Skip to content

Commit b3e15dd

Browse files
chore(deps)(deps): bump the github-actions group across 1 directory with 22 updates
Bumps the github-actions group with 22 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.1` | `2.16.1` | | [actions/checkout](https://github.com/actions/checkout) | `6.0.1` | `6.0.2` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.2.0` | `6.4.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.2` | `6.0.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6.0.0` | `7.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.0` | `4.35.1` | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2.5.0` | `3.0.0` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.7.0` | `4.0.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.0.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.10.0` | `6.0.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.18.0` | `7.0.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.30.0` | `0.35.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3.0.0` | `4.1.0` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.0.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.5.0` | `2.6.1` | | [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `6.1.0` | `6.2.0` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.9.1` | `4.1.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.1` | `0.24.0` | | [securego/gosec](https://github.com/securego/gosec) | `2.22.4` | `2.25.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.2.0` | `6.3.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.2` | `4.9.0` | Updates `step-security/harden-runner` from 2.14.1 to 2.16.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@e3f713f...fe10465) Updates `actions/checkout` from 6.0.1 to 6.0.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@8e8c483...de0fac2) Updates `actions/setup-go` from 6.2.0 to 6.4.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@7a3fe6c...4a36011) Updates `codecov/codecov-action` from 5.5.2 to 6.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@671740a...57e3a13) Updates `actions/upload-artifact` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b7c566a...bbbca2d) Updates `github/codeql-action` from 4.32.0 to 4.35.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b20883b...c10b806) Updates `dependabot/fetch-metadata` from 2.5.0 to 3.0.0 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@21025c7...ffa630c) Updates `docker/setup-qemu-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@c7c5346...ce36039) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...4d04d5d) Updates `docker/login-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@c94ce9f...b45d80f) Updates `docker/metadata-action` from 5.10.0 to 6.0.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@c299e40...030e881) Updates `docker/build-push-action` from 6.18.0 to 7.0.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@2634353...d08e5c3) Updates `aquasecurity/trivy-action` from 0.30.0 to 0.35.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@6c175e9...57a97c7) Updates `actions/attest-build-provenance` from 3.0.0 to 4.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@977bb37...a2bbfa2) Updates `actions/labeler` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...634933e) Updates `softprops/action-gh-release` from 2.5.0 to 2.6.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@a06a81a...153bb8e) Updates `mikepenz/release-changelog-builder-action` from 6.1.0 to 6.2.0 - [Release notes](https://github.com/mikepenz/release-changelog-builder-action/releases) - [Commits](mikepenz/release-changelog-builder-action@6faf020...2cb9bef) Updates `sigstore/cosign-installer` from 3.9.1 to 4.1.1 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@398d4b0...cad07c2) Updates `anchore/sbom-action` from 0.22.1 to 0.24.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@deef08a...e22c389) Updates `securego/gosec` from 2.22.4 to 2.25.0 - [Release notes](https://github.com/securego/gosec/releases) - [Commits](securego/gosec@6decf96...223e19b) Updates `actions/setup-node` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@6044e13...53b8394) Updates `actions/dependency-review-action` from 4.8.2 to 4.9.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@3c4e3dc...2031cfc) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.16.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.35.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dependabot/fetch-metadata dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: aquasecurity/trivy-action dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 2.6.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: mikepenz/release-changelog-builder-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: sigstore/cosign-installer dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: securego/gosec dependency-version: 2.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 0a31b56 commit b3e15dd

11 files changed

Lines changed: 98 additions & 98 deletions

File tree

.github/workflows/ci-agent.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -26,15 +26,15 @@ jobs:
2626

2727
steps:
2828
- name: Harden runner
29-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
29+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
3030
with:
3131
egress-policy: audit
3232

3333
- name: Checkout code
34-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
34+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
3535

3636
- name: Set up Go
37-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
37+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
3838
with:
3939
go-version-file: gearbox-agent/go.mod
4040
cache-dependency-path: gearbox-agent/go.sum
@@ -46,7 +46,7 @@ jobs:
4646
run: go test -v -race -coverprofile=coverage.out ./...
4747

4848
- name: Upload coverage to Codecov
49-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5
49+
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v5
5050
with:
5151
files: ./gearbox-agent/coverage.out
5252
flags: agent-unittests
@@ -65,15 +65,15 @@ jobs:
6565

6666
steps:
6767
- name: Harden runner
68-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
68+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
6969
with:
7070
egress-policy: audit
7171

7272
- name: Checkout code
73-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
73+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
7474

7575
- name: Set up Go
76-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
76+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
7777
with:
7878
go-version-file: gearbox-agent/go.mod
7979
cache-dependency-path: gearbox-agent/go.sum
@@ -97,15 +97,15 @@ jobs:
9797

9898
steps:
9999
- name: Harden runner
100-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
100+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
101101
with:
102102
egress-policy: audit
103103

104104
- name: Checkout code
105-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
105+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
106106

107107
- name: Set up Go
108-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
108+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
109109
with:
110110
go-version-file: gearbox-agent/go.mod
111111
cache-dependency-path: gearbox-agent/go.sum
@@ -121,7 +121,7 @@ jobs:
121121
./cmd/gearbox-agent
122122
123123
- name: Upload binary artifact
124-
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6
124+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
125125
with:
126126
name: gearbox-agent-${{ github.sha }}
127127
path: gearbox-agent/bin/gearbox-agent

.github/workflows/ci.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -26,15 +26,15 @@ jobs:
2626

2727
steps:
2828
- name: Harden runner
29-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
29+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
3030
with:
3131
egress-policy: audit
3232

3333
- name: Checkout code
34-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
34+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
3535

3636
- name: Set up Go
37-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
37+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
3838
with:
3939
go-version-file: gearbox/go.mod
4040
cache-dependency-path: gearbox/go.sum
@@ -52,7 +52,7 @@ jobs:
5252
run: go test -v -race -coverprofile=coverage.out ./...
5353

5454
- name: Upload coverage to Codecov
55-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5
55+
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v5
5656
with:
5757
files: ./gearbox/coverage.out
5858
flags: unittests
@@ -71,15 +71,15 @@ jobs:
7171

7272
steps:
7373
- name: Harden runner
74-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
74+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
7575
with:
7676
egress-policy: audit
7777

7878
- name: Checkout code
79-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
79+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
8080

8181
- name: Set up Go
82-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
82+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
8383
with:
8484
go-version-file: gearbox/go.mod
8585
cache-dependency-path: gearbox/go.sum
@@ -109,15 +109,15 @@ jobs:
109109

110110
steps:
111111
- name: Harden runner
112-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
112+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
113113
with:
114114
egress-policy: audit
115115

116116
- name: Checkout code
117-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
117+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
118118

119119
- name: Set up Go
120-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
120+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
121121
with:
122122
go-version-file: gearbox/go.mod
123123
cache-dependency-path: gearbox/go.sum
@@ -146,7 +146,7 @@ jobs:
146146
./cmd/server
147147
148148
- name: Upload binary artifact
149-
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6
149+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
150150
with:
151151
name: gearbox-${{ github.sha }}
152152
path: gearbox/bin/gearbox

.github/workflows/codeql.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,23 +26,23 @@ jobs:
2626

2727
steps:
2828
- name: Harden runner
29-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
29+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
3030
with:
3131
egress-policy: audit
3232

3333
- name: Checkout code
34-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
34+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
3535

3636
- name: Set up Go
37-
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6
37+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
3838
with:
3939
go-version-file: gearbox/go.mod
4040
cache-dependency-path: |
4141
gearbox/go.sum
4242
gearbox-agent/go.sum
4343
4444
- name: Initialize CodeQL
45-
uses: github/codeql-action/init@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
45+
uses: github/codeql-action/init@c10b8064de6f491fea524254123dbe5e09572f13 # v4
4646
with:
4747
languages: ${{ matrix.language }}
4848

@@ -58,6 +58,6 @@ jobs:
5858
run: go build ./...
5959

6060
- name: Perform CodeQL Analysis
61-
uses: github/codeql-action/analyze@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
61+
uses: github/codeql-action/analyze@c10b8064de6f491fea524254123dbe5e09572f13 # v4
6262
with:
6363
category: "/language:${{ matrix.language }}"

.github/workflows/dependabot-auto-merge.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,13 +16,13 @@ jobs:
1616

1717
steps:
1818
- name: Harden runner
19-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
19+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
2020
with:
2121
egress-policy: audit
2222

2323
- name: Fetch Dependabot metadata
2424
id: metadata
25-
uses: dependabot/fetch-metadata@21025c705c08248db411dc16f3619e6b5f9ea21a # v2
25+
uses: dependabot/fetch-metadata@ffa630c65fa7e0ecfa0625b5ceda64399aea1b36 # v2
2626
with:
2727
github-token: "${{ secrets.GITHUB_TOKEN }}"
2828

.github/workflows/docker-agent.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -33,30 +33,30 @@ jobs:
3333

3434
steps:
3535
- name: Harden runner
36-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
36+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
3737
with:
3838
egress-policy: audit
3939

4040
- name: Checkout code
41-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
41+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
4242

4343
- name: Set up QEMU
44-
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
44+
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
4545

4646
- name: Set up Docker Buildx
47-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
47+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
4848

4949
- name: Log in to Container Registry
5050
if: github.event_name != 'pull_request'
51-
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
51+
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
5252
with:
5353
registry: ${{ env.REGISTRY }}
5454
username: ${{ github.actor }}
5555
password: ${{ secrets.GITHUB_TOKEN }}
5656

5757
- name: Extract metadata
5858
id: meta
59-
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
59+
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
6060
with:
6161
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
6262
tags: |
@@ -70,7 +70,7 @@ jobs:
7070
7171
- name: Build and push Docker image
7272
id: build
73-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
73+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v6
7474
with:
7575
context: ./gearbox-agent
7676
push: ${{ github.event_name != 'pull_request' }}
@@ -86,7 +86,7 @@ jobs:
8686
load: false
8787

8888
- name: Build single-platform image for scanning
89-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
89+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v6
9090
with:
9191
context: ./gearbox-agent
9292
push: false
@@ -99,23 +99,23 @@ jobs:
9999
BUILD_DATE=${{ github.event.repository.updated_at }}
100100
101101
- name: Run Trivy image scan
102-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30.0
102+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0
103103
with:
104104
image-ref: gearbox-agent:scan
105105
format: 'sarif'
106106
output: 'trivy-image-results.sarif'
107107
severity: 'CRITICAL,HIGH'
108108

109109
- name: Upload Trivy results to GitHub Security
110-
uses: github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
110+
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v4
111111
if: always()
112112
with:
113113
sarif_file: 'trivy-image-results.sarif'
114114
category: trivy-docker-agent
115115

116116
- name: Generate artifact attestation
117117
if: github.event_name != 'pull_request' && !github.event.repository.private
118-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3
118+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
119119
with:
120120
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
121121
subject-digest: ${{ steps.build.outputs.digest }}

.github/workflows/docker.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -33,30 +33,30 @@ jobs:
3333

3434
steps:
3535
- name: Harden runner
36-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
36+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
3737
with:
3838
egress-policy: audit
3939

4040
- name: Checkout code
41-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
41+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
4242

4343
- name: Set up QEMU
44-
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
44+
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
4545

4646
- name: Set up Docker Buildx
47-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
47+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
4848

4949
- name: Log in to Container Registry
5050
if: github.event_name != 'pull_request'
51-
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
51+
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
5252
with:
5353
registry: ${{ env.REGISTRY }}
5454
username: ${{ github.actor }}
5555
password: ${{ secrets.GITHUB_TOKEN }}
5656

5757
- name: Extract metadata
5858
id: meta
59-
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
59+
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
6060
with:
6161
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
6262
tags: |
@@ -70,7 +70,7 @@ jobs:
7070
7171
- name: Build and push Docker image
7272
id: build
73-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
73+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v6
7474
with:
7575
context: ./gearbox
7676
push: ${{ github.event_name != 'pull_request' }}
@@ -86,7 +86,7 @@ jobs:
8686
load: false
8787

8888
- name: Build single-platform image for scanning
89-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
89+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v6
9090
with:
9191
context: ./gearbox
9292
push: false
@@ -99,23 +99,23 @@ jobs:
9999
BUILD_DATE=${{ github.event.repository.updated_at }}
100100
101101
- name: Run Trivy image scan
102-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30.0
102+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0
103103
with:
104104
image-ref: gearbox:scan
105105
format: 'sarif'
106106
output: 'trivy-image-results.sarif'
107107
severity: 'CRITICAL,HIGH'
108108

109109
- name: Upload Trivy results to GitHub Security
110-
uses: github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
110+
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v4
111111
if: always()
112112
with:
113113
sarif_file: 'trivy-image-results.sarif'
114114
category: trivy-docker-gearbox
115115

116116
- name: Generate artifact attestation
117117
if: github.event_name != 'pull_request' && !github.event.repository.private
118-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3
118+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
119119
with:
120120
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
121121
subject-digest: ${{ steps.build.outputs.digest }}

.github/workflows/labeler.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,14 +16,14 @@ jobs:
1616

1717
steps:
1818
- name: Harden runner
19-
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2
19+
uses: step-security/harden-runner@fe104658747b27e96e4f7e80cd0a94068e53901d # v2
2020
with:
2121
egress-policy: audit
2222

2323
- name: Checkout code
24-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
24+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2525

2626
- name: Label PR based on changed paths
27-
uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5
27+
uses: actions/labeler@634933edcd8ababfe52f92936142cc22ac488b1b # v6.0.1
2828
with:
2929
repo-token: "${{ secrets.GITHUB_TOKEN }}"

0 commit comments

Comments
 (0)