- 
                Notifications
    You must be signed in to change notification settings 
- Fork 0
⬆️ gha: Bump the github-actions group across 1 directory with 14 updates #19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
⬆️ gha: Bump the github-actions group across 1 directory with 14 updates #19
Conversation
Bumps the github-actions group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.12.0` | `2.13.0` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.6.0` | `4.7.3` | | [reviewdog/action-tflint](https://github.com/reviewdog/action-tflint) | `1.24.2` | `1.25.0` | | [reviewdog/action-trivy](https://github.com/reviewdog/action-trivy) | `1.13.10` | `1.14.0` | | [reviewdog/action-actionlint](https://github.com/reviewdog/action-actionlint) | `1.65.2` | `1.67.0` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.0.1` | | [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `5.3.0` | `5.4.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.2.2` | `2.3.3` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.2` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.16` | `3.30.1` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.4.0` | `6.0.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `5.0.0` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `4.1.0` | `5.0.0` | Updates `step-security/harden-runner` from 2.12.0 to 2.13.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@0634a26...ec9f2d5) Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) Updates `actions/dependency-review-action` from 4.6.0 to 4.7.3 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@ce3cf95...595b5ae) Updates `reviewdog/action-tflint` from 1.24.2 to 1.25.0 - [Release notes](https://github.com/reviewdog/action-tflint/releases) - [Commits](reviewdog/action-tflint@41b4770...54a5e5a) Updates `reviewdog/action-trivy` from 1.13.10 to 1.14.0 - [Release notes](https://github.com/reviewdog/action-trivy/releases) - [Commits](reviewdog/action-trivy@0cab87b...a1e6d7d) Updates `reviewdog/action-actionlint` from 1.65.2 to 1.67.0 - [Release notes](https://github.com/reviewdog/action-actionlint/releases) - [Commits](reviewdog/action-actionlint@a5524e1...95395aa) Updates `actions/labeler` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...634933e) Updates `mikepenz/release-changelog-builder-action` from 5.3.0 to 5.4.1 - [Release notes](https://github.com/mikepenz/release-changelog-builder-action/releases) - [Commits](mikepenz/release-changelog-builder-action@e92187b...c9dc836) Updates `softprops/action-gh-release` from 2.2.2 to 2.3.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@da05d55...6cbd405) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.2 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@f49aabe...05b42c6) Updates `github/codeql-action` from 3.28.16 to 3.30.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@28deaed...f1f6e5f) Updates `actions/setup-go` from 5.4.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@0aaccfd...4469467) Updates `actions/setup-node` from 4.4.0 to 5.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@49933ea...a0853c2) Updates `aws-actions/configure-aws-credentials` from 4.1.0 to 5.0.0 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@ececac1...a03048d) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.7.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-tflint dependency-version: 1.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-trivy dependency-version: 1.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-actionlint dependency-version: 1.67.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: mikepenz/release-changelog-builder-action dependency-version: 5.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 2.3.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 3.30.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
| Important Review skippedBot user detected. To trigger a single review, invoke the  You can disable this status message by setting the  Comment  | 
| 💰 Infracost reportMonthly estimate generatedThis comment will be updated when code changes. | 
| Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
 Scanned Files
 | 
| Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting  | 
| Looks like these dependencies are updatable in another way, so this is no longer needed. | 
Bumps the github-actions group with 14 updates in the / directory:
2.12.02.13.04.2.25.0.04.6.04.7.31.24.21.25.01.13.101.14.01.65.21.67.05.0.06.0.15.3.05.4.12.2.22.3.32.4.12.4.23.28.163.30.15.4.06.0.04.4.05.0.04.1.05.0.0Updates
step-security/harden-runnerfrom 2.12.0 to 2.13.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
ec9f2d5Merge pull request #565 from step-security/rc-2404bcbc3update agent7c7a56ffeat: get job summary from API6c439dcMerge pull request #562 from step-security/rc-22bf56886update agent5436dacupdate agent88d305aupdate agentb976878update agent875cc92Update agent002fdceMerge pull request #544 from step-security/rc-21Updates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
actions/dependency-review-actionfrom 4.6.0 to 4.7.3Release notes
Sourced from actions/dependency-review-action's releases.
Commits
595b5aeUpdate package version (#975)fc5fd66Claire153/fix spamming mentioned issue (#974)d38d1a4Merge pull request #965 from actions/dependabot/npm_and_yarn/multi-c22e25d29b8d420b8Merge branch 'main' into dependabot/npm_and_yarn/multi-c22e25d29bbde0129Merge pull request #966 from actions/ashelytc/add-permissionsab52490remove rubyef00a0aadd permissions to workflows74c8179Bump brace-expansionbc41886Cut 4.7.2 version release (#964)1c73553Merge pull request #960 from ahpook/ahpook/address-docs-dashesUpdates
reviewdog/action-tflintfrom 1.24.2 to 1.25.0Release notes
Sourced from reviewdog/action-tflint's releases.
Commits
54a5e5achore(deps): update reviewdog/reviewdog to 0.21.0 (#101)92ecd5bREADME: Pin GitHub Actions with commit SHA using pinact (#108)4e022bbchore(deps): update reviewdog/action-misspell action to v1.26.3 (#106)1848510chore(deps): update reviewdog/action-depup action to v1.6.4 (#104)f1101e4chore(deps): update reviewdog/action-misspell action to v1.26.2 (#105)Updates
reviewdog/action-trivyfrom 1.13.10 to 1.14.0Release notes
Sourced from reviewdog/action-trivy's releases.
Commits
a1e6d7dMerge pull request #104 from reviewdog/depup/reviewdog20b6816chore(deps): update reviewdog to 0.21.0a1a479dMerge pull request #94 from reviewdog/renovate/azurerm-4.x7a02290chore(deps): update terraform azurerm to ~> 4.26.0590ac69Merge pull request #93 from reviewdog/renovate/aws-5.xf895ad5chore(deps): update terraform aws to ~> 5.94.05392bccMerge pull request #92 from reviewdog/renovate/azurerm-4.x0e5f775chore(deps): update terraform azurerm to ~> 4.25.090be6baMerge pull request #91 from reviewdog/renovate/aws-5.x536d9aachore(deps): update terraform aws to ~> 5.93.0Updates
reviewdog/action-actionlintfrom 1.65.2 to 1.67.0Release notes
Sourced from reviewdog/action-actionlint's releases.
Commits
95395aabump v1.67.0af47a90Merge branch 'main' into releases/v193dc1f9Merge pull request #172 from reviewdog/depup/reviewdog37d6325chore(deps): update reviewdog to 0.21.0e37e2cabump v1.66.1421367cMerge branch 'main' into releases/v193ee9b0Merge pull request #171 from reviewdog/bump-minor41038bcbump the minor version4a597f8bump v1.65.3826eac1Merge branch 'main' into releases/v1Updates
actions/labelerfrom 5.0.0 to 6.0.1Release notes
Sourced from actions/labeler's releases.
... (truncated)
Commits
634933epublish-action upgrade to 0.4.0 from 0.2.2 (#901)f1a63e8Update Node.js version to 24 in action and dependencies (#891)b0a1180Bump@octokit/request-errorfrom 5.0.1 to 5.1.1 (#846)110d441Update README.md (#871)bee50feBump undici from 5.28.4 to 5.28.5 (#842)6463cdbBump eslint-plugin-jest from 28.9.0 to 28.11.0 (#839)c209686Bump typescript from 5.7.2 to 5.7.3 (#835)5184940Bump@vercel/nccfrom 0.38.1 to 0.38.3 (#830)3629d55Document update - permission section (#840)d24f7f3Bump ts-jest from 29.1.2 to 29.2.5 (#831)Updates
mikepenz/release-changelog-builder-actionfrom 5.3.0 to 5.4.1Release notes
Sourced from mikepenz/release-changelog-builder-action's releases.
Commits
c9dc836Merge pull request #1465 from mikepenz/develop825abd1Merge pull request #1463 from mikepenz/ci/impr59e4e52Merge pull request #1462 from mikepenz/feature/dependency_upgradese1c7bbf- combined run for tests to get a full report981311d- upgrade dependenciesglobals, and ton of dev dependenciese97a713Merge pull request #1461 from mikepenz/developaf5898dMerge pull request #1460 from mikepenz/feature/14596c979ed- also test the offline variant8357bc6- make sure we reset env prior to the next test0f359e3- apply codeQL ruleUpdates
softprops/action-gh-releasefrom 2.2.2 to 2.3.3Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
6cbd405release 2.3.3fbadcc9update to useactions/checkout@v54a84006chore(deps): bump@types/nodefrom 20.19.10 to 20.19.11 in the npm group (#648)7191749chore(deps): bump actions/checkout in the github-actions group (#649)126b1e7chore(deps): bump@types/nodefrom 20.19.9 to 20.19.10 in the npm group (#647)f82d31echore(deps): bump the npm group with 3 updates (#643)f2352b9chore(deps): bump@types/nodefrom 20.19.2 to 20.19.7 in the npm group (#640)f0b3259chore(deps): bump the npm group across 1 directory with 4 updates (#638)f37a2f9chore(deps): bump the npm group with 2 updates (#635)db56014chore(deps): bump brace-expansion from 2.0.1 to 2.0.2 (#634)Updates
ossf/scorecard-actionfrom 2.4.1 to 2.4.2Release notes
Sourced from ossf/scorecard-action's releases.
Commits
05b42c6🌱 bump docker to ghcr v2.4.2 (#1548)b225da6Bump github.com/ossf/scorecard/v5 from v5.2.0 to v5.2.1 (#1550)9399f6f🌱 Bump the docker-images group across 1 directory with 2 updates (#1...e1daa8c🌱 Bump the github-actions group across 1 directory with 5 updates (#...9fe6511🌱 Bump golang.org/x/net from 0.39.0 to 0.40.0 (#1542)25b9cd9🌱 Bump github.com/ossf/scorecard/v5 from v5.1.1 to v5.2.0 (#1547)18cc9b8🌱 Bump golang.org/x/net from 0.38.0 to 0.39.0 (#1536)db78142🌱 Bump the github-actions group with 2 updates (#1538)de386ed🌱 Bump golang from 1.24.1 to 1.24.2 in the docker-images group (#1534)5b7cedb🌱 Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 (#1537)Updates
github/codeql-actionfrom 3.28.16 to 3.30.1Release notes
Sourced from github/codeql-action's releases.