Skip to content

Commit 9477643

Browse files
chore(deps)(deps): bump the github-actions group across 1 directory with 18 updates
Bumps the github-actions group with 18 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.1` | `2.19.4` | | [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.4.0` | `6.5.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `6.0.0` | `7.0.0` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `9.2.0` | `9.3.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.35.4` | `4.36.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.35.4` | `4.36.2` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.0.0` | `4.1.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.0.0` | `4.1.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.0.0` | `6.1.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.2.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.35.4` | `4.36.2` | | [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.2.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.0` | `4.1.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.0` | `3.0.1` | | [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `6.2.1` | `6.2.3` | | [securego/gosec](https://github.com/securego/gosec) | `2.26.1` | `2.27.1` | | [gitleaks/gitleaks-action](https://github.com/gitleaks/gitleaks-action) | `2.3.9` | `3.0.0` | Updates `step-security/harden-runner` from 2.19.1 to 2.19.4 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a5ad31d...9af89fc) Updates `actions/checkout` from 6.0.2 to 7.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...9c091bb) Updates `actions/setup-go` from 6.4.0 to 6.5.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@4a36011...924ae3a) Updates `codecov/codecov-action` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@57e3a13...fb8b358) Updates `golangci/golangci-lint-action` from 9.2.0 to 9.3.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@1e7e51e...ba0d7d2) Updates `github/codeql-action/init` from 4.35.4 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...8aad20d) Updates `github/codeql-action/analyze` from 4.35.4 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...8aad20d) Updates `docker/setup-qemu-action` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@ce36039...0611638) Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@4d04d5d...d7f5e7f) Updates `docker/metadata-action` from 6.0.0 to 6.1.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@030e881...80c7e94) Updates `docker/build-push-action` from 7.1.0 to 7.2.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@bcafcac...f9f3042) Updates `github/codeql-action/upload-sarif` from 4.35.4 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...8aad20d) Updates `docker/login-action` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@4907a6d...650006c) Updates `actions/attest-build-provenance` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@a2bbfa2...0f67c3f) Updates `softprops/action-gh-release` from 3.0.0 to 3.0.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@b430933...718ea10) Updates `mikepenz/release-changelog-builder-action` from 6.2.1 to 6.2.3 - [Release notes](https://github.com/mikepenz/release-changelog-builder-action/releases) - [Commits](mikepenz/release-changelog-builder-action@bcae711...c9bcd82) Updates `securego/gosec` from 2.26.1 to 2.27.1 - [Release notes](https://github.com/securego/gosec/releases) - [Commits](securego/gosec@4a3bd8a...9e6a984) Updates `gitleaks/gitleaks-action` from 2.3.9 to 3.0.0 - [Release notes](https://github.com/gitleaks/gitleaks-action/releases) - [Commits](gitleaks/gitleaks-action@ff98106...e0c47f4) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 6.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: golangci/golangci-lint-action dependency-version: 9.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: mikepenz/release-changelog-builder-action dependency-version: 6.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: securego/gosec dependency-version: 2.27.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: gitleaks/gitleaks-action dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 3ff9a4e commit 9477643

10 files changed

Lines changed: 74 additions & 74 deletions

File tree

.github/workflows/ci.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,12 @@ jobs:
3030
apps: ${{ steps.apps.outputs.apps }}
3131
steps:
3232
- name: Harden runner
33-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
33+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
3434
with:
3535
egress-policy: audit
3636

3737
- name: Checkout code
38-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
38+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
3939

4040
- name: Filter changed paths
4141
id: filter
@@ -84,15 +84,15 @@ jobs:
8484

8585
steps:
8686
- name: Harden runner
87-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
87+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
8888
with:
8989
egress-policy: audit
9090

9191
- name: Checkout code
92-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
92+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
9393

9494
- name: Set up Go
95-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
95+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
9696
with:
9797
go-version-file: ${{ matrix.app }}/go.mod
9898
cache-dependency-path: ${{ matrix.app }}/go.sum
@@ -111,7 +111,7 @@ jobs:
111111
- name: Upload coverage to Codecov
112112
# Codecov tokens aren't available on fork PRs; skip rather than fail noisily.
113113
if: github.event.pull_request.head.repo.full_name == github.repository || github.event_name != 'pull_request'
114-
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v5
114+
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v5
115115
with:
116116
files: ./${{ matrix.app }}/coverage.out
117117
flags: ${{ matrix.app }}
@@ -136,15 +136,15 @@ jobs:
136136

137137
steps:
138138
- name: Harden runner
139-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
139+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
140140
with:
141141
egress-policy: audit
142142

143143
- name: Checkout code
144-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
144+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
145145

146146
- name: Set up Go
147-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
147+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
148148
with:
149149
go-version-file: ${{ matrix.app }}/go.mod
150150
cache-dependency-path: ${{ matrix.app }}/go.sum
@@ -158,7 +158,7 @@ jobs:
158158
run: templ generate
159159

160160
- name: Run golangci-lint
161-
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9
161+
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9
162162
with:
163163
version: v2.8.0
164164
working-directory: ./${{ matrix.app }}
@@ -181,15 +181,15 @@ jobs:
181181

182182
steps:
183183
- name: Harden runner
184-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
184+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
185185
with:
186186
egress-policy: audit
187187

188188
- name: Checkout code
189-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
189+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
190190

191191
- name: Set up Go
192-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
192+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
193193
with:
194194
go-version-file: ${{ matrix.app }}/go.mod
195195
cache-dependency-path: ${{ matrix.app }}/go.sum

.github/workflows/claude-security-review.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,12 +39,12 @@ jobs:
3939
pull-requests: write # post inline review comments
4040
steps:
4141
- name: Harden runner
42-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
42+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
4343
with:
4444
egress-policy: audit
4545

4646
- name: Checkout code
47-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
47+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
4848
with:
4949
ref: ${{ github.event.pull_request.head.sha || github.sha }}
5050
fetch-depth: 2 # action diffs against the parent commit

.github/workflows/codeql.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -33,23 +33,23 @@ jobs:
3333

3434
steps:
3535
- name: Harden runner
36-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
36+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
3737
with:
3838
egress-policy: audit
3939

4040
- name: Checkout code
41-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
41+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
4242

4343
- name: Set up Go
44-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
44+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
4545
with:
4646
go-version-file: gearbox/go.mod
4747
cache-dependency-path: |
4848
gearbox/go.sum
4949
gearbox-agent/go.sum
5050
5151
- name: Initialize CodeQL
52-
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
52+
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4
5353
with:
5454
languages: ${{ matrix.language }}
5555

@@ -65,6 +65,6 @@ jobs:
6565
run: go build ./...
6666

6767
- name: Perform CodeQL Analysis
68-
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
68+
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4
6969
with:
7070
category: "/language:${{ matrix.language }}"

.github/workflows/dependabot-auto-merge.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
steps:
2222
- name: Harden runner
23-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
23+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
2424
with:
2525
egress-policy: audit
2626

.github/workflows/docker.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -29,12 +29,12 @@ jobs:
2929
apps: ${{ steps.apps.outputs.apps }}
3030
steps:
3131
- name: Harden runner
32-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
32+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
3333
with:
3434
egress-policy: audit
3535

3636
- name: Checkout code
37-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
37+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
3838

3939
- name: Filter changed paths
4040
id: filter
@@ -94,22 +94,22 @@ jobs:
9494

9595
steps:
9696
- name: Harden runner
97-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
97+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
9898
with:
9999
egress-policy: audit
100100

101101
- name: Checkout code
102-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
102+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
103103

104104
- name: Set up QEMU
105-
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
105+
uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0
106106

107107
- name: Set up Docker Buildx
108-
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
108+
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
109109

110110
- name: Extract metadata
111111
id: meta
112-
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
112+
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
113113
with:
114114
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
115115
tags: |
@@ -126,7 +126,7 @@ jobs:
126126
# incremental cost of the second build is essentially zero.
127127
- name: Build image for scan
128128
id: scan-build
129-
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v6
129+
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v6
130130
with:
131131
context: ./${{ matrix.app }}
132132
push: false
@@ -153,15 +153,15 @@ jobs:
153153
exit-code: ${{ github.event_name == 'pull_request' && '0' || '1' }}
154154

155155
- name: Upload Trivy results to GitHub Security
156-
uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
156+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4
157157
if: always()
158158
with:
159159
sarif_file: 'trivy-image-results.sarif'
160160
category: trivy-docker-${{ matrix.app }}
161161

162162
- name: Log in to Container Registry
163163
if: github.event_name != 'pull_request'
164-
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
164+
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
165165
with:
166166
registry: ${{ env.REGISTRY }}
167167
username: ${{ github.actor }}
@@ -172,7 +172,7 @@ jobs:
172172
- name: Build and push (multi-platform)
173173
id: push
174174
if: github.event_name != 'pull_request'
175-
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v6
175+
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v6
176176
with:
177177
context: ./${{ matrix.app }}
178178
push: true
@@ -188,7 +188,7 @@ jobs:
188188

189189
- name: Generate artifact attestation
190190
if: github.event_name != 'pull_request' && !github.event.repository.private
191-
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
191+
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
192192
with:
193193
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
194194
subject-digest: ${{ steps.push.outputs.digest }}

.github/workflows/labeler.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,12 @@ jobs:
2020

2121
steps:
2222
- name: Harden runner
23-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
23+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
2424
with:
2525
egress-policy: audit
2626

2727
- name: Checkout code
28-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
28+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
2929

3030
- name: Label PR based on changed paths
3131
uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0

.github/workflows/monthly-release.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,12 +31,12 @@ jobs:
3131

3232
steps:
3333
- name: Harden runner
34-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
34+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
3535
with:
3636
egress-policy: audit
3737

3838
- name: Checkout code
39-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
39+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
4040
with:
4141
fetch-depth: 0
4242

@@ -128,7 +128,7 @@ jobs:
128128
129129
- name: Create GitHub Release
130130
if: steps.changes.outputs.has_changes == 'true'
131-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
131+
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2
132132
with:
133133
tag_name: ${{ steps.version.outputs.VERSION }}
134134
name: ${{ steps.version.outputs.VERSION }} (Monthly)

.github/workflows/release.yml

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -25,25 +25,25 @@ jobs:
2525

2626
steps:
2727
- name: Harden runner
28-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
28+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
2929
with:
3030
egress-policy: audit
3131

3232
- name: Checkout code
33-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
33+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
3434
with:
3535
fetch-depth: 0
3636

3737
- name: Generate changelog
3838
id: changelog
39-
uses: mikepenz/release-changelog-builder-action@bcae7115752d4ed746ff92feb666574428a79415 # v6
39+
uses: mikepenz/release-changelog-builder-action@c9bcd8238b6f41e05561348339429d360b1c0247 # v6
4040
with:
4141
configuration: ".github/changelog-config.json"
4242
env:
4343
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
4444

4545
- name: Create Release
46-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
46+
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2
4747
with:
4848
body: ${{ steps.changelog.outputs.changelog }}
4949
draft: false
@@ -73,15 +73,15 @@ jobs:
7373

7474
steps:
7575
- name: Harden runner
76-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
76+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
7777
with:
7878
egress-policy: audit
7979

8080
- name: Checkout code
81-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
81+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
8282

8383
- name: Set up Go
84-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
84+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
8585
with:
8686
go-version-file: gearbox/go.mod
8787
cache-dependency-path: gearbox/go.sum
@@ -124,12 +124,12 @@ jobs:
124124
fi
125125
126126
- name: Generate build provenance attestation
127-
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
127+
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
128128
with:
129129
subject-path: gearbox/bin/*
130130

131131
- name: Upload release assets
132-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
132+
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2
133133
with:
134134
files: |
135135
gearbox/bin/*
@@ -155,15 +155,15 @@ jobs:
155155

156156
steps:
157157
- name: Harden runner
158-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
158+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
159159
with:
160160
egress-policy: audit
161161

162162
- name: Checkout code
163-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
163+
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
164164

165165
- name: Set up Go
166-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
166+
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
167167
with:
168168
go-version-file: gearbox-agent/go.mod
169169
cache-dependency-path: gearbox-agent/go.sum
@@ -201,12 +201,12 @@ jobs:
201201
cd ..
202202
203203
- name: Generate build provenance attestation
204-
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
204+
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
205205
with:
206206
subject-path: gearbox-agent/bin/*
207207

208208
- name: Upload release assets
209-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
209+
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2
210210
with:
211211
files: |
212212
gearbox-agent/bin/*
@@ -223,7 +223,7 @@ jobs:
223223

224224
steps:
225225
- name: Harden runner
226-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
226+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2
227227
with:
228228
egress-policy: audit
229229

@@ -258,7 +258,7 @@ jobs:
258258
done
259259
260260
- name: Upload checksums, signature, and SBOMs
261-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
261+
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2
262262
with:
263263
files: |
264264
assets/checksums.txt

0 commit comments

Comments
 (0)