Skip to content

Commit 7abb091

Browse files
chore(deps): bump the actions group across 1 directory with 19 updates
Bumps the actions group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `6.0.2` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.5.0` | `6.3.0` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `8.0.0` | `9.2.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.4.3` | `5.5.2` | | [hashicorp/setup-terraform](https://github.com/hashicorp/setup-terraform) | `3.1.2` | `4.0.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `8.0.0` | | [peter-evans/find-comment](https://github.com/peter-evans/find-comment) | `3.1.0` | `4.0.0` | | [peter-evans/create-or-update-comment](https://github.com/peter-evans/create-or-update-comment) | `4.0.0` | `5.0.0` | | [actions/github-script](https://github.com/actions/github-script) | `7.0.1` | `8.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.29.2` | `4.32.4` | | [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) | `5.5.3` | `6.1.1` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.3.0` | `7.0.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `2.4.0` | `4.1.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.3.2` | `2.5.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.90.1` | `3.93.6` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `77137e9dc3ab1b329b7c8a38c2eb7475850a14e8` | `97e0b3872f55f89b95b2f65b3dbab56962816478` | | [securego/gosec](https://github.com/securego/gosec) | `59ae7e9e275d7dce03bb9c37432b7b3575dbe5fc` | `6641fcf966593bf52ed426aa262839b340d56375` | | [DavidAnson/markdownlint-cli2-action](https://github.com/davidanson/markdownlint-cli2-action) | `20.0.0` | `22.0.0` | Updates `actions/checkout` from 4.2.2 to 6.0.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...de0fac2) Updates `actions/setup-go` from 5.5.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@d35c59a...4b73464) Updates `golangci/golangci-lint-action` from 8.0.0 to 9.2.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@4afd733...1e7e51e) Updates `actions/upload-artifact` from 4.6.2 to 7.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...bbbca2d) Updates `codecov/codecov-action` from 5.4.3 to 5.5.2 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@18283e0...671740a) Updates `hashicorp/setup-terraform` from 3.1.2 to 4.0.0 - [Release notes](https://github.com/hashicorp/setup-terraform/releases) - [Changelog](https://github.com/hashicorp/setup-terraform/blob/main/CHANGELOG.md) - [Commits](hashicorp/setup-terraform@b9cd54a...5e8dbf3) Updates `actions/download-artifact` from 4.3.0 to 8.0.0 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@d3f86a1...70fc10c) Updates `peter-evans/find-comment` from 3.1.0 to 4.0.0 - [Release notes](https://github.com/peter-evans/find-comment/releases) - [Commits](peter-evans/find-comment@3eae4d3...b30e6a3) Updates `peter-evans/create-or-update-comment` from 4.0.0 to 5.0.0 - [Release notes](https://github.com/peter-evans/create-or-update-comment/releases) - [Commits](peter-evans/create-or-update-comment@71345be...e8674b0) Updates `actions/github-script` from 7.0.1 to 8.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@60a0d83...ed59741) Updates `github/codeql-action` from 3.29.2 to 4.32.4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@181d5ee...89a39a4) Updates `amannn/action-semantic-pull-request` from 5.5.3 to 6.1.1 - [Release notes](https://github.com/amannn/action-semantic-pull-request/releases) - [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md) - [Commits](amannn/action-semantic-pull-request@0723387...48f2562) Updates `goreleaser/goreleaser-action` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@9c156ee...ec59f47) Updates `actions/attest-build-provenance` from 2.4.0 to 4.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@e8998f9...a2bbfa2) Updates `softprops/action-gh-release` from 2.3.2 to 2.5.0 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@72f2c25...a06a81a) Updates `trufflesecurity/trufflehog` from 3.90.1 to 3.93.6 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@907ac64...041f07e) Updates `aquasecurity/trivy-action` from 77137e9dc3ab1b329b7c8a38c2eb7475850a14e8 to 97e0b3872f55f89b95b2f65b3dbab56962816478 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@77137e9...97e0b38) Updates `securego/gosec` from 59ae7e9e275d7dce03bb9c37432b7b3575dbe5fc to 6641fcf966593bf52ed426aa262839b340d56375 - [Release notes](https://github.com/securego/gosec/releases) - [Commits](securego/gosec@59ae7e9...6641fcf) Updates `DavidAnson/markdownlint-cli2-action` from 20.0.0 to 22.0.0 - [Release notes](https://github.com/davidanson/markdownlint-cli2-action/releases) - [Commits](DavidAnson/markdownlint-cli2-action@992badc...07035fd) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-go dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: golangci/golangci-lint-action dependency-version: 9.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: codecov/codecov-action dependency-version: 5.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: hashicorp/setup-terraform dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/download-artifact dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: peter-evans/find-comment dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: peter-evans/create-or-update-comment dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: github/codeql-action dependency-version: 4.32.4 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: amannn/action-semantic-pull-request dependency-version: 6.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: goreleaser/goreleaser-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/attest-build-provenance dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: softprops/action-gh-release dependency-version: 2.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.93.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: aquasecurity/trivy-action dependency-version: 97e0b3872f55f89b95b2f65b3dbab56962816478 dependency-type: direct:production dependency-group: actions - dependency-name: securego/gosec dependency-version: 6641fcf966593bf52ed426aa262839b340d56375 dependency-type: direct:production dependency-group: actions - dependency-name: DavidAnson/markdownlint-cli2-action dependency-version: 22.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent a13a0c6 commit 7abb091

File tree

9 files changed

+52
-52
lines changed

9 files changed

+52
-52
lines changed

.github/workflows/ci.yml

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
scripts: ${{ steps.filter.outputs.scripts }}
2626
steps:
2727
- name: Checkout code
28-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
28+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
2929

3030
- name: Check for file changes
3131
uses: dorny/paths-filter@v3
@@ -48,10 +48,10 @@ jobs:
4848
if: needs.changes.outputs.go == 'true'
4949
steps:
5050
- name: Checkout code
51-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
51+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
5252

5353
- name: Set up Go
54-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
54+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
5555
with:
5656
go-version: ${{ env.GO_VERSION }}
5757
cache: true
@@ -72,7 +72,7 @@ jobs:
7272
7373
- name: Run golangci-lint
7474
if: steps.filter.outputs.go == 'true'
75-
uses: golangci/golangci-lint-action@4afd733a84b1f43292c63897423277bb7f4313a9 # v8
75+
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9.2.0
7676
with:
7777
version: ${{ env.GOLANGCI_LINT_VERSION }}
7878

@@ -92,10 +92,10 @@ jobs:
9292
if: needs.changes.outputs.go == 'true'
9393
steps:
9494
- name: Checkout code
95-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
95+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
9696

9797
- name: Set up Go
98-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
98+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
9999
with:
100100
go-version: "1.24"
101101
cache: true
@@ -111,14 +111,14 @@ jobs:
111111
gotestsum --junitfile junit.xml --format testname -- -v -cover -coverprofile=coverage.out ./internal/...
112112
113113
- name: Upload test results
114-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
114+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
115115
if: always()
116116
with:
117117
name: test-results
118118
path: junit.xml
119119

120120
- name: Upload coverage reports
121-
uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5
121+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5
122122
if: matrix.go-version == env.GO_VERSION
123123
with:
124124
token: ${{ secrets.CODECOV_TOKEN }}
@@ -136,10 +136,10 @@ jobs:
136136
if: needs.changes.outputs.go == 'true'
137137
steps:
138138
- name: Checkout code
139-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
139+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
140140

141141
- name: Set up Go
142-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
142+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
143143
with:
144144
go-version: ${{ env.GO_VERSION }}
145145
cache: true
@@ -166,7 +166,7 @@ jobs:
166166
go test -v -timeout 30m -cover -coverprofile=acceptance-coverage.out ./internal/... -tags=acc
167167
168168
- name: Upload acceptance test coverage
169-
uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5
169+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5
170170
with:
171171
token: ${{ secrets.CODECOV_TOKEN }}
172172
slug: Trozz/terraform-provider-pocketid
@@ -191,10 +191,10 @@ jobs:
191191
if: needs.changes.outputs.go == 'true'
192192
steps:
193193
- name: Checkout code
194-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
194+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
195195

196196
- name: Set up Go
197-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
197+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
198198
with:
199199
go-version: ${{ env.GO_VERSION }}
200200
cache: true
@@ -214,7 +214,7 @@ jobs:
214214
cp terraform-provider-pocketid "$PROVIDER_DIR/"
215215
216216
- name: Upload provider artifact
217-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
217+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
218218
with:
219219
name: provider-binary
220220
path: artifact/
@@ -231,15 +231,15 @@ jobs:
231231
terraform-version: ["1.5.7", "1.6.6", "1.7.5", "1.8.5", "1.9.8"]
232232
steps:
233233
- name: Checkout code
234-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
234+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
235235

236236
- name: Setup Terraform ${{ matrix.terraform-version }}
237-
uses: hashicorp/setup-terraform@b9cd54a3c349d3f38e8881555d616ced269862dd # v3
237+
uses: hashicorp/setup-terraform@5e8dbf3c6d9deaf4193ca7a8fb23f2ac83bb6c85 # v4.0.0
238238
with:
239239
terraform_version: ${{ matrix.terraform-version }}
240240

241241
- name: Download provider artifact
242-
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
242+
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
243243
with:
244244
name: provider-binary
245245
path: artifact/
@@ -310,7 +310,7 @@ jobs:
310310
if: always()
311311
steps:
312312
- name: Checkout code
313-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
313+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
314314

315315
- name: Check CI Status
316316
id: check_status
@@ -324,7 +324,7 @@ jobs:
324324

325325
- name: Find Comment
326326
if: always() && github.event_name == 'pull_request'
327-
uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3
327+
uses: peter-evans/find-comment@b30e6a3c0ed37e7c023ccd3f1db5c6c0b0c23aad # v4.0.0
328328
id: fc
329329
with:
330330
issue-number: ${{ github.event.pull_request.number }}
@@ -354,7 +354,7 @@ jobs:
354354
355355
- name: Create or Update PR Comment
356356
if: always() && steps.generate_comment.outputs.should_comment == 'true'
357-
uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4
357+
uses: peter-evans/create-or-update-comment@e8674b075228eee787fea43ef493e45ece1004c9 # v5.0.0
358358
with:
359359
comment-id: ${{ steps.fc.outputs.comment-id }}
360360
issue-number: ${{ github.event.pull_request.number }}

.github/workflows/cleanup-prereleases.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
runs-on: ubuntu-latest
2727
steps:
2828
- name: Cleanup pre-releases
29-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
29+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7
3030
with:
3131
script: |
3232
const { owner, repo } = context.repo;

.github/workflows/codeql.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,16 +24,16 @@ jobs:
2424

2525
steps:
2626
- name: Checkout repository
27-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
27+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2828

2929
- name: Initialize CodeQL
30-
uses: github/codeql-action/init@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
30+
uses: github/codeql-action/init@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
3131
with:
3232
languages: ${{ matrix.language }}
3333
queries: security-extended,security-and-quality
3434

3535
- name: Setup Go
36-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
36+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
3737
with:
3838
go-version-file: 'go.mod'
3939
cache: true
@@ -42,6 +42,6 @@ jobs:
4242
run: go build -v ./...
4343

4444
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
45+
uses: github/codeql-action/analyze@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
4646
with:
4747
category: "/language:${{matrix.language}}"

.github/workflows/contributors.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919

2020
steps:
2121
- name: Checkout repository
22-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
22+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
2323
with:
2424
fetch-depth: 0
2525

.github/workflows/conventional-commits.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
name: Conventional Commits
1414
steps:
1515
- name: Validate PR title follows Conventional Commits
16-
uses: amannn/action-semantic-pull-request@0723387faaf9b38adef4775cd42cfd5155ed6017 # v5
16+
uses: amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # v5
1717
env:
1818
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
1919
with:
@@ -33,7 +33,7 @@ jobs:
3333

3434
- name: Add PR Comment on Failure
3535
if: failure()
36-
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
36+
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7
3737
with:
3838
github-token: ${{ secrets.GITHUB_TOKEN }}
3939
script: |

.github/workflows/pre-release.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
if: github.actor != 'dependabot[bot]'
2121
steps:
2222
- name: Checkout code
23-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
23+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
2424
with:
2525
fetch-depth: 0
2626

@@ -49,7 +49,7 @@ jobs:
4949
5050
- name: Set up Go
5151
if: steps.go_changes.outputs.changed == 'true'
52-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
52+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
5353
with:
5454
go-version: ${{ env.GO_VERSION }}
5555
cache: true
@@ -88,7 +88,7 @@ jobs:
8888
8989
- name: Run GoReleaser (snapshot)
9090
if: steps.go_changes.outputs.changed == 'true'
91-
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6
91+
uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v6
9292
with:
9393
version: latest
9494
args: release --snapshot --skip=sign --clean --skip=validate
@@ -97,22 +97,22 @@ jobs:
9797

9898
- name: Generate pre-release attestations
9999
if: steps.go_changes.outputs.changed == 'true'
100-
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
100+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
101101
with:
102102
subject-path: |
103103
dist/*.zip
104104
dist/*_checksums.txt
105105
106106
- name: Upload artifacts
107107
if: steps.go_changes.outputs.changed == 'true'
108-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
108+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
109109
with:
110110
name: pre-release-artifacts
111111
path: dist/*
112112

113113
- name: Create GitHub pre-release
114114
if: steps.go_changes.outputs.changed == 'true'
115-
uses: softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8 # v2
115+
uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2
116116
with:
117117
name: "Development Build v${{ steps.version.outputs.version }}"
118118
tag_name: "v${{ steps.version.outputs.version }}"

.github/workflows/release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,12 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout
18-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
18+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
1919
with:
2020
fetch-depth: 0
2121

2222
- name: Set up Go
23-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
23+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
2424
with:
2525
go-version-file: "go.mod"
2626
cache: true
@@ -33,7 +33,7 @@ jobs:
3333
passphrase: ${{ secrets.PASSPHRASE }}
3434

3535
- name: Run GoReleaser
36-
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6
36+
uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v6
3737
with:
3838
version: latest
3939
args: release --clean
@@ -43,7 +43,7 @@ jobs:
4343
PASSPHRASE: ${{ secrets.PASSPHRASE }}
4444

4545
- name: Generate release attestations
46-
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
46+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
4747
with:
4848
subject-path: |
4949
dist/*.zip

.github/workflows/security.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -14,13 +14,13 @@ jobs:
1414
continue-on-error: true
1515
steps:
1616
- name: Checkout code
17-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
17+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
1818
with:
1919
fetch-depth: 0 # Required for TruffleHog to scan git history
2020

2121
# Secret scanning
2222
- name: TruffleHog Secret Scan
23-
uses: trufflesecurity/trufflehog@907ac64fd42b18dab2ceba2fda39834d3f8ba7e3 # v3.90.1
23+
uses: trufflesecurity/trufflehog@041f07e9df901a1038a528e5525b0226d04dd5ea # v3.93.6
2424
with:
2525
path: ./
2626
base: ${{ github.event.repository.default_branch }}
@@ -29,7 +29,7 @@ jobs:
2929

3030
# Vulnerability scanning
3131
- name: Run Trivy vulnerability scanner
32-
uses: aquasecurity/trivy-action@77137e9dc3ab1b329b7c8a38c2eb7475850a14e8 # master
32+
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # master
3333
with:
3434
scan-type: "fs"
3535
scan-ref: "."
@@ -39,26 +39,26 @@ jobs:
3939
exit-code: "0" # Don't fail the build
4040

4141
- name: Upload Trivy scan results
42-
uses: github/codeql-action/upload-sarif@181d5eefc20863364f96762470ba6f862bdef56b # v3
42+
uses: github/codeql-action/upload-sarif@89a39a4e59826350b863aa6b6252a07ad50cf83e # v3
4343
if: always()
4444
with:
4545
sarif_file: "trivy-results.sarif"
4646
category: "trivy"
4747

4848
# Go security scanning
4949
- name: Set up Go
50-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5
50+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v5
5151
with:
5252
go-version: "1.24"
5353
cache: true
5454

5555
- name: Run gosec security scanner
56-
uses: securego/gosec@59ae7e9e275d7dce03bb9c37432b7b3575dbe5fc # master
56+
uses: securego/gosec@6641fcf966593bf52ed426aa262839b340d56375 # master
5757
with:
5858
args: "-fmt sarif -out gosec-results.sarif ./..."
5959

6060
- name: Upload gosec results
61-
uses: github/codeql-action/upload-sarif@181d5eefc20863364f96762470ba6f862bdef56b # v3
61+
uses: github/codeql-action/upload-sarif@89a39a4e59826350b863aa6b6252a07ad50cf83e # v3
6262
if: always()
6363
with:
6464
sarif_file: "gosec-results.sarif"

0 commit comments

Comments
 (0)