0.2.1` | `0.2.2` | | 1password/load-secrets-action | `5.0.0` | `5.0.1` | | lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml | `0.10.1` | `0.10.2` | Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.4 to 2.0.0 ## Release notes Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases. v2.0.0 💥 Breaking Change 💥 Fix!: Harden fork pull request handling @ModeSevenIndustrialSolutions (#384) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#371) Chore: Bump astral-sh/setup-uv from 9.0.0 to 10.0.1 @dependabot[bot] (#373) Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.0.4 to 0.0.5 @dependabot[bot] (#374) Chore: Bump ruff from 0.16.2 to 0.16.3 @dependabot[bot] (#375) Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#376) Chore: Bump mypy from 2.3.0 to 2.3.1 @dependabot[bot] (#377) Chore: Bump hatchling from 1.31.0 to 1.32.0 @dependabot[bot] (#378) Chore: Bump lfreleng-actions/pypi-publish-action from 0.1.9 to 0.2.0 @dependabot[bot] (#379) Links Submit bugs/feature requests v1.4.5 🐛 Bug Fixes 🐛 Fix: Silence a false-positive S310 in gitreview @ModeSevenIndustrialSolutions (#357) 🔧 Maintenance 🔧 Chore: Disable pre-commit.ci autofix PRs @ModeSevenIndustrialSolutions (#352) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#351) Chore: Bump astral-sh/setup-uv from 8.3.2 to 9.0.0 @dependabot[bot] (#353) Chore: Bump ruff from 0.15.22 to 0.16.0 @dependabot[bot] (#354) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.8.1 to 0.9.1 @dependabot[bot] (#355) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#356) Chore: Bump cryptography from 49.0.0 to 50.0.0 @dependabot[bot] (#358) Refactor: Call the shared cache-clearing workflow @ModeSevenIndustrialSolutions (#359) Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test-release.yaml from 0.2.0 to 0.3.0 @dependabot[bot] (#360) Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test.yaml from 0.2.0 to 0.3.0 @dependabot[bot] (#361) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.0 @dependabot[bot] (#362) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#363) Chore: Bump ruff from 0.16.0 to 0.16.1 @dependabot[bot] (#364) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#365) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#366) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#367) Chore: Bump typer from 0.27.0 to 0.27.1 @dependabot[bot] (#368) Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.0.3 to 0.0.4 @dependabot[bot] (#369) Chore: Bump ruff from 0.16.1 to 0.16.2 @dependabot[bot] (#370) ... (truncated) ## Commits f44ab26 Merge pull request #384 from modeseven-lfreleng-actions/fix/fork-pr-hardening 5f9b6ff Fix: Address Copilot review feedback 1e6e3ab Fix: Ignore fork-supplied .gitreview for Gerrit target 1a4577e Fix!: Remove redundant repository checkout steps 2b9aa7a Merge pull request #379 from lfreleng-actions/dependabot/github_actions/lfrel 6b85d70 Merge pull request #378 from lfreleng-actions/dependabot/uv/hatchling-1.32.0 68f8bb0 Merge pull request #377 from lfreleng-actions/dependabot/uv/mypy-2.3.1 77ffea0 Merge pull request #376 from lfreleng-actions/dependabot/github_actions/step- 185ac7f Merge pull request #375 from lfreleng-actions/dependabot/uv/ruff-0.16.3 e2bdd7a Merge pull request #374 from lfreleng-actions/dependabot/github_actions/lfrel Additional commits viewable in compare view Updates `lfreleng-actions/gerrit-review-action` from 1.1.2 to 1.1.3 ## Release notes Sourced from lfreleng-actions/gerrit-review-action's releases. v1.1.3 🐛 Bug Fixes 🐛 Fix: resolve zizmor auditor persona findings @ModeSevenIndustrialSolutions (#125) 🔧 Maintenance 🔧 Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#117) Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#118) Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#119) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.4 @dependabot[bot] (#120) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#121) Chore: Bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @dependabot[bot] (#123) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#124) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#126) Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#127) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#128) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#129) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#130) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#131) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.4 to 1.1.0 @dependabot[bot] (#132) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#133) Chore: Disable pre-commit.ci autofix PRs @ModeSevenIndustrialSolutions (#134) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.8.1 to 0.9.1 @dependabot[bot] (#135) Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#136) Chore: Bump lfreleng-actions/tag-validate-action from 1.1.0 to 1.1.2 @dependabot[bot] (#137) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#139) Refactor: Call the shared release workflow @ModeSevenIndustrialSolutions (#138) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.0 @dependabot[bot] (#140) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#141) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#142) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#143) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#144) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#145) Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#146) 🎓 Code Quality 🎓 CI: Add OpenSSF Scorecard workflow @ModeSevenIndustrialSolutions (#122) Links Submit bugs/feature requests ## Commits 1e3eae7 Merge pull request #146 from lfreleng-actions/dependabot/github_actions/step- cf518f9 Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 c0cf518 Merge pull request #145 from lfreleng-actions/pre-commit-ci-update-config 4ecb804 Chore: pre-commit autoupdate 9658839 Merge pull request #144 from lfreleng-actions/dependabot/github_actions/step- bd38f6a Merge pull request #143 from lfreleng-actions/dependabot/github_actions/lfit/ ee2e5ae Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 e82f354 Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc 364f7f6 Merge pull request #142 from lfreleng-actions/pre-commit-ci-update-config 31fb5bd Merge pull request #141 from lfreleng-actions/dependabot/github_actions/relea Additional commits viewable in compare view Updates `lfreleng-actions/checkout-gerrit-change-action` from 1.0.2 to 1.1.0 ## Release notes Sourced from lfreleng-actions/checkout-gerrit-change-action's releases. v1.1.0 ✨ New Features ✨ Feat: Warn on mismatched Gerrit checkout target @ModeSevenIndustrialSolutions (#136) 🐛 Bug Fixes 🐛 Fix: resolve Zizmor template-injection findings @ModeSevenIndustrialSolutions (#108) Fix: resolve zizmor auditor persona findings @ModeSevenIndustrialSolutions (#116) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#107) Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#109) Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#110) Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#111) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#112) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.4 @dependabot[bot] (#114) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#115) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#117) Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#118) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#119) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#120) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#121) Chore: Disable pre-commit.ci autofix PRs @ModeSevenIndustrialSolutions (#122) Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#123) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.4 to 1.1.2 @dependabot[bot] (#124) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.9.1 @dependabot[bot] (#125) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#126) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#128) Refactor: Call the shared release workflow @ModeSevenIndustrialSolutions (#127) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#131) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#132) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.1 @dependabot[bot] (#133) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#134) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#135) 🎓 Code Quality 🎓 CI: Add OpenSSF Scorecard workflow @ModeSevenIndustrialSolutions (#113) Links Submit bugs/feature requests ## Commits 298f53b Merge pull request #136 from modeseven-lfreleng-actions/feat/warn-checkout-ta 0db7d1f Merge pull request #135 from lfreleng-actions/pre-commit-ci-update-config 6211c33 Feat: Warn on mismatched Gerrit checkout target 72a5a13 Chore: pre-commit autoupdate bcd8c7e Merge pull request #134 from lfreleng-actions/dependabot/github_actions/step- 10c8d49 Merge pull request #133 from lfreleng-actions/dependabot/github_actions/lfit/ c6220f6 Merge pull request #132 from lfreleng-actions/pre-commit-ci-update-config b574171 Merge pull request #131 from lfreleng-actions/dependabot/github_actions/relea 1080b60 Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 fcc1514 Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc Additional commits viewable in compare view Updates `lfreleng-actions/path-check-action` from 0.2.1 to 0.2.2 ## Release notes Sourced from lfreleng-actions/path-check-action's releases. v0.2.2 🐛 Bug Fixes 🐛 Fix: resolve zizmor auditor persona findings @ModeSevenIndustrialSolutions (#118) Fix: Env-mediate expressions in run blocks @ModeSevenIndustrialSolutions (#126) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#108) Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#109) Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#110) Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#111) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.3 @dependabot[bot] (#112) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#113) Chore: Bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @dependabot[bot] (#115) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.3 to 1.0.4 @dependabot[bot] (#116) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#117) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#119) Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#120) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#121) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#122) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.8.0 @dependabot[bot] (#123) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#124) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#127) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.4 to 1.1.2 @dependabot[bot] (#128) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.8.0 to 0.9.1 @dependabot[bot] (#129) Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#130) Chore: Disable pre-commit.ci autofix PRs @ModeSevenIndustrialSolutions (#125) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#132) Refactor: Call the shared release workflow @ModeSevenIndustrialSolutions (#131) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#133) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#135) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.1 @dependabot[bot] (#136) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#137) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#138) 🎓 Code Quality 🎓 CI: Add OpenSSF Scorecard workflow @ModeSevenIndustrialSolutions (#114) Links Submit bugs/feature requests ## Commits fae378d Merge pull request #138 from lfreleng-actions/pre-commit-ci-update-config 3d6cb18 Chore: pre-commit autoupdate c3e031f Merge pull request #137 from lfreleng-actions/dependabot/github_actions/step- 9a3105b Merge pull request #136 from lfreleng-actions/dependabot/github_actions/lfit/ fefa8a7 Merge pull request #135 from lfreleng-actions/pre-commit-ci-update-config 357d92a Merge pull request #133 from lfreleng-actions/dependabot/github_actions/relea e28cc51 Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 f1614eb Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc 3ca1fb2 Chore: pre-commit autoupdate 7066313 Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 Additional commits viewable in compare view Updates `1password/load-secrets-action` from 5.0.0 to 5.0.1 ## Release notes Sourced from 1password/load-secrets-action's releases. v5.0.1 What's Changed Fixes Correct the authentication error message. It previously listed only the CLI methods (OP_SERVICE_ACCOUNT_TOKEN, or OP_CONNECT_HOST + OP_CONNECT_TOKEN), which misled anyone who meant to use Workload Identity but had one of those variables missing or misspelled. It now lists OP_WORKLOAD_ID + OP_ENVIRONMENT_ID + OP_INTEGRATION_KEY as a third valid option. (#187) Dependencies Bump @1password/sdk from 0.5.0-beta.1 to the stable 0.5.0, and rebuild dist/ (including core_bg.wasm). (#187) Update the baked-in beta CLI fallback version: 2.38.1-beta.02 → 2.39.0-beta.02. Security Harden CI: add the StepSecurity harden-runner and pin GitHub Actions to commit SHAs across the E2E and fallback-version workflows, and restrict workflow permissions. (#182) Full Changelog: 1Password/load-secrets-action@v5.0.0...v5.0.1 ## Commits 70062d7 Merge pull request #190 from 1Password/release/v5.0.1 6f5bd0e Prepare Release 5.0.1 846abe0 Merge pull request #187 from 1Password/jill/bump-to-stable-sdk 557708f Bump sdk type 2d8a25c Merge pull request #182 from 1Password/chore/GHA-211518-stepsecurity-remediation 631992c Apply GitHub Actions security best practices See full diff in compare view Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.10.1 to 0.10.2 ## Release notes Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases. v0.10.2 🔧 Maintenance 🔧 Chore: Bump lfreleng-actions/change-isolation-action from 0.2.0 to 0.2.1 @dependabot[bot] (#835) Chore: Bump release-drafter/release-drafter/autolabeler from 7.6.0 to 7.7.0 @dependabot[bot] (#833) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#838) Chore: Bump actions/setup-java from 5.6.0 to 5.7.0 @dependabot[bot] (#837) Chore: Bump lfreleng-actions/gradle-build-action from 0.5.0 to 0.6.0 @dependabot[bot] (#841) Chore: Bump 1password/load-secrets-action from 4.1.1 to 5.0.0 @dependabot[bot] (#834) Chore: pre-commit linting updates @pre-commit-ci[bot] (#842) Chore: Bump lfreleng-actions/credential-load-action from 2.0.2 to 2.0.3 @dependabot[bot] (#845) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/gerrit-compose-required-tox-verify.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#847) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-sonatype-lifecycle.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#846) Chore: Bump github/codeql-action/init from 4.37.3 to 4.37.6 @dependabot[bot] (#848) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#849) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-jjb-verify.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#851) Chore: Bump lfreleng-actions/maven-build-action from 0.3.0 to 0.3.1 @dependabot[bot] (#850) Chore: Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 @dependabot[bot] (#852) Chore: Bump github/codeql-action/analyze from 4.37.3 to 4.37.6 @dependabot[bot] (#853) Chore: Bump github/codeql-action/analyze from 4.37.6 to 4.37.7 @dependabot[bot] (#857) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-verify-github-actions.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#856) Chore: Bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 @dependabot[bot] (#859) Chore: Bump dorny/paths-filter from 4.0.2 to 4.0.3 @dependabot[bot] (#858) Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#862) Chore: pre-commit linting updates @pre-commit-ci[bot] (#864) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-packer-verify.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#860) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#861) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-repo-linting.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#863) Chore: Bump github/codeql-action/init from 4.37.6 to 4.37.7 @dependabot[bot] (#855) Links Submit bugs/feature requests ## Commits dd7e7f1 Merge pull request #855 from lfit/dependabot/github_actions/github/codeql-act e9d6817 Merge pull request #863 from lfit/dependabot/github_actions/lfit/releng-reusa 4fd29c8 Merge pull request #861 from lfit/dependabot/github_actions/lfit/releng-reusa 6825f50 Merge pull request #860 from lfit/dependabot/github_actions/lfit/releng-reusa ace7e08 Merge pull request #864 from lfit/pre-commit-ci-update-config 7b94d45 Merge pull request #862 from lfit/dependabot/github_actions/step-security/har 7586482 Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf 9adaeb9 Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf a1948dc Merge pull request #858 from lfit/dependabot/github_actions/dorny/paths-filte 0f796b7 Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf Additional commits viewable in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: I9b29a5e1966d07253d5e5020db88dd81abc0e02b GitHub-PR: #28 GitHub-Hash: 104f0efe69b48c3c Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 6 updates:
1.4.42.0.01.1.21.1.31.0.21.1.00.2.10.2.25.0.05.0.10.10.10.10.2Updates
lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yamlfrom 1.4.4 to 2.0.0Release notes
Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.
... (truncated)
Commits
f44ab26Merge pull request #384 from modeseven-lfreleng-actions/fix/fork-pr-hardening5f9b6ffFix: Address Copilot review feedback1e6e3abFix: Ignore fork-supplied .gitreview for Gerrit target1a4577eFix!: Remove redundant repository checkout steps2b9aa7aMerge pull request #379 from lfreleng-actions/dependabot/github_actions/lfrel...6b85d70Merge pull request #378 from lfreleng-actions/dependabot/uv/hatchling-1.32.068f8bb0Merge pull request #377 from lfreleng-actions/dependabot/uv/mypy-2.3.177ffea0Merge pull request #376 from lfreleng-actions/dependabot/github_actions/step-...185ac7fMerge pull request #375 from lfreleng-actions/dependabot/uv/ruff-0.16.3e2bdd7aMerge pull request #374 from lfreleng-actions/dependabot/github_actions/lfrel...Updates
lfreleng-actions/gerrit-review-actionfrom 1.1.2 to 1.1.3Release notes
Sourced from lfreleng-actions/gerrit-review-action's releases.
Commits
1e3eae7Merge pull request #146 from lfreleng-actions/dependabot/github_actions/step-...cf518f9Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0c0cf518Merge pull request #145 from lfreleng-actions/pre-commit-ci-update-config4ecb804Chore: pre-commit autoupdate9658839Merge pull request #144 from lfreleng-actions/dependabot/github_actions/step-...bd38f6aMerge pull request #143 from lfreleng-actions/dependabot/github_actions/lfit/...ee2e5aeChore: Bump step-security/harden-runner from 2.20.0 to 2.20.1e82f354Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc...364f7f6Merge pull request #142 from lfreleng-actions/pre-commit-ci-update-config31fb5bdMerge pull request #141 from lfreleng-actions/dependabot/github_actions/relea...Updates
lfreleng-actions/checkout-gerrit-change-actionfrom 1.0.2 to 1.1.0Release notes
Sourced from lfreleng-actions/checkout-gerrit-change-action's releases.
Commits
298f53bMerge pull request #136 from modeseven-lfreleng-actions/feat/warn-checkout-ta...0db7d1fMerge pull request #135 from lfreleng-actions/pre-commit-ci-update-config6211c33Feat: Warn on mismatched Gerrit checkout target72a5a13Chore: pre-commit autoupdatebcd8c7eMerge pull request #134 from lfreleng-actions/dependabot/github_actions/step-...10c8d49Merge pull request #133 from lfreleng-actions/dependabot/github_actions/lfit/...c6220f6Merge pull request #132 from lfreleng-actions/pre-commit-ci-update-configb574171Merge pull request #131 from lfreleng-actions/dependabot/github_actions/relea...1080b60Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1fcc1514Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc...Updates
lfreleng-actions/path-check-actionfrom 0.2.1 to 0.2.2Release notes
Sourced from lfreleng-actions/path-check-action's releases.
Commits
fae378dMerge pull request #138 from lfreleng-actions/pre-commit-ci-update-config3d6cb18Chore: pre-commit autoupdatec3e031fMerge pull request #137 from lfreleng-actions/dependabot/github_actions/step-...9a3105bMerge pull request #136 from lfreleng-actions/dependabot/github_actions/lfit/...fefa8a7Merge pull request #135 from lfreleng-actions/pre-commit-ci-update-config357d92aMerge pull request #133 from lfreleng-actions/dependabot/github_actions/relea...e28cc51Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1f1614ebChore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc...3ca1fb2Chore: pre-commit autoupdate7066313Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0Updates
1password/load-secrets-actionfrom 5.0.0 to 5.0.1Release notes
Sourced from 1password/load-secrets-action's releases.
Commits
70062d7Merge pull request #190 from 1Password/release/v5.0.16f5bd0ePrepare Release 5.0.1846abe0Merge pull request #187 from 1Password/jill/bump-to-stable-sdk557708fBump sdk type2d8a25cMerge pull request #182 from 1Password/chore/GHA-211518-stepsecurity-remediation631992cApply GitHub Actions security best practicesUpdates
lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yamlfrom 0.10.1 to 0.10.2Release notes
Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases.
Commits
dd7e7f1Merge pull request #855 from lfit/dependabot/github_actions/github/codeql-act...e9d6817Merge pull request #863 from lfit/dependabot/github_actions/lfit/releng-reusa...4fd29c8Merge pull request #861 from lfit/dependabot/github_actions/lfit/releng-reusa...6825f50Merge pull request #860 from lfit/dependabot/github_actions/lfit/releng-reusa...ace7e08Merge pull request #864 from lfit/pre-commit-ci-update-config7b94d45Merge pull request #862 from lfit/dependabot/github_actions/step-security/har...7586482Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf...9adaeb9Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf...a1948dcMerge pull request #858 from lfit/dependabot/github_actions/dorny/paths-filte...0f796b7Merge branch 'main' into dependabot/github_actions/lfit/releng-reusable-workf...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions