-
Notifications
You must be signed in to change notification settings - Fork 3
Bump the action-deps group across 1 directory with 4 updates #909
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the action-deps group across 1 directory with 4 updates #909
Conversation
Bumps the action-deps group with 4 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action), [actions/dependency-review-action](https://github.com/actions/dependency-review-action), [docker/login-action](https://github.com/docker/login-action) and [ossf/scorecard-action](https://github.com/ossf/scorecard-action). Updates `github/codeql-action` from 3.30.3 to 3.30.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@192325c...3599b3b) Updates `actions/dependency-review-action` from 4.7.3 to 4.8.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@595b5ae...56339e5) Updates `docker/login-action` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@184bdaa...5e57cd1) Updates `ossf/scorecard-action` from 2.4.2 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@05b42c6...4eaacf0) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 3.30.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: action-deps - dependency-name: actions/dependency-review-action dependency-version: 4.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-deps - dependency-name: docker/login-action dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-deps - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: action-deps ... Signed-off-by: dependabot[bot] <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #909 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 8 8
Lines 151 151
Branches 11 11
=========================================
Hits 151 151
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
🔍 Vulnerabilities of
|
| digest | sha256:49beadc488e817975667cb85de99d1363830b5bdb10e69e792ed5f7bc2fcf63d |
| vulnerabilities | |
| platform | linux/amd64 |
| size | 26 MB |
| packages | 60 |
📦 Base Image python:3-alpine
| also known as |
|
| digest | sha256:527c28b29498575b851ad88e7522ac7201bbd9e920d2c11b00ff2b39b315f5f8 |
| vulnerabilities |
Description
Description
| ||||||||||||||||||||||||
Description
Description
Description | ||||||||||||||||||||||||
Description
Description
| ||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||
Description
Description |
Overview
Environment Variables (2 changes)
GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305
PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
PYTHONDONTWRITEBYTECODE=1
PYTHONFAULTHANDLER=1
-PYTHON_SHA256=93e583f243454e6e9e4588ca2c2662206ad961659863277afcdb96801647d640
+PYTHON_SHA256=5462f9099dfd30e238def83c71d91897d8caa5ff6ebc7a50f14d4802cdaaa79a
-PYTHON_VERSION=3.13.5
+PYTHON_VERSION=3.13.7Labels (3 changes)
-org.opencontainers.image.created=2025-06-20T11:12:42.735Z
+org.opencontainers.image.created=2025-10-03T08:02:52.402Z
org.opencontainers.image.description=Update Hetzner Cloud firewall rules with current Cloudflare IP ranges
org.opencontainers.image.licenses=MIT
-org.opencontainers.image.revision=90ebdb0cde09868906e19bfb8b149a1abd09824b
+org.opencontainers.image.revision=f139d98c27dc21c5ae4d60d352f49b34fbc86c40
org.opencontainers.image.source=https://github.com/jkreileder/cf-ips-to-hcloud-fw
org.opencontainers.image.title=cf-ips-to-hcloud-fw
org.opencontainers.image.url=https://github.com/jkreileder/cf-ips-to-hcloud-fw
-org.opencontainers.image.version=1.0.17
+org.opencontainers.image.version=pr-909Policies (0 improved, 2 worsened, 2 missing data)
Packages and Vulnerabilities (13 package changes and 2 vulnerability changes)
Changes for packages of type
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Package | Versionjkreileder/cf-ips-to-hcloud-fw:1 |
Versionquay.io/jkreileder/cf-ips-to-hcloud-fw:pr-909 |
|
|---|---|---|---|
| ♾️ | .python-rundeps | 20250619.205442 |
20250819.144338 |
| ♾️ | alpine-base | 3.22.0-r0 |
3.22.1-r0 |
| ♾️ | alpine-release | 3.22.0-r0 |
3.22.1-r0 |
| ♾️ | ca-certificates | 20241121-r2 |
20250619-r0 |
| ♾️ | ca-certificates-bundle | 20241121-r2 |
20250619-r0 |
| ♾️ | libcrypto3 | 3.5.0-r0 |
3.5.1-r0 |
| ♾️ | libssl3 | 3.5.0-r0 |
3.5.1-r0 |
| ♾️ | openssl | 3.5.0-r0 |
3.5.1-r0 |
| Removed vulnerabilities (1): |
|||
| ♾️ | sqlite | 3.49.2-r0 |
3.49.2-r1 |
| Removed vulnerabilities (1): |
|||
| ♾️ | sqlite-libs | 3.49.2-r0 |
3.49.2-r1 |
Changes for packages of type generic (1 changes)
| Package | Versionjkreileder/cf-ips-to-hcloud-fw:1 |
Versionquay.io/jkreileder/cf-ips-to-hcloud-fw:pr-909 |
|
|---|---|---|---|
| ♾️ | python | 3.13.5 |
3.13.7 |
Bumps the action-deps group with 4 updates in the / directory: github/codeql-action, actions/dependency-review-action, docker/login-action and ossf/scorecard-action.
Updates
github/codeql-actionfrom 3.30.3 to 3.30.5Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
3599b3bMerge pull request #3161 from github/update-v3.30.5-0a67bd46a2ca0085Update changelog for v3.30.50a67bd4Merge pull request #3160 from github/mbg/fix/upload-sarif8e34f2fAdd changelog0b7fc56Fixupload-sarifnot uploading non-.sariffiles94a9b7aMerge pull request #3155 from github/mbg/node/no-install-in-actionsa0ae9baLog what the script is doingb27a8efExit if running in an Actions workflow6592567Merge pull request #3139 from github/henrymercer/fix-log-messagefa64a7dMerge pull request #3154 from github/mbg/node/check-up-to-date-depsUpdates
actions/dependency-review-actionfrom 4.7.3 to 4.8.0Release notes
Sourced from actions/dependency-review-action's releases.
Commits
56339e5Merge pull request #988 from actions/brrygrdn/rc-4.8.01688b74Bump to a 4.8.031c9f17Merge pull request #987 from actions/rc-4.7.4eacde78Update version8151009Merge pull request #986 from actions/brrygrdn/rc-4.7.4b472ec9Add a quick regression test for the artefact summarye0cedc5feat: add large summary handling with artifact uploade3fdf0fThis ensures large allow or deny lists don't create huge comments6fad417Merge pull request #978 from actions/ljones140/make-ruby-code-scannablee86e969Update scripts/scan_pr_lib.rbUpdates
docker/login-actionfrom 3.5.0 to 3.6.0Release notes
Sourced from docker/login-action's releases.
Commits
5e57cd1Merge pull request #890 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...97e3143chore: update generated content3a0796bbuild(deps): bump the aws-sdk-dependencies group with 2 updates5b7b28bMerge pull request #882 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...abc9fb3chore: update generated contentd468688build(deps): bump the aws-sdk-dependencies group with 2 updatesa99b2f8Merge pull request #883 from docker/dependabot/npm_and_yarn/docker/actions-to...0d7fae8chore: update generated content9832253build(deps): bump@docker/actions-toolkitfrom 0.62.1 to 0.63.009e05bbMerge pull request #881 from docker/dependabot/npm_and_yarn/tmp-0.2.4Updates
ossf/scorecard-actionfrom 2.4.2 to 2.4.3Release notes
Sourced from ossf/scorecard-action's releases.
Commits
4eaacf0bump docker to ghcr v2.4.3 (#1587)42e3a01🌱 Bump the github-actions group with 3 updates (#1585)88c07ac🌱 Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)6c690f2Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)92083b5📖 Fix recommended command to test the image in development (#1583)7975ea6🌱 Bump the docker-images group across 1 directory with 2 updates (#1...0d1a743🌱 Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)46e6e0c🌱 Bump the github-actions group with 2 updates (#1580)c3f1350🌱 Improve printing options (#1584)43e475b🌱 Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions