Repository navigation
Bump the github-actions-updates group with 2 updates - #40
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions-updates group with 2 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) and [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows). Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.2.2 to 2.4.0 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](lfreleng-actions/github2gerrit-action@5f84610...df12d7f) Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.8.0 to 0.9.0 - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@7483557...76ea523) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 2.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #40 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/pap/+/147993 |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml. Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.2.2 to 2.4.0 ## Release notes Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases. v2.4.0 ✨ New Features ✨ Feat: Sweep approved fork PRs on a schedule @ModeSevenIndustrialSolutions (#455) Links Submit bugs/feature requests v2.3.0 ✨ New Features ✨ Feat: Fan out bulk sweeps and skip transferred forks @ModeSevenIndustrialSolutions (#454) Links Submit bugs/feature requests ## Commits df12d7f Merge pull request #455 from modeseven-lfreleng-actions/feat/scheduled-sweep 56d3246 Feat: Sweep approved fork PRs on a schedule 2fbfa39 Test: Share the reusable workflow test harness a483c25 Merge pull request #454 from modeseven-lfreleng-actions/feat/sweep-fan-out-id edb2d7b Fix: Address Copilot review feedback bced4e6 Feat: Fan bulk dispatch out to a job per PR 48bbc46 Feat: Record fork transfers so sweeps skip them See full diff in compare view Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.8.0 to 0.9.0 ## Release notes Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases. v0.9.0 ✨ New Features ✨ Feat: Test lane steps per PR and add Python CLM @ModeSevenIndustrialSolutions (#113) 🔧 Maintenance 🔧 CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.1 to 0.5.2 @dependabot[bot] (#108) CI(actions): Bump github/codeql-action/analyze from 4.37.9 to 4.38.0 @dependabot[bot] (#109) CI(actions): Bump lfreleng-actions/go-test-action from 0.1.0 to 0.1.1 @dependabot[bot] (#110) CI(actions): Bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0 @dependabot[bot] (#111) CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0 @dependabot[bot] (#112) Links Submit bugs/feature requests ## Commits 76ea523 Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness 3bd6689 Docs: Name Python among scan_targets exceptions ab0f5c6 Feat: Add a python build_type to the CLM lane 4c88685 Test: Run the lanes' validation steps on every PR 37d4e67 Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu 430b1ba Merge pull request #111 from lfreleng-actions/dependabot/github_actions/githu bb7e758 Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel 95377d3 Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu a12865c Merge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel 9d6aa08 CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0 Additional commits viewable in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: I9f296d6f9721159ae053ff6af05009bd073718d9 GitHub-PR: #40 GitHub-Hash: 8e3ce1ba8e3ce3cd Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml.
Updates
lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yamlfrom 2.2.2 to 2.4.0Release notes
Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.
Commits
df12d7fMerge pull request #455 from modeseven-lfreleng-actions/feat/scheduled-sweep56d3246Feat: Sweep approved fork PRs on a schedule2fbfa39Test: Share the reusable workflow test harnessa483c25Merge pull request #454 from modeseven-lfreleng-actions/feat/sweep-fan-out-id...edb2d7bFix: Address Copilot review feedbackbced4e6Feat: Fan bulk dispatch out to a job per PR48bbc46Feat: Record fork transfers so sweeps skip themUpdates
lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yamlfrom 0.8.0 to 0.9.0Release notes
Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.
Commits
76ea523Merge pull request #113 from modeseven-lfreleng-actions/test/validation-harness3bd6689Docs: Name Python among scan_targets exceptionsab0f5c6Feat: Add a python build_type to the CLM lane4c88685Test: Run the lanes' validation steps on every PR37d4e67Merge pull request #112 from lfreleng-actions/dependabot/github_actions/githu...430b1baMerge pull request #111 from lfreleng-actions/dependabot/github_actions/githu...bb7e758Merge pull request #110 from lfreleng-actions/dependabot/github_actions/lfrel...95377d3Merge pull request #109 from lfreleng-actions/dependabot/github_actions/githu...a12865cMerge pull request #108 from lfreleng-actions/dependabot/github_actions/lfrel...9d6aa08CI(actions): Bump github/codeql-action/init from 4.37.9 to 4.38.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions