Skip to content

Bump the github-actions-updates group with 3 updates - #41

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-5d1f0c7530
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-5d1f0c7530

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-updates group with 3 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml, step-security/harden-runner and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml.

Updates lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml from 2.4.0 to 2.4.2

Release notes

Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.

v2.4.2

Downloads for this release

🔧 Maintenance 🔧

Links

v2.4.1

Downloads for this release

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

Commits
  • 6cdadc0 Merge pull request #464 from lfreleng-actions/dependabot/uv/uv-2118ef368f
  • 14f5957 Chore: Bump pyjwt
  • 35ee28f Merge pull request #463 from modeseven-lfreleng-actions/docs/agents-stub
  • 40a0623 Docs: Add repository AGENTS.md stub
  • 5b695df Merge pull request #456 from modeseven-lfreleng-actions/ci/lint-baseline-and-...
  • 3129b1d CI: Exercise the scheduled sweep daily
  • 27448b4 CI: Use self-repository syntax in testing
  • 47d46b6 CI(lint): Adopt the actions-template lint baseline
  • ae700ab Merge pull request #462 from lfreleng-actions/pre-commit-ci-update-config
  • f242c24 Chore: pre-commit autoupdate
  • Additional commits viewable in compare view

Updates step-security/harden-runner from 2.21.1 to 2.22.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.22.0

What's Changed

  • Linux ARM64 support for community tier
  • GHES support for self-hosted VMs (enterprise tier)
  • MacOS and Windows runner deny list support for block policy (enterprise tier).

Full Changelog: step-security/harden-runner@v2.21.1...v2.22.0

Commits

Updates lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.9.0 to 0.9.2

Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.9.2

Downloads for this release

🐛 Bug Fixes 🐛

🎓 Code Quality 🎓

Links

v0.9.1

Downloads for this release

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

Links

Commits
  • 4da5165 Merge pull request #116 from modeseven-lfreleng-actions/fix/scorecard-publish...
  • 81e09a2 Fix(scorecard): Tighten the publish-rule guard
  • b050a69 Fix(scorecard): Hard-code the scan runner label
  • 34374ce Merge pull request #114 from modeseven-lfreleng-actions/test/submodule-scan-c...
  • ae96a8d Merge pull request #130 from lfreleng-actions/dependabot/github_actions/lfrel...
  • b952d9e Merge pull request #129 from lfreleng-actions/dependabot/github_actions/githu...
  • 17e0bd6 Merge pull request #128 from lfreleng-actions/dependabot/github_actions/lfrel...
  • d5a60f0 Merge pull request #127 from lfreleng-actions/dependabot/github_actions/lfrel...
  • 8becb40 Merge pull request #126 from lfreleng-actions/dependabot/github_actions/astra...
  • d184f53 Merge pull request #125 from lfreleng-actions/dependabot/github_actions/lfrel...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-updates group with 3 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action), [step-security/harden-runner](https://github.com/step-security/harden-runner) and [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows).


Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.4.0 to 2.4.2
- [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases)
- [Commits](lfreleng-actions/github2gerrit-action@df12d7f...6cdadc0)

Updates `step-security/harden-runner` from 2.21.1 to 2.22.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@v2.21.1...351661c)

Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.9.0 to 0.9.2
- [Release notes](https://github.com/lfreleng-actions/security-workflows/releases)
- [Commits](lfreleng-actions/security-workflows@76ea523...4da5165)

---
updated-dependencies:
- dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: step-security/harden-runner
  dependency-version: 2.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

PR: #41
Mode: squash
Topic: GH-policy-pap-41
Change-Ids:
Ib4e68cfbafd05d32f4a90b5694095b0141a265a9
Digest: ac6c32d92c9f
GitHub-Hash: a66330825552baea

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/pap/+/148133

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants