generated from sigstore/sigstore-project-template
-
Notifications
You must be signed in to change notification settings - Fork 60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): Bump the minor-patch group across 1 directory with 13 updates #1814
Open
dependabot
wants to merge
1
commit into
main
Choose a base branch
from
dependabot/github_actions/minor-patch-a20ff97b3b
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…dates Bumps the minor-patch group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.7.0` | `3.8.1` | | [ko-build/setup-ko](https://github.com/ko-build/setup-ko) | `0.7` | `0.8` | | [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.7` | `2.1.8` | | [actions/cache](https://github.com/actions/cache) | `4.2.0` | `4.2.3` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.27.9` | `3.28.13` | | [mikefarah/yq](https://github.com/mikefarah/yq) | `4.44.6` | `4.45.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.17.9` | `0.18.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.1.0` | `6.3.0` | | [google-github-actions/setup-gcloud](https://github.com/google-github-actions/setup-gcloud) | `2.1.2` | `2.1.4` | | [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) | `2.0.0` | `2.1.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.3` | `4.6.2` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.1.1` | `5.4.0` | Updates `sigstore/cosign-installer` from 3.7.0 to 3.8.1 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@dc72c7d...d7d6bc7) Updates `ko-build/setup-ko` from 0.7 to 0.8 - [Release notes](https://github.com/ko-build/setup-ko/releases) - [Commits](ko-build/setup-ko@3aebd05...d982fec) Updates `google-github-actions/auth` from 2.1.7 to 2.1.8 - [Release notes](https://github.com/google-github-actions/auth/releases) - [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md) - [Commits](google-github-actions/auth@6fc4af4...71f9864) Updates `actions/cache` from 4.2.0 to 4.2.3 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@1bd1e32...5a3ec84) Updates `github/codeql-action` from 3.27.9 to 3.28.13 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@df409f7...1b549b9) Updates `mikefarah/yq` from 4.44.6 to 4.45.1 - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@4839dbb...8bf425b) Updates `anchore/sbom-action` from 0.17.9 to 0.18.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@df80a98...f325610) Updates `goreleaser/goreleaser-action` from 6.1.0 to 6.3.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@9ed2f89...9c156ee) Updates `google-github-actions/setup-gcloud` from 2.1.2 to 2.1.4 - [Release notes](https://github.com/google-github-actions/setup-gcloud/releases) - [Changelog](https://github.com/google-github-actions/setup-gcloud/blob/main/CHANGELOG.md) - [Commits](google-github-actions/setup-gcloud@6189d56...77e7a55) Updates `slsa-framework/slsa-github-generator` from 2.0.0 to 2.1.0 - [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases) - [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md) - [Commits](slsa-framework/slsa-github-generator@v2.0.0...v2.1.0) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.1 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@62b2cac...f49aabe) Updates `actions/upload-artifact` from 4.4.3 to 4.6.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b4b15b8...ea165f8) Updates `codecov/codecov-action` from 5.1.1 to 5.4.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@7f8b4b4...0565863) --- updated-dependencies: - dependency-name: sigstore/cosign-installer dependency-version: 3.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: ko-build/setup-ko dependency-version: '0.8' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: google-github-actions/auth dependency-version: 2.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: actions/cache dependency-version: 4.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: github/codeql-action dependency-version: 3.28.13 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: mikefarah/yq dependency-version: 4.45.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: anchore/sbom-action dependency-version: 0.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: goreleaser/goreleaser-action dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: google-github-actions/setup-gcloud dependency-version: 2.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: slsa-framework/slsa-github-generator dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: ossf/scorecard-action dependency-version: 2.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-patch - dependency-name: actions/upload-artifact dependency-version: 4.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch - dependency-name: codecov/codecov-action dependency-version: 5.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the minor-patch group with 13 updates in the / directory:
3.7.0
3.8.1
0.7
0.8
2.1.7
2.1.8
4.2.0
4.2.3
3.27.9
3.28.13
4.44.6
4.45.1
0.17.9
0.18.0
6.1.0
6.3.0
2.1.2
2.1.4
2.0.0
2.1.0
2.4.0
2.4.1
4.4.3
4.6.2
5.1.1
5.4.0
Updates
sigstore/cosign-installer
from 3.7.0 to 3.8.1Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
d7d6bc7
use cosign 2.4.3 and other updates (#182)c56c2d3
Bump actions/setup-go from 5.2.0 to 5.3.0 (#180)02e36b8
bump for cosign v2.4.2 release (#181)789d288
test action against all non-rc releases, verify entry in rekor log (#179)e11c089
Bump actions/setup-go from 5.1.0 to 5.2.0 (#178)718228a
Bump actions/setup-go from 5.0.2 to 5.1.0 (#176)325063e
Bump actions/checkout from 4.2.1 to 4.2.2 (#177)b929758
Bump actions/checkout from 4.2.0 to 4.2.1 (#175)Updates
ko-build/setup-ko
from 0.7 to 0.8Release notes
Sourced from ko-build/setup-ko's releases.
Commits
d982fec
Merge pull request #42 from ko-build/imjasonh-patch-3d9a259d
install without sudo3eacfb1
Merge pull request #41 from ko-build/imjasonh-patch-2bc1d28d
Update use-action.yaml6f2a060
Merge pull request #40 from ko-build/imjasonh-patch-279f378f
Update use-action.yaml913b299
Update use-action.yaml92449d1
ci: test on arm2a5f936
Merge pull request #29 from hsblhsn/maind632f4f
Update ci.yamlUpdates
google-github-actions/auth
from 2.1.7 to 2.1.8Release notes
Sourced from google-github-actions/auth's releases.
Commits
71f9864
Release: v2.1.8 (#467)0cd8f2e
Update deps (#466)332e0ba
security: bump undici from 5.28.4 to 5.28.5 in the npm_and_yarn group (#463)28d44ba
fix: add runs-on to README.md example (#460)83354ca
Update TROUBLESHOOTING.md (#457)Updates
actions/cache
from 4.2.0 to 4.2.3Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
5a3ec84
Merge pull request #1577 from salmanmkc/salmanmkc/4-test7de2102
Update releases.md76d40dd
Update to use the latest version of the cache package to obfuscate the SAS76dd5eb
update cache with main8c80c27
new package45cfd0e
updatesedd449b
updated cache with latest changes0576707
latest test before pr3105dc9
update9450d42
maskUpdates
github/codeql-action
from 3.27.9 to 3.28.13Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
1b549b9
Merge pull request #2819 from github/update-v3.28.13-e0ea1410282630c8
Update changelog for v3.28.13e0ea141
Merge pull request #2818 from github/cklin/empty-pr-diff-rangeb361a91
Diff-informed analysis: fix empty PR handlingbd1d9ab
Merge pull request #2816 from github/cklin/overlay-file-listb98ae6c
Add overlay-database-utils tests9825184
Add getFileOidsUnderPath() testsac67cff
Merge pull request #2817 from github/cklin/default-setup-diff-informed9c674ba
build: refresh js filesd109dd5
Detect PR branches for Default SetupUpdates
mikefarah/yq
from 4.44.6 to 4.45.1Release notes
Sourced from mikefarah/yq's releases.
Changelog
Sourced from mikefarah/yq's changelog.
... (truncated)
Commits
8bf425b
Bumping versionf755755
Updated release notes0f390b2
Bumping goccy31ad7fb
Bump github.com/magiconair/properties from 1.8.7 to 1.8.9566cf82
Bump github.com/goccy/go-json from 0.10.3 to 0.10.42c9f833
Bump github.com/elliotchance/orderedmap from 1.7.0 to 1.7.1c02d44d
Bump golang.org/x/net from 0.32.0 to 0.33.0f73c862
feat: Create parent directories if --split-exp is used.294a170
Bumping versionUpdates
anchore/sbom-action
from 0.17.9 to 0.18.0Release notes
Sourced from anchore/sbom-action's releases.
Commits
f325610
chore(deps): bump peter-evans/create-pull-request from 7.0.5 to 7.0.6 (#511)83a99f5
chore(deps): bump release-drafter/release-drafter from 6.0.0 to 6.1.0 (#512)9af714f
chore(deps): update Syft to v1.19.0 (#513)Updates
goreleaser/goreleaser-action
from 6.1.0 to 6.3.0Release notes
Sourced from goreleaser/goreleaser-action's releases.
Commits
9c156ee
ci: update bake-action to v6 (#493)73c477b
chore(deps): bump undici from 5.28.3 to 5.28.5 (#488)19c00a9
chore(deps): bump codecov/codecov-action from 4 to 5 (#481)90a3faa
chore(deps): bake vendor0262998
test: fixes450d3a4
test: fix configs25b92ab
chore(deps): update semver and tool-cachebc0ac76
chore(deps): update actions842e7cc
feat: update for goreleaser v2.7d28c982
chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 (#482)Updates
google-github-actions/setup-gcloud
from 2.1.2 to 2.1.4Release notes
Sourced from google-github-actions/setup-gcloud's releases.
Commits
77e7a55
Release: v2.1.4 (#707)334c690
Revert to pinned release workflows (#706)4111bea
Release: v2.1.3 (#705)0c0751a
Update deps (#704)ae61ebc
security: bump undici from 5.28.4 to 5.28.5 in the npm_and_yarn group (#703)25043b0
Allow manually running integration tests with workflow_dispatch (#702)Updates
slsa-framework/slsa-github-generator
from 2.0.0 to 2.1.0Release notes
Sourced from slsa-framework/slsa-github-generator's releases.
... (truncated)
Changelog
Sourced from slsa-framework/slsa-github-generator's changelog.
Commits
f7dd8c5
update the ref in the pre-submit0a5124b
fix jq for the sigstore bundlesfbeecf0
update docsf701310
update workflows3618598
v2.1.0-rc.346f81fc
chore: update refs to v2.1.0-rc.1 (#4120)5d20c93
chore: use builder tag v2.1.0-rc.0 (#4118)e27b237
chore: braces and ejs vulns (#4116)8967e1c
chore: Update CODEOWNERS (#4115)47d1954
chore: update octokit deps (#4114)Updates
ossf/scorecard-action
from 2.4.0 to 2.4.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
f49aabe
bump docker to ghcr v2.4.1 (#1478)30a595b
🌱 Bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 (#1515)69ae593
omit vcs info ...Description has been truncated