chore(deps): bump the all-actions group across 1 directory with 10 updates#583
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): bump the all-actions group across 1 directory with 10 updates#583dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
…dates Bumps the all-actions group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.0` | `2.19.0` | | [actions/checkout](https://github.com/actions/checkout) | `6.0.1` | `6.0.2` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.1.0` | `6.4.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `5.1.0` | `5.2.0` | | [gradle/actions](https://github.com/gradle/actions) | `5.0.0` | `6.1.0` | | [step-security/publish-unit-test-result-action](https://github.com/step-security/publish-unit-test-result-action) | `2.21.1` | `2.23.0` | | [step-security/action-semantic-pull-request](https://github.com/step-security/action-semantic-pull-request) | `6.1.1` | `6.1.2` | | [step-security/ghaction-import-gpg](https://github.com/step-security/ghaction-import-gpg) | `6.3.1` | `7.0.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.1.0` | `6.4.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6.0.0` | `7.0.1` | Updates `step-security/harden-runner` from 2.14.0 to 2.19.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@20cf305...8d3c67d) Updates `actions/checkout` from 6.0.1 to 6.0.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@8e8c483...de0fac2) Updates `actions/setup-go` from 6.1.0 to 6.4.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@4dc6199...4a36011) Updates `actions/setup-java` from 5.1.0 to 5.2.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@f2beeb2...be666c2) Updates `gradle/actions` from 5.0.0 to 6.1.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@4d9f0ba...50e97c2) Updates `step-security/publish-unit-test-result-action` from 2.21.1 to 2.23.0 - [Release notes](https://github.com/step-security/publish-unit-test-result-action/releases) - [Commits](step-security/publish-unit-test-result-action@914f0f6...681100d) Updates `step-security/action-semantic-pull-request` from 6.1.1 to 6.1.2 - [Release notes](https://github.com/step-security/action-semantic-pull-request/releases) - [Commits](step-security/action-semantic-pull-request@bc0cf74...75d2dd5) Updates `step-security/ghaction-import-gpg` from 6.3.1 to 7.0.0 - [Release notes](https://github.com/step-security/ghaction-import-gpg/releases) - [Commits](step-security/ghaction-import-gpg@69c854a...c0b4a33) Updates `actions/setup-node` from 6.1.0 to 6.4.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@395ad32...48b55a0) Updates `actions/upload-artifact` from 6.0.0 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b7c566a...043fb46) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-actions - dependency-name: actions/setup-go dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/setup-java dependency-version: 5.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: gradle/actions dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions - dependency-name: step-security/publish-unit-test-result-action dependency-version: 2.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: step-security/action-semantic-pull-request dependency-version: 6.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-actions - dependency-name: step-security/ghaction-import-gpg dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions - dependency-name: actions/setup-node dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all-actions group with 10 updates in the / directory:
2.14.02.19.06.0.16.0.26.1.06.4.05.1.05.2.05.0.06.1.02.21.12.23.06.1.16.1.26.3.17.0.06.1.06.4.06.0.07.0.1Updates
step-security/harden-runnerfrom 2.14.0 to 2.19.0Release notes
Sourced from step-security/harden-runner's releases.
... (truncated)
Commits
8d3c67dRelease v2.19.0 (#661)6c3c2f2Feature/deploy on self hosted vm (#658)f808768Feature/policy store (#656)fe10465v2.16.1 (#654)fa2e9d6Release v2.16.0 (#646)58077d3Release v2.15.1 (#641)a90bcbcUpdate readme (#637)f0a59d8Release v2.15.0 (#639)5ef0c07Merge pull request #635 from step-security/rc-34eb43c7bupdate agentUpdates
actions/checkoutfrom 6.0.1 to 6.0.2Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...Updates
actions/setup-gofrom 6.1.0 to 6.4.0Release notes
Sourced from actions/setup-go's releases.
Commits
4a36011docs: fix Microsoft build of Go link (#734)8f19afcfeat: add go-download-base-url input for custom Go distributions (#721)27fdb26Bump minimatch from 3.1.2 to 3.1.5 (#727)def8c39Rearrange README.md, add advanced-usage.md (#724)4b73464Fix golang download url to go.dev (#469)a5f9b05Update default Go module caching to use go.mod (#705)7a3fe6cBump qs from 6.14.0 to 6.14.1 (#703)b9adafdBump actions/checkout from 5 to 6 (#686)d73f6bcREADME.md: correct to actions/checkout@v6 (#683)ae252eeBump@actions/cacheto v5 (#695)Updates
actions/setup-javafrom 5.1.0 to 5.2.0Release notes
Sourced from actions/setup-java's releases.
Commits
be666c2Chore: Version Update and Checkout Update to v6 (#973)f7a6fefBump actions/checkout from 5 to 6 (#961)d81c4e4Upgrade@actions/cacheto v5 (#968)1b1bbe1readme update (#972)5d7b214Retry on HTTP 522 Connection timed out (#964)Updates
gradle/actionsfrom 5.0.0 to 6.1.0Release notes
Sourced from gradle/actions's releases.
... (truncated)
Commits
50e97c2Link to docs for caching providersf2e6298Restructure caching documentation for basic and enhanced providers (#934)b294b1eReally fix integ-test-full83d3189Revise license details for gradle-actions-caching1d5db06Update license link for gradle-actions-caching component1c80961Fix license link for Enhanced Caching component9e99920Fix integ-test-full workflowbb8aaafFix workflow permissionsf5dfb43[bot] Update dist directoryff9ae24Add open-source 'basic' cache provider and revamp licensing documentation (#930)Updates
step-security/publish-unit-test-result-actionfrom 2.21.1 to 2.23.0Release notes
Sourced from step-security/publish-unit-test-result-action's releases.
Commits
681100dMerge pull request #180 from step-security/anurag-stepsecurity-patch-176407c0chore: Update image tag to v2.23.0f89dc9eMerge pull request #179 from step-security/anurag-stepsecurity-patch-136cc645chore: Remove image tag and sha482a1c9Merge pull request #177 from step-security/fix-vulnsf5e4ca9fix: Resolve security vulnerabilitiesff81920Merge pull request #166 from step-security/fix-vulns5de1103fix: Resolve security vulnerabilitiesa1d6c2eMerge pull request #173 from step-security/feat/update-subscription-check39a5377fix: resolve Windows cp1252 UnicodeEncodeError and refresh stale test fixturesUpdates
step-security/action-semantic-pull-requestfrom 6.1.1 to 6.1.2Release notes
Sourced from step-security/action-semantic-pull-request's releases.
Commits
75d2dd5Merge pull request #162 from step-security/Raj-StepSecurity-patch-11dce66eeUpdate actions_release.yml80eb62bMerge pull request #161 from step-security/yarn-audit-fixac0700ffix: apply audit fixes92d4228fix: apply audit fixes91fa82ffix: apply audit fixesfed9df2Merge pull request #160 from step-security/feat/update-subscription-check9d0ba60code linted21be1b8feat: added banner and update subscription check to make maintained actions f...57d5042Merge pull request #159 from step-security/yarn-audit-fixUpdates
step-security/ghaction-import-gpgfrom 6.3.1 to 7.0.0Release notes
Sourced from step-security/ghaction-import-gpg's releases.
Commits
c0b4a33Merge pull request #210 from step-security/feat/update-subscription-checkc2fcf60package updated9100cd3Update package.json04550bcUpdate action.ymla665b29Merge branch 'main' into feat/update-subscription-check7cf51b3Merge pull request #211 from step-security/Raj-StepSecurity-patch-5b14d3b0code lintedcca0382ci: Create claude_review.ymlcf10c6efeat: added banner and update subscription check to make maintained actions f...8bc4cd6Merge pull request #206 from step-security/auto-cherry-pickUpdates
actions/setup-nodefrom 6.1.0 to 6.4.0Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
48b55a0Update Node.js versions in versions.yml and bump package to v6.4.0 (#1533)ab72c7eUpgrade@actionsdependencies (#1525)53b8394Bump minimatch from 3.1.2 to 3.1.5 (#1498)54045abScope test lockfiles by package manager and update cache tests (#1495)