Repository navigation
Bump the github-actions-updates group with 2 updates - #30
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions-updates group with 2 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) and [lfreleng-actions/sonatype-lifecycle-scan-action](https://github.com/lfreleng-actions/sonatype-lifecycle-scan-action). Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.1.0 to 2.1.1 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](lfreleng-actions/github2gerrit-action@3d548cc...bbf43f3) Updates `lfreleng-actions/sonatype-lifecycle-scan-action` from 0.2.0 to 0.2.1 - [Release notes](https://github.com/lfreleng-actions/sonatype-lifecycle-scan-action/releases) - [Commits](lfreleng-actions/sonatype-lifecycle-scan-action@f5b35cb...bfe8863) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: lfreleng-actions/sonatype-lifecycle-scan-action dependency-version: 0.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #30 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/models/+/147457 |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/sonatype-lifecycle-scan-action. Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.1.0 to 2.1.1 ## Release notes Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases. v2.1.1 🐛 Bug Fixes 🐛 Fix: Resolve open cache-isolation and config-provenance issues @ModeSevenIndustrialSolutions (#393) Fix: Derive Gerrit credentials from live inputs @ModeSevenIndustrialSolutions (#396) Fix: Stop mixing typer's click with the real one @ModeSevenIndustrialSolutions (#399) 🔧 Maintenance 🔧 Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test-release.yaml from 0.3.0 to 0.3.1 @dependabot[bot] (#401) Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test.yaml from 0.3.0 to 0.3.1 @dependabot[bot] (#402) Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.0.5 to 0.2.1 @dependabot[bot] (#403) Chore: Bump lfreleng-actions/harden-runner-block-action from 0.2.1 to 0.12.1 @dependabot[bot] (#404) Chore: Bump pygithub from 2.9.1 to 2.10.0 @dependabot[bot] (#405) Chore: Bump ruff from 0.16.3 to 0.16.4 @dependabot[bot] (#406) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#407) Chore: Replace LICENSE symlink with regular file @ModeSevenIndustrialSolutions (#400) 🎓 Code Quality 🎓 CI: Extend static analysis to the test suite @ModeSevenIndustrialSolutions (#392) CI: Grant issues read to the reusable workflows @ModeSevenIndustrialSolutions (#408) CI: Extend mypy to tests and scripts @ModeSevenIndustrialSolutions (#397) CI: Bump python-workflows to v0.4.0 @ModeSevenIndustrialSolutions (#409) Links Submit bugs/feature requests ## Commits bbf43f3 Merge pull request #399 from modeseven-lfreleng-actions/fix/typer-click-split 2dfe445 Merge pull request #409 from modeseven-lfreleng-actions/chore/python-workflow ee17956 Fix: Stop mixing typer's click with the real one fe59ba8 Merge pull request #397 from modeseven-lfreleng-actions/fix/mypy-tests 77702ba CI: Bump python-workflows to v0.4.0 2b482e8 CI: Extend mypy to tests and scripts 6631818 Fix: Let explicit CLI flags outrank the environment 3b60cee Merge pull request #396 from modeseven-lfreleng-actions/fix/credential-memo da8eb9a Fix: Derive Gerrit credentials from live inputs 8d271c6 Merge pull request #393 from modeseven-lfreleng-actions/fix/open-issues Additional commits viewable in compare view Updates `lfreleng-actions/sonatype-lifecycle-scan-action` from 0.2.0 to 0.2.1 ## Release notes Sourced from lfreleng-actions/sonatype-lifecycle-scan-action's releases. v0.2.1 🐛 Bug Fixes 🐛 Fix: Expand workspace variables in CLI inputs @ModeSevenIndustrialSolutions (#177) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#154) Chore: Disable pre-commit.ci autofix PRs @ModeSevenIndustrialSolutions (#155) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.4 to 1.1.2 @dependabot[bot] (#156) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.9.1 @dependabot[bot] (#157) Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#158) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#159) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#160) Refactor: Call the shared release workflow @ModeSevenIndustrialSolutions (#161) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.0 @dependabot[bot] (#162) Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#163) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#164) Chore: Bump actions/setup-java from 5.6.0 to 5.7.0 @dependabot[bot] (#165) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#166) Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#167) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#168) Chore: Bump sonatype/actions/setup-iq-cli from 1.13.0 to 1.14.0 @dependabot[bot] (#169) Chore: Bump sonatype/actions/run-iq-cli from 1.13.0 to 1.14.0 @dependabot[bot] (#170) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#171) Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#173) Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.0.4 to 0.1.0 @dependabot[bot] (#174) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#176) Chore: Replace LICENSE symlink with regular file @ModeSevenIndustrialSolutions (#175) Links Submit bugs/feature requests ## Commits bfe8863 Merge pull request #177 from modeseven-lfreleng-actions/fix/expand-workspace- c94c3c8 Fix: Expand workspace variables in CLI inputs 684feb4 Merge pull request #175 from modeseven-lfreleng-actions/chore/license-regular 55d7811 Merge pull request #176 from lfreleng-actions/pre-commit-ci-update-config 153957b Chore: pre-commit autoupdate 858b73d Chore: Replace LICENSE symlink with regular file 92a89fe Merge pull request #174 from lfreleng-actions/dependabot/github_actions/lfrel 3661490 Merge pull request #173 from lfreleng-actions/dependabot/github_actions/step- b61d6a3 Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml 50b471f Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 Additional commits viewable in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Iee7f1bea8b7b2765d0565b1888424b54d8d8220a GitHub-PR: #30 GitHub-Hash: 4e17ca7447dbbb7c Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/sonatype-lifecycle-scan-action.
Updates
lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yamlfrom 2.1.0 to 2.1.1Release notes
Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.
Commits
bbf43f3Merge pull request #399 from modeseven-lfreleng-actions/fix/typer-click-split2dfe445Merge pull request #409 from modeseven-lfreleng-actions/chore/python-workflow...ee17956Fix: Stop mixing typer's click with the real onefe59ba8Merge pull request #397 from modeseven-lfreleng-actions/fix/mypy-tests77702baCI: Bump python-workflows to v0.4.02b482e8CI: Extend mypy to tests and scripts6631818Fix: Let explicit CLI flags outrank the environment3b60ceeMerge pull request #396 from modeseven-lfreleng-actions/fix/credential-memoda8eb9aFix: Derive Gerrit credentials from live inputs8d271c6Merge pull request #393 from modeseven-lfreleng-actions/fix/open-issuesUpdates
lfreleng-actions/sonatype-lifecycle-scan-actionfrom 0.2.0 to 0.2.1Release notes
Sourced from lfreleng-actions/sonatype-lifecycle-scan-action's releases.
Commits
bfe8863Merge pull request #177 from modeseven-lfreleng-actions/fix/expand-workspace-...c94c3c8Fix: Expand workspace variables in CLI inputs684feb4Merge pull request #175 from modeseven-lfreleng-actions/chore/license-regular...55d7811Merge pull request #176 from lfreleng-actions/pre-commit-ci-update-config153957bChore: pre-commit autoupdate858b73dChore: Replace LICENSE symlink with regular file92a89feMerge pull request #174 from lfreleng-actions/dependabot/github_actions/lfrel...3661490Merge pull request #173 from lfreleng-actions/dependabot/github_actions/step-...b61d6a3Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml50b471fChore: Bump step-security/harden-runner from 2.20.1 to 2.21.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions