Skip to content

Commit c65fe25

Browse files
chore(deps)(deps): bump the github-actions group across 1 directory with 22 updates
Bumps the github-actions group with 22 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.1` | `2.20.0` | | [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.1` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.2` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.4.0` | `7.0.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `6.0.0` | `7.0.0` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `9.2.0` | `9.3.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.35.4` | `4.37.3` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.35.4` | `4.37.3` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.0.0` | `4.2.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.0.0` | `4.2.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.0.0` | `6.2.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.3.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.35.4` | `4.37.3` | | [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.0` | `4.1.1` | | [actions/labeler](https://github.com/actions/labeler) | `6.1.0` | `7.0.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.0` | `3.0.2` | | [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `6.2.1` | `6.2.3` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` | | [securego/gosec](https://github.com/securego/gosec) | `2.26.1` | `2.28.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` | | [gitleaks/gitleaks-action](https://github.com/gitleaks/gitleaks-action) | `2.3.9` | `3.0.0` | Updates `step-security/harden-runner` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a5ad31d...bf7454d) Updates `actions/checkout` from 6.0.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...3d3c42e) Updates `dorny/paths-filter` from 4.0.1 to 4.0.2 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](dorny/paths-filter@fbd0ab8...7b450ff) Updates `actions/setup-go` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@4a36011...b7ad1da) Updates `codecov/codecov-action` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@57e3a13...fb8b358) Updates `golangci/golangci-lint-action` from 9.2.0 to 9.3.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@1e7e51e...ba0d7d2) Updates `github/codeql-action/init` from 4.35.4 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...e4fba86) Updates `github/codeql-action/analyze` from 4.35.4 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...e4fba86) Updates `docker/setup-qemu-action` from 4.0.0 to 4.2.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@ce36039...96fe6ef) Updates `docker/setup-buildx-action` from 4.0.0 to 4.2.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@4d04d5d...bb05f3f) Updates `docker/metadata-action` from 6.0.0 to 6.2.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@030e881...dc80280) Updates `docker/build-push-action` from 7.1.0 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@bcafcac...53b7df9) Updates `github/codeql-action/upload-sarif` from 4.35.4 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...e4fba86) Updates `docker/login-action` from 4.1.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@4907a6d...dbcb813) Updates `actions/attest-build-provenance` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@a2bbfa2...0f67c3f) Updates `actions/labeler` from 6.1.0 to 7.0.0 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@f27b608...bf12e9b) Updates `softprops/action-gh-release` from 3.0.0 to 3.0.2 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@b430933...3d0d988) Updates `mikepenz/release-changelog-builder-action` from 6.2.1 to 6.2.3 - [Release notes](https://github.com/mikepenz/release-changelog-builder-action/releases) - [Commits](mikepenz/release-changelog-builder-action@bcae711...c9bcd82) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@4eaacf0...2d11466) Updates `securego/gosec` from 2.26.1 to 2.28.0 - [Release notes](https://github.com/securego/gosec/releases) - [Commits](securego/gosec@4a3bd8a...9e75c05) Updates `actions/setup-node` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@48b55a0...8207627) Updates `gitleaks/gitleaks-action` from 2.3.9 to 3.0.0 - [Release notes](https://github.com/gitleaks/gitleaks-action/releases) - [Commits](gitleaks/gitleaks-action@ff98106...e0c47f4) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dorny/paths-filter dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: golangci/golangci-lint-action dependency-version: 9.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: mikepenz/release-changelog-builder-action dependency-version: 6.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: securego/gosec dependency-version: 2.28.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: gitleaks/gitleaks-action dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 3ff9a4e commit c65fe25

10 files changed

Lines changed: 79 additions & 79 deletions

File tree

.github/workflows/ci.yml

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -30,16 +30,16 @@ jobs:
3030
apps: ${{ steps.apps.outputs.apps }}
3131
steps:
3232
- name: Harden runner
33-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
33+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
3434
with:
3535
egress-policy: audit
3636

3737
- name: Checkout code
38-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
38+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
3939

4040
- name: Filter changed paths
4141
id: filter
42-
uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
42+
uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
4343
with:
4444
# A change to ci.yml itself rebuilds both apps so we don't ship a
4545
# broken pipeline.
@@ -84,15 +84,15 @@ jobs:
8484

8585
steps:
8686
- name: Harden runner
87-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
87+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
8888
with:
8989
egress-policy: audit
9090

9191
- name: Checkout code
92-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
92+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
9393

9494
- name: Set up Go
95-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
95+
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v6
9696
with:
9797
go-version-file: ${{ matrix.app }}/go.mod
9898
cache-dependency-path: ${{ matrix.app }}/go.sum
@@ -111,7 +111,7 @@ jobs:
111111
- name: Upload coverage to Codecov
112112
# Codecov tokens aren't available on fork PRs; skip rather than fail noisily.
113113
if: github.event.pull_request.head.repo.full_name == github.repository || github.event_name != 'pull_request'
114-
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v5
114+
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v5
115115
with:
116116
files: ./${{ matrix.app }}/coverage.out
117117
flags: ${{ matrix.app }}
@@ -136,15 +136,15 @@ jobs:
136136

137137
steps:
138138
- name: Harden runner
139-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
139+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
140140
with:
141141
egress-policy: audit
142142

143143
- name: Checkout code
144-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
144+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
145145

146146
- name: Set up Go
147-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
147+
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v6
148148
with:
149149
go-version-file: ${{ matrix.app }}/go.mod
150150
cache-dependency-path: ${{ matrix.app }}/go.sum
@@ -158,7 +158,7 @@ jobs:
158158
run: templ generate
159159

160160
- name: Run golangci-lint
161-
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9
161+
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9
162162
with:
163163
version: v2.8.0
164164
working-directory: ./${{ matrix.app }}
@@ -181,15 +181,15 @@ jobs:
181181

182182
steps:
183183
- name: Harden runner
184-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
184+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
185185
with:
186186
egress-policy: audit
187187

188188
- name: Checkout code
189-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
189+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
190190

191191
- name: Set up Go
192-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
192+
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v6
193193
with:
194194
go-version-file: ${{ matrix.app }}/go.mod
195195
cache-dependency-path: ${{ matrix.app }}/go.sum

.github/workflows/claude-security-review.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,12 +39,12 @@ jobs:
3939
pull-requests: write # post inline review comments
4040
steps:
4141
- name: Harden runner
42-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
42+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
4343
with:
4444
egress-policy: audit
4545

4646
- name: Checkout code
47-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
47+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
4848
with:
4949
ref: ${{ github.event.pull_request.head.sha || github.sha }}
5050
fetch-depth: 2 # action diffs against the parent commit

.github/workflows/codeql.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -33,23 +33,23 @@ jobs:
3333

3434
steps:
3535
- name: Harden runner
36-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
36+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
3737
with:
3838
egress-policy: audit
3939

4040
- name: Checkout code
41-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
41+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
4242

4343
- name: Set up Go
44-
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
44+
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v6
4545
with:
4646
go-version-file: gearbox/go.mod
4747
cache-dependency-path: |
4848
gearbox/go.sum
4949
gearbox-agent/go.sum
5050
5151
- name: Initialize CodeQL
52-
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
52+
uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
5353
with:
5454
languages: ${{ matrix.language }}
5555

@@ -65,6 +65,6 @@ jobs:
6565
run: go build ./...
6666

6767
- name: Perform CodeQL Analysis
68-
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
68+
uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
6969
with:
7070
category: "/language:${{ matrix.language }}"

.github/workflows/dependabot-auto-merge.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
steps:
2222
- name: Harden runner
23-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
23+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
2424
with:
2525
egress-policy: audit
2626

.github/workflows/docker.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -29,19 +29,19 @@ jobs:
2929
apps: ${{ steps.apps.outputs.apps }}
3030
steps:
3131
- name: Harden runner
32-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
32+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
3333
with:
3434
egress-policy: audit
3535

3636
- name: Checkout code
37-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
37+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
3838

3939
- name: Filter changed paths
4040
id: filter
4141
# Tag pushes have no base ref to diff against, so always-build is the
4242
# safe default (a tag means we want to release both images).
4343
if: github.event_name != 'push' || github.ref_type != 'tag'
44-
uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
44+
uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
4545
with:
4646
filters: |
4747
gearbox:
@@ -94,22 +94,22 @@ jobs:
9494

9595
steps:
9696
- name: Harden runner
97-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
97+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
9898
with:
9999
egress-policy: audit
100100

101101
- name: Checkout code
102-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
102+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
103103

104104
- name: Set up QEMU
105-
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
105+
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
106106

107107
- name: Set up Docker Buildx
108-
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
108+
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
109109

110110
- name: Extract metadata
111111
id: meta
112-
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
112+
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
113113
with:
114114
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
115115
tags: |
@@ -126,7 +126,7 @@ jobs:
126126
# incremental cost of the second build is essentially zero.
127127
- name: Build image for scan
128128
id: scan-build
129-
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v6
129+
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v6
130130
with:
131131
context: ./${{ matrix.app }}
132132
push: false
@@ -153,15 +153,15 @@ jobs:
153153
exit-code: ${{ github.event_name == 'pull_request' && '0' || '1' }}
154154

155155
- name: Upload Trivy results to GitHub Security
156-
uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
156+
uses: github/codeql-action/upload-sarif@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
157157
if: always()
158158
with:
159159
sarif_file: 'trivy-image-results.sarif'
160160
category: trivy-docker-${{ matrix.app }}
161161

162162
- name: Log in to Container Registry
163163
if: github.event_name != 'pull_request'
164-
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
164+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
165165
with:
166166
registry: ${{ env.REGISTRY }}
167167
username: ${{ github.actor }}
@@ -172,7 +172,7 @@ jobs:
172172
- name: Build and push (multi-platform)
173173
id: push
174174
if: github.event_name != 'pull_request'
175-
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v6
175+
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v6
176176
with:
177177
context: ./${{ matrix.app }}
178178
push: true
@@ -188,7 +188,7 @@ jobs:
188188

189189
- name: Generate artifact attestation
190190
if: github.event_name != 'pull_request' && !github.event.repository.private
191-
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
191+
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
192192
with:
193193
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
194194
subject-digest: ${{ steps.push.outputs.digest }}

.github/workflows/labeler.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,14 +20,14 @@ jobs:
2020

2121
steps:
2222
- name: Harden runner
23-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
23+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
2424
with:
2525
egress-policy: audit
2626

2727
- name: Checkout code
28-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
28+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
2929

3030
- name: Label PR based on changed paths
31-
uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0
31+
uses: actions/labeler@bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13 # v7.0.0
3232
with:
3333
repo-token: "${{ secrets.GITHUB_TOKEN }}"

.github/workflows/monthly-release.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,12 +31,12 @@ jobs:
3131

3232
steps:
3333
- name: Harden runner
34-
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2
34+
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2
3535
with:
3636
egress-policy: audit
3737

3838
- name: Checkout code
39-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
39+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
4040
with:
4141
fetch-depth: 0
4242

@@ -128,7 +128,7 @@ jobs:
128128
129129
- name: Create GitHub Release
130130
if: steps.changes.outputs.has_changes == 'true'
131-
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v2
131+
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v2
132132
with:
133133
tag_name: ${{ steps.version.outputs.VERSION }}
134134
name: ${{ steps.version.outputs.VERSION }} (Monthly)

0 commit comments

Comments
 (0)