From 9d5710ba90ca23ba1fed807e6551aef51475e45d Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 8 Oct 2026 20:43:34 +0000 Subject: [PATCH] Bump the github-actions-updates group with 4 updates Bumps the github-actions-updates group with 4 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action), [step-security/harden-runner](https://github.com/step-security/harden-runner), [lfreleng-actions/checkout-gerrit-change-action](https://github.com/lfreleng-actions/checkout-gerrit-change-action) and [lfreleng-actions/maven-build-action](https://github.com/lfreleng-actions/maven-build-action). Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.4.0 to 2.4.2 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](https://github.com/lfreleng-actions/github2gerrit-action/compare/df12d7f11e4765687efefd034d10116b1d8d0f4d...6cdadc0d954315c37bbe50cf0edac88eb01df041) Updates `step-security/harden-runner` from 2.21.1 to 2.22.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/e14015d583714f6e62063499dc959a02595150a1...351661ca32ac09a36dc5ee2d536e3128f2a3c8ed) Updates `lfreleng-actions/checkout-gerrit-change-action` from 1.1.0 to 1.1.2 - [Release notes](https://github.com/lfreleng-actions/checkout-gerrit-change-action/releases) - [Commits](https://github.com/lfreleng-actions/checkout-gerrit-change-action/compare/298f53bbbc1d5f9e54df9feb484d110dc2b33197...35e98c8043ec411611e464e296bcfb441a5c5093) Updates `lfreleng-actions/maven-build-action` from 0.4.3 to 0.5.2 - [Release notes](https://github.com/lfreleng-actions/maven-build-action/releases) - [Commits](https://github.com/lfreleng-actions/maven-build-action/compare/7781c31c0c5e7d345313807cde36377d0932e5d6...01a3700e14ee592694d1030c2305d0579e9df571) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 2.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: step-security/harden-runner dependency-version: 2.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/checkout-gerrit-change-action dependency-version: 1.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: lfreleng-actions/maven-build-action dependency-version: 0.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/call-github2gerrit.yaml | 2 +- .github/workflows/gerrit-clm.yaml | 10 +++++----- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/call-github2gerrit.yaml b/.github/workflows/call-github2gerrit.yaml index 612afeaae..b895cb08b 100644 --- a/.github/workflows/call-github2gerrit.yaml +++ b/.github/workflows/call-github2gerrit.yaml @@ -67,7 +67,7 @@ jobs: pull-requests: write # comment on and close mirrored PRs issues: write # manage PR/issue metadata during mirroring # yamllint disable-line rule:line-length - uses: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml@df12d7f11e4765687efefd034d10116b1d8d0f4d # v2.4.0 + uses: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml@6cdadc0d954315c37bbe50cf0edac88eb01df041 # v2.4.2 with: USE_PR_AS_COMMIT: true GERRIT_KNOWN_HOSTS: ${{ vars.GERRIT_KNOWN_HOSTS }} diff --git a/.github/workflows/gerrit-clm.yaml b/.github/workflows/gerrit-clm.yaml index d70d97667..af5ab37b4 100644 --- a/.github/workflows/gerrit-clm.yaml +++ b/.github/workflows/gerrit-clm.yaml @@ -111,7 +111,7 @@ jobs: steps: # Harden the runner used by this workflow # yamllint disable-line rule:line-length - - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + - uses: step-security/harden-runner@351661ca32ac09a36dc5ee2d536e3128f2a3c8ed # v2.22.0 with: egress-policy: audit @@ -139,7 +139,7 @@ jobs: steps: # Harden the runner used by this workflow # yamllint disable-line rule:line-length - - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + - uses: step-security/harden-runner@351661ca32ac09a36dc5ee2d536e3128f2a3c8ed # v2.22.0 with: egress-policy: audit @@ -160,7 +160,7 @@ jobs: # yamllint disable-line rule:line-length if: github.event_name == 'workflow_dispatch' && inputs.GERRIT_DISABLED != true # yamllint disable-line rule:line-length - uses: lfreleng-actions/checkout-gerrit-change-action@298f53bbbc1d5f9e54df9feb484d110dc2b33197 # v1.1.0 + uses: lfreleng-actions/checkout-gerrit-change-action@35e98c8043ec411611e464e296bcfb441a5c5093 # v1.1.2 with: gerrit-refspec: ${{ inputs.GERRIT_REFSPEC }} gerrit-project: ${{ inputs.GERRIT_PROJECT }} @@ -374,7 +374,7 @@ jobs: if: steps.check-pom-xml.outputs.exists == 'true' continue-on-error: true # yamllint disable-line rule:line-length - uses: lfreleng-actions/maven-build-action@7781c31c0c5e7d345313807cde36377d0932e5d6 # v0.4.3 + uses: lfreleng-actions/maven-build-action@01a3700e14ee592694d1030c2305d0579e9df571 # v0.5.2 with: java-version: ${{ env.JAVA_VERSION }} distribution: ${{ env.JAVA_DISTRIBUTION }} @@ -411,7 +411,7 @@ jobs: steps: # Harden the runner used by this workflow # yamllint disable-line rule:line-length - - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + - uses: step-security/harden-runner@351661ca32ac09a36dc5ee2d536e3128f2a3c8ed # v2.22.0 with: egress-policy: audit