chore: bump the all group with 8 updates #962
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates the requirements on step-security/harden-runner, github/codeql-action, actions/dependency-review-action, actions/setup-node, actions/cache, actions/setup-go, aquasecurity/trivy-action and ossf/scorecard-action to permit the latest version.
Updates
step-security/harden-runner
from 2.6.0 to 2.6.1Release notes
Sourced from step-security/harden-runner's releases.
Commits
eb238b5
Release v2.6.1 (#356)2579b52
Merge pull request #350 from step-security/dependabot/github_actions/actions/...c11b220
Merge pull request #352 from step-security/dependabot/github_actions/ossf/sco...3338abc
Bump ossf/scorecard-action from 2.3.0 to 2.3.17523e86
Bump actions/checkout from 4.1.0 to 4.1.1bf4cac9
Merge pull request #349 from step-security/dependabot/github_actions/ossf/sco...ab35e30
Bump ossf/scorecard-action from 2.2.0 to 2.3.002adcd6
Merge pull request #348 from step-security/dependabot/github_actions/step-sec...cddb4d2
Bump step-security/harden-runner from 2.5.1 to 2.6.0d7f96b7
Merge pull request #347 from step-security/varunsh-coder-patch-1Updates
github/codeql-action
to cdcdbb579706841c47f7063dda365e292e5cad7aChangelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
Updates
actions/dependency-review-action
from 3.1.4 to 4.0.0Release notes
Sourced from actions/dependency-review-action's releases.
Commits
4901385
bump to 4.0.0dbf82a4
Merge pull request #639 from takost/takost/update-to-node-2078aeb2a
Merge pull request #663 from actions/dependabot/npm_and_yarn/typescript-eslin...4e51000
Bump@typescript-eslint/parser
from 6.18.0 to 6.18.19560737
Merge pull request #661 from actions/dependabot/npm_and_yarn/typescript-eslin...4125f47
Merge pull request #660 from actions/dependabot/npm_and_yarn/types/node-16.18.7007cc93e
Bump@typescript-eslint/eslint-plugin
from 6.18.0 to 6.18.1e2c203b
Bump@types/node
from 16.18.62 to 16.18.70f0b304d
Merge pull request #653 from actions/dependabot/npm_and_yarn/got-14.0.0e41543e
Merge pull request #656 from actions/dependabot/npm_and_yarn/typescript-eslin...Updates
actions/setup-node
from 3.8.1 to 4.0.1Release notes
Sourced from actions/setup-node's releases.
Commits
b39b52d
Fix node-version-file interprets entire package.json as a version (#865)7247617
Addpackage.json
tonode-version-file
list of examples. (#879)f3ec4ca
Fix README.md (#898)ec97f37
Add fix for cache (#917)5ef044f
Update reusable workflows to use Node.js v20 (#889)c45882a
update to setup-node@v4 in docs (#884)ee36e8b
Ignore engines check in Yarn 1 e2e-cache tests (#882)8f152de
Update actions/checkout for documentation and yaml (#876)23755b5
upgrade actions/checkout to v4 (#868)54534a2
Change node version for action to node20 (#866)Updates
actions/cache
from 3.3.2 to 4.0.0Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
13aacd8
Merge pull request #1242 from to-s/main53b35c5
Merge branch 'main' into main65b8989
Merge pull request #1284 from takost/update-to-node-20d0be34d
Fix dist66cf064
Merge branch 'main' into update-to-node-201326563
Merge branch 'main' into maine12d46a
Merge pull request #1302 from actions/robherley/v3.3.31baebfc
licensedeb94f1a
cache v3.3.3e718767
Fix formatUpdates
actions/setup-go
from 4.1.0 to 5.0.0Release notes
Sourced from actions/setup-go's releases.
Commits
0c52d54
Update dependencies for node20 (#445)bfd2fb3
Merge pull request #421 from chenrui333/node20-runtime3d65fa5
feat: bump to use actions/checkout@v48a505c9
feat: bump to use node20 runtime883490d
Merge pull request #417 from artemgavrilov/maind45ebba
Rephrase sentence317c661
Replacewildcards
term withglobs
.f90673a
Merge pull request #1 from artemgavrilov/caching-docs-improvement8018234
Improve documentation regarding dependencies cachind085b4f
Merge pull request #411 from galargh/fix/windows-hostedtoolcacheUpdates
aquasecurity/trivy-action
from 0.12.0 to 0.16.1Release notes
Sourced from aquasecurity/trivy-action's releases.
... (truncated)
Commits
d43c1f1
docs: fix typo in README.md (#293)5f1841d
Update Trivy to 0.48.1 (#291)91713af
Update to trivy version 0.48.0 (#289)22d2755
feature(config): add terraform variable files (#285)2b6a709
Add filesystem alias (#269)47e481a
Update totrivy
version0.47.0
in Dockerfile (#280)7b07fa7
fix: set return code after each Trivy call (#247)f78e9ec
Update Dockerfile to 0.46.1 (#277)b77b85c
Update Dockerfile to 0.46.0 (#274)69cbbc0
fix: mark image-ref attribute optional (#261)Updates
ossf/scorecard-action
from 2.3.0 to 2.3.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
0864cf1
🌱 Bump docker tag to for v2.3.1 release (#1284)72df3bf
🌱 Bump github.com/ossf/scorecard/v4 from v4.13.0 to v4.13.1 (#1282)0ea411f
🌱 Bump the docker-images group with 1 update (#1281)dbfd042
🌱 Bump the github-actions group with 1 update (#1280)2fa1e2f
🌱 Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1278)652ddd0
🌱 Bump github.com/google/go-cmp from 0.5.9 to 0.6.0 (#1277)28d0c92
🌱 Group Dependabot updates for GitHub Actions and Dockerfiles (#1276)cb50491
🌱 Bump distroless/base froma35b652
tob31a6e0
(#1275)87157ac
🌱 Bump github/codeql-action from 2.21.9 to 2.22.1 (#1274)7c1648b
🌱 Bump step-security/harden-runner from 2.5.1 to 2.6.0 (#1273)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions