Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update github-actions #369

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 24, 2024

This PR contains the following updates:

Package Type Update Change
actions/cache action minor v4.1.1 -> v4.2.2
actions/checkout action patch v4.2.1 -> v4.2.2
actions/download-artifact action patch v4.1.8 -> v4.1.9
actions/setup-java action minor v4.4.0 -> v4.7.0
actions/setup-python action minor v5.2.0 -> v5.4.0
actions/upload-artifact action minor v4.4.3 -> v4.6.1
aquasecurity/trivy-action action minor 0.28.0 -> 0.29.0
docker/build-push-action action minor v6.9.0 -> v6.15.0
docker/metadata-action action minor v5.5.1 -> v5.7.0
docker/setup-buildx-action action minor v3.7.1 -> v3.10.0
ghcr.io/chgl/kube-powertools container patch v2.3.27 -> v2.3.45
ghcr.io/miracum/ig-build-tools container patch v2.1.6 -> v2.1.17
github/codeql-action action minor v3.26.13 -> v3.28.10
googleapis/release-please-action action patch v4.1.3 -> v4.1.4
gradle/actions action minor v4.1.0 -> v4.3.0
helm/kind-action action minor v1.10.0 -> v1.12.0
lycheeverse/lychee-action action minor v2.0.2 -> v2.3.0
ossf/scorecard-action action patch v2.4.0 -> v2.4.1
oxsecurity/megalinter action minor v8.1.0 -> v8.4.2
peter-evans/create-pull-request action patch v7.0.5 -> v7.0.7
sigstore/cosign-installer action minor v3.7.0 -> v3.8.1
slsa-framework/slsa-github-generator action minor v2.0.0 -> v2.1.0
softprops/action-gh-release action minor v2.0.8 -> v2.2.1
yogeshlonkar/trivy-cache-action action patch v0.1.8 -> v0.1.12

Release Notes

actions/cache (actions/cache)

v4.2.2

Compare Source

What's Changed

[!IMPORTANT]
As a reminder, there were important backend changes to release v4.2.0, see those release notes and the announcement for more details.

Full Changelog: actions/cache@v4.2.1...v4.2.2

v4.2.1

Compare Source

What's Changed

[!IMPORTANT]
As a reminder, there were important backend changes to release v4.2.0, see those release notes and the announcement for more details.

New Contributors

Full Changelog: actions/cache@v4.2.0...v4.2.1

v4.2.0

Compare Source

⚠️ Important Changes

The cache backend service has been rewritten from the ground up for improved performance and reliability. actions/cache now integrates with the new cache service (v2) APIs.

The new service will gradually roll out as of February 1st, 2025. The legacy service will also be sunset on the same date. Changes in these release are fully backward compatible.

We are deprecating some versions of this action. We recommend upgrading to version v4 or v3 as soon as possible before February 1st, 2025. (Upgrade instructions below).

If you are using pinned SHAs, please use the SHAs of versions v4.2.0 or v3.4.0

If you do not upgrade, all workflow runs using any of the deprecated actions/cache will fail.

Upgrading to the recommended versions will not break your workflows.

Read more about the change & access the migration guide: reference to the announcement.

Minor changes

Minor and patch version updates for these dependencies:

Full Changelog: actions/cache@v4.1.2...v4.2.0

v4.1.2

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v4.1.1...v4.1.2

actions/checkout (actions/checkout)

v4.2.2

Compare Source

actions/download-artifact (actions/download-artifact)

v4.1.9

Compare Source

actions/setup-java (actions/setup-java)

v4.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/setup-java@v4...v4.7.0

v4.6.0

Compare Source

What's Changed

Add-ons:

 - name: Checkout
   uses: actions/checkout@v4
 - name: Setup-java
   uses: actions/setup-java@v4
   with:
     distribution: ‘jetbrains’
     java-version: '21'

Bug fixes:

New Contributors

Full Changelog: actions/setup-java@v4...v4.6.0

v4.5.0

Compare Source

What's Changed

Bug fixes:
New Contributors:

Full Changelog: actions/setup-java@v4...v4.5.0

actions/setup-python (actions/setup-python)

v5.4.0

Compare Source

What's Changed

Enhancements:
Documentation changes:
Dependency updates:

New Contributors

Full Changelog: actions/setup-python@v5...v5.4.0

v5.3.0

Compare Source

What's Changed
Bug Fixes:
Enhancements:
New Contributors

Full Changelog: actions/setup-python@v5...v5.3.0

actions/upload-artifact (actions/upload-artifact)

v4.6.1

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v4...v4.6.1

v4.6.0

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v4...v4.6.0

v4.5.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/upload-artifact@v4.4.3...v4.5.0

aquasecurity/trivy-action (aquasecurity/trivy-action)

v0.29.0

Compare Source

What's Changed

New Contributors

Full Changelog: aquasecurity/trivy-action@0.28.0...0.29.0

docker/build-push-action (docker/build-push-action)

v6.15.0

Compare Source

v6.14.0

Compare Source

Full Changelog: docker/build-push-action@v6.13.0...v6.14.0

v6.13.0

Compare Source

Full Changelog: docker/build-push-action@v6.12.0...v6.13.0

v6.12.0

Compare Source

Full Changelog: docker/build-push-action@v6.11.0...v6.12.0

v6.11.0

Compare Source

Full Changelog: docker/build-push-action@v6.10.0...v6.11.0

v6.10.0

Compare Source

Full Changelog: docker/build-push-action@v6.9.0...v6.10.0

docker/metadata-action (docker/metadata-action)

v5.7.0

Compare Source

Full Changelog: docker/metadata-action@v5.6.1...v5.7.0

v5.6.1

Compare Source

Full Changelog: docker/metadata-action@v5.6.0...v5.6.1

v5.6.0

Compare Source

Full Changelog: docker/metadata-action@v5.5.1...v5.6.0

docker/setup-buildx-action (docker/setup-buildx-action)

v3.10.0

Compare Source

v3.9.0

Compare Source

Full Changelog: docker/setup-buildx-action@v3.8.0...v3.9.0

v3.8.0

Compare Source

Full Changelog: docker/setup-buildx-action@v3.7.1...v3.8.0

chgl/kube-powertools (ghcr.io/chgl/kube-powertools)

v2.3.45

Compare Source

Bug Fixes
CI/CD
  • disable non pip-compile (e15bb29)
  • option to run scorecards.yml manually (01845be)
  • renovate: possibly fixed pip-compile (2612755)

v2.3.44

Compare Source

Bug Fixes
  • addressed scorecard complaints & updated to Ubuntu 24.04 (#​515) (6a571f2)

v2.3.43

Compare Source

Miscellaneous Chores

v2.3.42

Compare Source

Bug Fixes

v2.3.41

Compare Source

Bug Fixes

v2.3.40

Compare Source

Miscellaneous Chores

v2.3.39

Compare Source

Miscellaneous Chores

v2.3.38

Compare Source

Miscellaneous Chores

v2.3.37

Compare Source

Miscellaneous Chores
CI/CD
  • ignore some megalinter errors and address zizmor lints (#​504) (47b2122)

v2.3.36

Compare Source

Bug Fixes
  • use helm-schema instead of deprecated helm-schema-gen plugin (#​499) (3d79ba5)

v2.3.35

Compare Source

Bug Fixes
Miscellaneous Chores

v2.3.34

Compare Source

Bug Fixes
  • use app token for releases (4151c33)

v2.3.30

Compare Source

Miscellaneous Chores
  • deps: update all non-major dependencies (fb7c564)

v2.3.29

Compare Source

Miscellaneous Chores
  • deps: update docker.io/nginxinc/nginx-unprivileged:1.27.2 docker digest to 1492491 (#​481) (60c87ae)
  • deps: update lycheeverse/lychee-action action to v2 (#​484) (9a9ffd5)

v2.3.28

Compare Source

Miscellaneous Chores
  • deps: update all non-major dependencies (8dead52)
  • deps: update github-actions (bf35c66)
miracum/ig-build-tools (ghcr.io/miracum/ig-build-tools)

v2.1.17

Compare Source

Miscellaneous Chores
  • deps: update dependency hapifhir/org.hl7.fhir.core to v6.5.9 (#​205) (cb0972e)
  • deps: update docker.io/library/eclipse-temurin:21-jre-noble docker digest to 3ef64ec (#​204) (f23be5e)
  • deps: update github/codeql-action action to v3.28.9 (#​206) (32b6a85)
CI/CD
  • renovate: try dedicated extractversion of fhir validator since the releases aren't v-prefixed (04609be)

v2.1.16

Compare Source

Miscellaneous Chores
  • deps: bumped validator jar version (0ef8775)

v2.1.15

Compare Source

Miscellaneous Chores

v2.1.14

Compare Source

Bug Fixes
  • fixed renovate comments and Firely.Terminal version problems (#​202) (f1ce932)

v2.1.13

Compare Source

Bug Fixes

v2.1.12

Compare Source

Miscellaneous Chores

v2.1.11

Compare Source

Miscellaneous Chores
  • deps: update docker.io/library/eclipse-temurin:21-jre-noble docker digest to 860f93f (#​198) (27516be)

v2.1.10

Compare Source

Bug Fixes

v2.1.9

Compare Source

Miscellaneous Chores

v2.1.8

Compare Source

Miscellaneous Chores

v2.1.7

Compare Source

Miscellaneous Chores
  • deps: update all non-major dependencies (8d9e829)
  • deps: update all non-major dependencies (8f475c6)
  • deps: update docker.io/library/eclipse-temurin:11-jre docker digest to 22639ff (18913e9)
  • deps: update docker.io/library/eclipse-temurin:11-jre docker digest to a271604 (994236f)
  • deps: update docker.io/library/eclipse-temurin:11-jre docker digest to cc5855a (338ac43)
  • deps: update github-actions (8ed9c79)
  • deps: update github-actions (5504b9f)
  • deps: update github-actions (6f502c3)
  • deps: updated node, java, fhir terminal and re-ordered Dockerfile (#​195) (4436296)
github/codeql-action (github/codeql-action)

v3.28.10

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.10 - 21 Feb 2025
  • Update default CodeQL bundle version to 2.20.5. #​2772
  • Address an issue where the CodeQL Bundle would occasionally fail to decompress on macOS. #​2768

See the full CHANGELOG.md for more information.

v3.28.9

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.9 - 07 Feb 2025
  • Update default CodeQL bundle version to 2.20.4. #​2753

See the full CHANGELOG.md for more information.

v3.28.8

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.8 - 29 Jan 2025

  • Enable support for Kotlin 2.1.10 when running with CodeQL CLI v2.20.3. #​2744

See the full CHANGELOG.md for more information.

v3.28.7

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.7 - 29 Jan 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.28.6

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.6 - 27 Jan 2025
  • Re-enable debug artifact upload for CLI versions 2.20.3 or greater. #​2726

See the full CHANGELOG.md for more information.

v3.28.5

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.28.5 - 24 Jan 2025
  • Update default CodeQL bundle version to 2.20.3. #​2717

See the full CHANGELOG.md for more information.

v3.28.4

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language pa


Configuration

📅 Schedule: Branch creation - "* 0-3 1 * *" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

github-actions bot commented Oct 24, 2024

🦙 MegaLinter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 18 0 0.22s
✅ BASH bash-exec 5 0 0.03s
✅ BASH shellcheck 2 0 0.13s
⚠️ BASH shfmt 5 1 0.01s
⚠️ CSHARP csharpier 1 1 1.14s
⚠️ CSHARP dotnet-format yes 1 1.58s
✅ CSHARP roslynator 1 0 23.33s
✅ CSS stylelint 1 0 2.5s
✅ DOCKERFILE hadolint 4 0 0.23s
✅ EDITORCONFIG editorconfig-checker 379 0 5.07s
✅ ENV dotenv-linter 1 0 0.01s
✅ GROOVY npm-groovy-lint 7 0 15.33s
✅ HTML djlint 2 0 1.57s
✅ HTML htmlhint 2 0 0.41s
✅ JAVA checkstyle 59 0 9.25s
✅ JSON jsonlint 31 0 0.38s
⚠️ JSON prettier 31 1 5.08s
✅ JSON v8r 31 0 26.33s
⚠️ MARKDOWN markdownlint 22 190 1.93s
✅ PYTHON bandit 1 0 1.73s
✅ PYTHON black 1 0 1.1s
✅ PYTHON flake8 1 0 0.68s
✅ PYTHON isort 1 0 0.46s
✅ PYTHON mypy 1 0 9.57s
✅ PYTHON ruff 1 0 0.01s
✅ REPOSITORY checkov yes no 25.13s
✅ REPOSITORY gitleaks yes no 2.84s
✅ REPOSITORY git_diff yes no 0.13s
✅ REPOSITORY kics yes no 59.63s
✅ REPOSITORY secretlint yes no 2.2s
✅ REPOSITORY syft yes no 3.99s
❌ REPOSITORY trivy yes 1 20.93s
✅ REPOSITORY trivy-sbom yes no 0.73s
✅ REPOSITORY trufflehog yes no 5.68s
✅ XML xmllint 3 0 0.02s
✅ YAML prettier 111 0 1.89s

See detailed report in MegaLinter reports

You could have same capabilities but better runtime performances if you request a new MegaLinter flavor.

MegaLinter is graciously provided by OX Security

@renovate renovate bot force-pushed the renovate/github-actions branch from 097caf3 to 9aee785 Compare October 24, 2024 16:59
@renovate renovate bot force-pushed the renovate/github-actions branch 6 times, most recently from ca541c6 to 2ae5589 Compare November 7, 2024 15:28
@renovate renovate bot force-pushed the renovate/github-actions branch 6 times, most recently from 38d1f3f to 29ea524 Compare November 14, 2024 14:43
@renovate renovate bot force-pushed the renovate/github-actions branch 8 times, most recently from 7c153b6 to 290ee56 Compare November 23, 2024 11:20
@renovate renovate bot force-pushed the renovate/github-actions branch 8 times, most recently from e746fb5 to 5a599ad Compare December 3, 2024 12:34
@renovate renovate bot force-pushed the renovate/github-actions branch 10 times, most recently from 589ff42 to 1c7e415 Compare January 29, 2025 21:27
@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from 4020556 to d563314 Compare February 2, 2025 13:20
@renovate renovate bot force-pushed the renovate/github-actions branch 3 times, most recently from e3dac63 to e3de31a Compare February 11, 2025 12:59
@renovate renovate bot force-pushed the renovate/github-actions branch 8 times, most recently from c03c794 to a68567f Compare February 21, 2025 23:42
@renovate renovate bot force-pushed the renovate/github-actions branch 5 times, most recently from dd4ce2a to c1cdc6f Compare February 27, 2025 19:48
@renovate renovate bot force-pushed the renovate/github-actions branch from c1cdc6f to 13de788 Compare February 27, 2025 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants