Skip to content

Commit d56a105

Browse files
Bump the action-deps group across 1 directory with 4 updates (#909)
Bumps the action-deps group with 4 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action), [actions/dependency-review-action](https://github.com/actions/dependency-review-action), [docker/login-action](https://github.com/docker/login-action) and [ossf/scorecard-action](https://github.com/ossf/scorecard-action). Updates `github/codeql-action` from 3.30.3 to 3.30.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@192325c...3599b3b) Updates `actions/dependency-review-action` from 4.7.3 to 4.8.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@595b5ae...56339e5) Updates `docker/login-action` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@184bdaa...5e57cd1) Updates `ossf/scorecard-action` from 2.4.2 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@05b42c6...4eaacf0) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 3.30.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: action-deps - dependency-name: actions/dependency-review-action dependency-version: 4.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-deps - dependency-name: docker/login-action dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-deps - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: action-deps ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent b152568 commit d56a105

File tree

4 files changed

+10
-10
lines changed

4 files changed

+10
-10
lines changed

.github/workflows/codeql.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ jobs:
6464
run: make venv
6565

6666
- name: Initialize CodeQL
67-
uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
67+
uses: github/codeql-action/init@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.29.5
6868
with:
6969
languages: ${{ matrix.language }}
7070
queries: security-and-quality
@@ -73,6 +73,6 @@ jobs:
7373
run: make build
7474

7575
- name: Perform CodeQL analysis
76-
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
76+
uses: github/codeql-action/analyze@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.29.5
7777
with:
7878
category: "/language:${{ matrix.language }}"

.github/workflows/dependency-review.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,4 +35,4 @@ jobs:
3535
persist-credentials: false
3636

3737
- name: Dependency review
38-
uses: actions/dependency-review-action@595b5aeba73380359d98a5e087f648dbb0edce1b # v4.7.3
38+
uses: actions/dependency-review-action@56339e523c0409420f6c2c9a2f4292bbb3c07dd3 # v4.8.0

.github/workflows/docker.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -100,22 +100,22 @@ jobs:
100100

101101
- name: Login to DockerHub
102102
if: ${{ (github.event_name != 'pull_request' || !github.event.pull_request.head.repo.fork) && github.actor != 'dependabot[bot]' }}
103-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
103+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
104104
with:
105105
username: ${{ vars.DOCKERHUB_USERNAME }}
106106
password: ${{ secrets.DOCKERHUB_TOKEN }}
107107

108108
- name: Login to Quay
109109
if: ${{ github.event_name != 'pull_request' && github.actor != 'dependabot[bot]' }}
110-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
110+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
111111
with:
112112
registry: quay.io
113113
username: ${{ vars.QUAY_ROBOT }}
114114
password: ${{ secrets.QUAY_TOKEN }}
115115

116116
- name: Login to GitHub Container Registry
117117
if: ${{ github.event_name != 'pull_request' && github.actor != 'dependabot[bot]' }}
118-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
118+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
119119
with:
120120
registry: ghcr.io
121121
username: ${{ github.repository_owner }}
@@ -223,7 +223,7 @@ jobs:
223223
- name: Upload Docker Scout scan result to GitHub Security tab
224224
if: ${{ (github.event_name != 'pull_request' || !github.event.pull_request.head.repo.fork) && github.actor != 'dependabot[bot]' }}
225225
continue-on-error: true
226-
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
226+
uses: github/codeql-action/upload-sarif@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.29.5
227227
with:
228228
sarif_file: sarif.output.json
229229

@@ -237,7 +237,7 @@ jobs:
237237
add-cpes-if-none: true
238238

239239
- name: Upload Grype scan result to GitHub Security tab
240-
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
240+
uses: github/codeql-action/upload-sarif@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.29.5
241241
continue-on-error: true
242242
with:
243243
sarif_file: ${{ steps.grype-scan.outputs.sarif }}

.github/workflows/scorecard.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ jobs:
5151
persist-credentials: false
5252

5353
- name: Run analysis
54-
uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
54+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
5555
with:
5656
results_file: results.sarif
5757
results_format: sarif
@@ -65,6 +65,6 @@ jobs:
6565
retention-days: 5
6666

6767
- name: Upload to code-scanning
68-
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
68+
uses: github/codeql-action/upload-sarif@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.29.5
6969
with:
7070
sarif_file: results.sarif

0 commit comments

Comments
 (0)