-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
⬆️ (deps-ghaction): Bump the github-actions group across 1 directory with 10 updates #71
⬆️ (deps-ghaction): Bump the github-actions group across 1 directory with 10 updates #71
Conversation
…with 10 updates Bumps the github-actions group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.8.1` | `2.9.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.0.1` | `5.0.2` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.25.10` | `3.25.14` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.3.3` | `4.3.4` | | [reviewdog/action-trivy](https://github.com/reviewdog/action-trivy) | `1.9.0` | `1.11.0` | | [reviewdog/action-misspell](https://github.com/reviewdog/action-misspell) | `1.21.0` | `1.23.0` | | [reviewdog/action-alex](https://github.com/reviewdog/action-alex) | `1.11.0` | `1.13.0` | | [reviewdog/action-markdownlint](https://github.com/reviewdog/action-markdownlint) | `0.22.0` | `0.24.0` | | [reviewdog/action-actionlint](https://github.com/reviewdog/action-actionlint) | `1.51.0` | `1.54.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `4.3.4` | Updates `step-security/harden-runner` from 2.8.1 to 2.9.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@17d0e2b...0d38121) Updates `actions/setup-go` from 5.0.1 to 5.0.2 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@cdcb360...0a12ed9) Updates `github/codeql-action` from 3.25.10 to 3.25.14 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@23acc5c...5cf07d8) Updates `actions/dependency-review-action` from 4.3.3 to 4.3.4 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@72eb03d...5a2ce3f) Updates `reviewdog/action-trivy` from 1.9.0 to 1.11.0 - [Release notes](https://github.com/reviewdog/action-trivy/releases) - [Commits](reviewdog/action-trivy@53df306...14e16b3) Updates `reviewdog/action-misspell` from 1.21.0 to 1.23.0 - [Release notes](https://github.com/reviewdog/action-misspell/releases) - [Commits](reviewdog/action-misspell@30433ca...ef8b22c) Updates `reviewdog/action-alex` from 1.11.0 to 1.13.0 - [Release notes](https://github.com/reviewdog/action-alex/releases) - [Commits](reviewdog/action-alex@cb33600...f95df9e) Updates `reviewdog/action-markdownlint` from 0.22.0 to 0.24.0 - [Release notes](https://github.com/reviewdog/action-markdownlint/releases) - [Commits](reviewdog/action-markdownlint@03033f3...e9f3ab4) Updates `reviewdog/action-actionlint` from 1.51.0 to 1.54.0 - [Release notes](https://github.com/reviewdog/action-actionlint/releases) - [Commits](reviewdog/action-actionlint@afad3b6...4f8f996) Updates `actions/upload-artifact` from 4.3.3 to 4.3.4 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6546280...0b2256b) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: reviewdog/action-trivy dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-misspell dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-alex dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-markdownlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-actionlint dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (invoked as PR comments)
Additionally, you can add CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
simply
may be insensitive, try not to use it simple retext-equality
# For most projects, this workflow file will not need changing; you simply need |
@dependabot recreate |
Looks like these dependencies are no longer updatable, so this is no longer needed. |
Bumps the github-actions group with 10 updates in the / directory:
2.8.1
2.9.0
5.0.1
5.0.2
3.25.10
3.25.14
4.3.3
4.3.4
1.9.0
1.11.0
1.21.0
1.23.0
1.11.0
1.13.0
0.22.0
0.24.0
1.51.0
1.54.0
4.3.3
4.3.4
Updates
step-security/harden-runner
from 2.8.1 to 2.9.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
0d38121
Release v2.9.0 (#435)29e9ae1
Merge pull request #436 from step-security/dependabot/github_actions/actions/...9d596cf
Bump actions/upload-artifact from 3.1.3 to 4.3.46d3c2fe
Merge pull request #410 from step-security/dependabot/github_actions/ossf/sco...c2e63d3
Bump ossf/scorecard-action from 2.3.1 to 2.3.3547a5cc
Merge pull request #427 from step-security/dependabot/github_actions/step-sec...a5e1dca
Bump step-security/harden-runner from 2.8.0 to 2.8.13d32f8d
Merge pull request #426 from step-security/varunsh-coder-patch-1891104c
Update README.mdUpdates
actions/setup-go
from 5.0.1 to 5.0.2Release notes
Sourced from actions/setup-go's releases.
Commits
0a12ed9
Bump braces from 3.0.2 to 3.0.3 (#487)4ab57d7
Fix versions check failure (#479)Updates
github/codeql-action
from 3.25.10 to 3.25.14Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
5cf07d8
Merge pull request #2388 from github/update-v3.25.14-1b214db07ecab108
Update changelog for v3.25.141b214db
Merge pull request #2387 from github/aibaars/remove-set-secret826b78c
Remove setSecret callf67c9cd
Merge pull request #2376 from github/aibaars/start-proxy77e4172
start-proxy: get binary from toolcache4733419
Address comments6186179
Print proxy log when debugging is enabled7b43b7c
Add codeql-action/start-proxy5669f66
Add node-forge to package.jsonUpdates
actions/dependency-review-action
from 4.3.3 to 4.3.4Release notes
Sourced from actions/dependency-review-action's releases.
Commits
5a2ce3f
Merge pull request #791 from actions/juxtin/update-versionac6a6ad
Prepare even more for v4.3.43e2b917
Merge pull request #790 from actions/juxtin/update-versiond9ab9c8
Update version in package.json8c152c7
Merge pull request #769 from actions/dependabot/npm_and_yarn/zod-3.23.80085d30
Update dist08b5bf2
Bump zod from 3.22.4 to 3.23.8986fce9
Merge pull request #784 from actions/dependabot/npm_and_yarn/got-14.4.128743f8
Merge pull request #719 from actions/change-spdx-parserd6f34c3
Merge pull request #789 from actions/dependabot/npm_and_yarn/braces-3.0.3Updates
reviewdog/action-trivy
from 1.9.0 to 1.11.0Release notes
Sourced from reviewdog/action-trivy's releases.
Commits
14e16b3
Merge pull request #54 from reviewdog/depup/reviewdog030a047
chore(deps): update reviewdog to 0.20.182e31f8
Merge pull request #53 from reviewdog/depup/reviewdog7411c21
chore(deps): update reviewdog to 0.19.0Updates
reviewdog/action-misspell
from 1.21.0 to 1.23.0Release notes
Sourced from reviewdog/action-misspell's releases.
Commits
ef8b22c
Merge pull request #72 from reviewdog/depup/reviewdog8392e31
chore(deps): update reviewdog to 0.20.1278e1b3
Merge pull request #71 from reviewdog/depup/reviewdog0001bab
chore(deps): update reviewdog to 0.19.0Updates
reviewdog/action-alex
from 1.11.0 to 1.13.0Release notes
Sourced from reviewdog/action-alex's releases.
Commits
f95df9e
Merge pull request #31 from reviewdog/depup/reviewdog210bba4
chore(deps): update reviewdog to 0.20.195457e9
Merge pull request #30 from reviewdog/depup/reviewdog666fe69
chore(deps): update reviewdog to 0.19.0Updates
reviewdog/action-markdownlint
from 0.22.0 to 0.24.0Release notes
Sourced from reviewdog/action-markdownlint's releases.
Commits
e9f3ab4
Merge pull request #63 from reviewdog/depup/reviewdoge9244ae
chore(deps): update reviewdog to 0.20.1af20b94
Merge pull request #62 from reviewdog/depup/reviewdoge8a161f
chore(deps): update reviewdog to 0.19.0Updates
reviewdog/action-actionlint
from 1.51.0 to 1.54.0Release notes
Sourced from reviewdog/action-actionlint's releases.
Commits
4f8f996
bump v1.54.06ffd884
Merge branch 'main' into releases/v1eaf7d6d
Merge pull request #138 from reviewdog/depup/reviewdog6c0e341
chore(deps): update reviewdog to 0.20.1d99f1ce
bump v1.53.03a6247a
Merge branch 'main' into releases/v104a55cd
Merge pull request #137 from reviewdog/depup/reviewdog106246d
chore(deps): update reviewdog to 0.20.06fce89c
bump v1.52.0f49e824
Merge branch 'main' into releases/v1Updates
actions/upload-artifact
from 4.3.3 to 4.3.4Release notes
Sourced from actions/upload-artifact's releases.
Commits
0b2256b
Merge pull request #584 from actions/robherley/bump-pkgs488dcef
licensed cache04c51f5
ncc32a9e27
bump@actions/artifact
and npm audit552bf37
new version79616d2
Merge pull request #565 from actions/eggyhead/use-artifact-v2.1.6Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions