Skip to content

ci: bump the github-actions group across 1 directory with 13 updates #187

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Mar 10, 2025

Bumps the github-actions group with 13 updates in the / directory:

Package From To
step-security/harden-runner 2.10.4 2.11.0
crate-ci/typos 1.29.4 1.30.1
azure/setup-helm 4.2.0 4.3.0
google-github-actions/auth 2.1.7 2.1.8
google-github-actions/setup-gcloud 2.1.2 2.1.4
fluxcd/flux2 2.4.0 2.5.1
google-github-actions/get-gke-credentials 2.3.0 2.3.3
dependabot/fetch-metadata 2.2.0 2.3.0
tj-actions/changed-files 45.0.6 45.0.7
docker/setup-buildx-action 3.8.0 3.10.0
ossf/scorecard-action 2.4.0 2.4.1
github/codeql-action 3.28.1 3.28.11
umbrelladocs/action-linkspector 1.2.4 1.2.5

Updates step-security/harden-runner from 2.10.4 to 2.11.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.11.0

What's Changed

Release v2.11.0 in #498 Harden-Runner Enterprise tier now supports the use of eBPF for DNS resolution and network call monitoring

Full Changelog: step-security/harden-runner@v2...v2.11.0

Commits

Updates crate-ci/typos from 1.29.4 to 1.30.1

Release notes

Sourced from crate-ci/typos's releases.

v1.30.1

[1.30.1] - 2025-03-04

Features

  • (action) Create v1 tag

v1.30.0

[1.30.0] - 2025-03-01

Features

v1.29.10

[1.29.10] - 2025-02-25

Fixes

  • Also correct contaminent as contaminant

v1.29.9

[1.29.9] - 2025-02-20

Fixes

  • (action) Correctly get binary for some aarch64 systems

v1.29.8

[1.29.8] - 2025-02-19

Features

  • Attempt to build Linux aarch64 binaries

v1.29.7

[1.29.7] - 2025-02-13

Fixes

  • Don't correct implementors

v1.29.6

[1.29.6] - 2025-02-13

Features

v1.29.5

... (truncated)

Changelog

Sourced from crate-ci/typos's changelog.

Change Log

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

[Unreleased] - ReleaseDate

[1.30.1] - 2025-03-04

Features

  • (action) Create v1 tag

[1.30.0] - 2025-03-01

Features

[1.29.10] - 2025-02-25

Fixes

  • Also correct contaminent as contaminant

[1.29.9] - 2025-02-20

Fixes

  • (action) Correctly get binary for some aarch64 systems

[1.29.8] - 2025-02-19

Features

  • Attempt to build Linux aarch64 binaries

[1.29.7] - 2025-02-13

Fixes

  • Don't correct implementors

[1.29.6] - 2025-02-13

Features

... (truncated)

Commits

Updates azure/setup-helm from 4.2.0 to 4.3.0

Release notes

Sourced from azure/setup-helm's releases.

v4.3.0

  • #152 feat: log when restoring from cache
  • #157 Dependencies Update
  • #137 Add dependabot
Changelog

Sourced from azure/setup-helm's changelog.

Change Log

[4.3.0] - 2025-02-15

  • #152 feat: log when restoring from cache
  • #157 Dependencies Update
  • #137 Add dependabot

[4.2.0] - 2024-04-15

  • #124 Fix OS detection and download OS-native archive extension

[4.1.0] - 2024-03-01

  • #130 switches to use Helm published file to read latest version instead of using GitHub releases

[4.0.0] - 2024-02-12

  • #121 update to node20 as node16 is deprecated
Commits
  • b9e5190 build
  • 0e8654b Release setup-helm version 4.3.0 (#162)
  • b48e1df feat: log when restoring from cache (#152)
  • 855ae7a Bump the actions group across 1 directory with 3 updates (#159)
  • 124c6d8 Dependencies Update (#157)
  • 048f4e7 Bump the actions group across 1 directory with 2 updates (#151)
  • 8618769 Bump the actions group across 1 directory with 4 updates (#149)
  • 4eb898e Bump the actions group across 1 directory with 2 updates (#145)
  • 7a2001c Bump the actions group across 1 directory with 2 updates (#143)
  • e90c86c Bump the actions group across 1 directory with 9 updates (#141)
  • Additional commits viewable in compare view

Updates google-github-actions/auth from 2.1.7 to 2.1.8

Release notes

Sourced from google-github-actions/auth's releases.

v2.1.8

What's Changed

New Contributors

Full Changelog: google-github-actions/auth@v2...v2.1.8

Commits

Updates google-github-actions/setup-gcloud from 2.1.2 to 2.1.4

Release notes

Sourced from google-github-actions/setup-gcloud's releases.

v2.1.4

What's Changed

Full Changelog: google-github-actions/setup-gcloud@v2.1.3...v2.1.4

v2.1.3

What's Changed

Full Changelog: google-github-actions/setup-gcloud@v2...v2.1.3

Commits

Updates fluxcd/flux2 from 2.4.0 to 2.5.1

Release notes

Sourced from fluxcd/flux2's releases.

v2.5.1

Highlights

Flux v2.5.1 is a patch release which comes with various fixes. Users are encouraged to upgrade for the best experience.

Fixes:

  • Fix a bug introduced in kustomize-controller v1.5.0 that was causing spurious logging for deprecated API versions and health check failures.
  • Sanitize the kustomize-controller logs when encountering errors during SOPS decryption.

Components changelog

CLI Changelog

v2.5.0

Highlights

Flux v2.5.0 is a feature release. Users are encouraged to upgrade for the best experience.

For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.5 GA blog post.

Overview of the new features:

  • Support for GitHub App authentication (GitRepository and ImageUpdateAutomation API)
  • Custom Health Checks using CEL (Kustomization API)
  • Fine-grained control of garbage collection (Kustomization API)
  • Enable decryption of secrets generated by Kustomize components (Kustomization API)
  • Support for custom event metadata from annotations (Alert API)
  • Git commit status updates for Flux Kustomizations with OCIRepository sources (Alert API)
  • Resource filtering using CEL for webhook receivers (Receiver API)
  • Debug commands for Flux Kustomizations and HelmReleases (Flux CLI)

❤️ Big thanks to all the Flux contributors that helped us with this release!

Kubernetes compatibility

This release is compatible with the following Kubernetes versions:

Kubernetes version Minimum required
v1.30 >= 1.30.0
v1.31 >= 1.31.0
v1.32 >= 1.32.0

... (truncated)

Commits
  • 8d5f40d Merge pull request #5216 from fluxcd/backport-5214-to-release/v2.5.x
  • 3beabfe Update toolkit components
  • af67405 Merge pull request #5204 from fluxcd/kubectl-1.32.2
  • 6f65c92 Update kubectl in flux-cli image
  • c84d312 Merge pull request #5203 from fluxcd/fix-cli-build
  • d37473f Update flux-cli image
  • 712b037 Merge pull request #5200 from fluxcd/update-k8s-check
  • 14da7d5 Update Kubernetes min supported version to 1.30
  • 45da6a8 Merge pull request #5199 from fluxcd/tests-2.5
  • 3053a0b Update integration tests dependencies for Flux 2.5
  • Additional commits viewable in compare view

Updates google-github-actions/get-gke-credentials from 2.3.0 to 2.3.3

Release notes

Sourced from google-github-actions/get-gke-credentials's releases.

v2.3.3

What's Changed

Full Changelog: google-github-actions/get-gke-credentials@v2.3.2...v2.3.3

v2.3.2

What's Changed

Full Changelog: google-github-actions/get-gke-credentials@v2.3.1...v2.3.2

v2.3.1

What's Changed

Full Changelog: google-github-actions/get-gke-credentials@v2...v2.3.1

Commits

Updates dependabot/fetch-metadata from 2.2.0 to 2.3.0

Release notes

Sourced from dependabot/fetch-metadata's releases.

v2.3.0

What's Changed

New Contributors

Full Changelog: dependabot/fetch-metadata@v2...v2.3.0

Commits
  • d7267f6 Merge pull request #543 from dependabot/bump-to-v2.3.0
  • e3dd295 v2.3.0
  • 3da9521 Merge pull request #565 from CloudNStoyan/main
  • de52f60 update build
  • 59d2b1f fix incorrect parsing of directory when using dependency-group
  • 0d27069 Merge pull request #564 from CatChen/fixed-missing-outputs-in-action-yml
  • 5a7546a Fixed missing outputs in action.yml
  • 06ea45a Merge pull request #563 from CloudNStoyan/main
  • bbfca7e fix readme action example
  • b0d0393 Merge pull request #554 from dependabot/dependabot/github_actions/actions/cre...
  • Additional commits viewable in compare view

Updates tj-actions/changed-files from 45.0.6 to 45.0.7

Release notes

Sourced from tj-actions/changed-files's releases.

v45.0.7

What's Changed

Full Changelog: tj-actions/changed-files@v45...v45.0.7

Changelog

Sourced from tj-actions/changed-files's changelog.

Changelog

45.0.7 - (2025-02-04)

🐛 Bug Fixes

  • deps: Update dependency @​octokit/rest to v21.1.0 (#2394) (7b72c97) - (renovate[bot])

⚙️ Miscellaneous Tasks

  • deps: Update dependency eslint-plugin-github to v5.1.8 (#2424) (dcc7a0c) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.13.1 (#2422) (364748a) - (renovate[bot])
  • deps: Lock file maintenance (#2420) (301bed6) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.13.0 (#2419) (be1c470) - (renovate[bot])
  • deps: Update dependency eslint-plugin-github to v5.1.7 (#2417) (81785a6) - (renovate[bot])
  • deps: Update dependency @​types/lodash to v4.17.15 (#2415) (065e671) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.12.0 (#2414) (45cd7f3) - (renovate[bot])
  • deps: Update dependency eslint-plugin-github to v5.1.6 (#2413) (47f21ba) - (renovate[bot])
  • deps: Update actions/setup-node action to v4.2.0 (#2411) (3b30412) - (renovate[bot])
  • deps: Lock file maintenance (#2410) (eec6665) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.10.10 (#2409) (cefd9aa) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.10.9 (#2408) (6296564) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.10.8 (#2407) (203f0af) - (renovate[bot])
  • deps: Lock file maintenance (#2406) (8b82442) - (renovate[bot])
  • deps: Update dependency eslint-plugin-prettier to v5.2.3 (#2405) (2b7a1ec) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.10.7 (#2403) (a2600ce) - (renovate[bot])
  • deps: Update dependency eslint-plugin-jest to v28.11.0 (#2400) (5dc51d3) - (renovate[bot])
  • deps: Update dependency eslint-plugin-prettier to v5.2.2 (#2399) (18de9f3) - (renovate[bot])
  • deps: Update dependency @​types/node to v22.10.6 (#2397) (467e548) - (renovate[bot])
  • deps: Update dependency eslint-config-prettier to v10 (#2396) (556e62a) - (renovate[bot])
  • deps: Lock file maintenance (#2395) (4f1e6b0) - (renovate[bot])
  • deps: Update dependency typescript to v5.7.3 (#2393) (82deec7) - (renovate[bot])
  • deps: Update dependency eslint-plugin-github to v5.1.5 (#2392) (ef7202d) - (renovate[bot])
  • deps: Lock file maintenance (#2390) (01c978c) - (renovate[bot])

⬆️ Upgrades

  • Upgraded to v45.0.6 (#2389)

Co-authored-by: jackton1 17484350+jackton1@users.noreply.github.com (ed8e9f6) - (tj-actions[bot])

45.0.6 - (2025-01-03)

🐛 Bug Fixes

  • deps: Update dependency yaml to v2.7.0 (#2383) (5f974c2) - (renovate[bot])

⚙️ Miscellaneous Tasks

  • deps: Update dependency @​types/lodash to v4.17.14 (#2388) (d6e91a2) - (renovate[bot])

... (truncated)

Commits
  • dcc7a0c chore(deps): update dependency eslint-plugin-github to v5.1.8 (#2424)
  • 364748a chore(deps): update dependency @​types/node to v22.13.1 (#2422)
  • 301bed6 chore(deps): lock file maintenance (#2420)
  • be1c470 chore(deps): update dependency @​types/node to v22.13.0 (#2419)
  • 81785a6 chore(deps): update dependency eslint-plugin-github to v5.1.7 (#2417)
  • 065e671 chore(deps): update dependency @​types/lodash to v4.17.15 (#2415)
  • 45cd7f3 chore(deps): update dependency @​types/node to v22.12.0 (#2414)
  • 47f21ba chore(deps): update dependency eslint-plugin-github to v5.1.6 (#2413)
  • 3b30412 chore(deps): update actions/setup-node action to v4.2.0 (#2411)
  • eec6665 chore(deps): lock file maintenance (#2410)
  • Additional commits viewable in compare view

Updates docker/setup-buildx-action from 3.8.0 to 3.10.0

Release notes

Sourced from docker/setup-buildx-action's releases.

v3.10.0

Full Changelog: docker/setup-buildx-action@v3.9.0...v3.10.0

v3.9.0

Full Changelog: docker/setup-buildx-action@v3.8.0...v3.9.0

Commits
  • b5ca514 Merge pull request #408 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 1418a4e chore: update generated content
  • 93acf83 build(deps): bump @​docker/actions-toolkit from 0.54.0 to 0.56.0
  • f7ce87c Merge pull request #404 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • aa1e2a0 chore: update generated content
  • 673e008 build(deps): bump @​docker/actions-toolkit from 0.53.0 to 0.54.0
  • ba31df4 Merge pull request #402 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 5475af1 chore: update generated content
  • acacad9 build(deps): bump @​docker/actions-toolkit from 0.48.0 to 0.53.0
  • 6a25f98 Merge pull request #396 from crazy-max/bake-v6
  • Additional commits viewable in compare view

Updates ossf/scorecard-action from 2.4.0 to 2.4.1

Release notes

Sourced from ossf/scorecard-action's releases.

v2.4.1

What's Changed

  • This update bumps the Scorecard version to the v5.1.1 release. For a complete list of changes, please refer to the v5.1.0 and v5.1.1 release notes.
  • Publishing results now uses half the API quota as before. The exact savings depends on the repository in question.
  • Some errors were made into annotations to make them more visible
  • There is now an optional file_mode input which controls how repository files are fetched from GitHub. The default is archive, but git produces the most accurate results for repositories with .gitattributes files at the cost of analysis speed.
  • The underlying container for the action is now hosted on GitHub Container Registry. There should be no functional changes.

Docs

New Contributors

Commits
  • f49aabe bump docker to ghcr v2.4.1 (#1478)
  • 30a595b 🌱 Bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 (#1515)
  • 69ae593 omit vcs info from build (#1514)
  • 6a62a1c add input for specifying --file-mode (#1509)
  • 2722664 🌱 Bump the github-actions group with 2 updates (#1510)
  • ae0ef31 🌱 Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 (

Bumps the github-actions group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.10.4` | `2.11.0` |
| [crate-ci/typos](https://github.com/crate-ci/typos) | `1.29.4` | `1.30.1` |
| [azure/setup-helm](https://github.com/azure/setup-helm) | `4.2.0` | `4.3.0` |
| [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.7` | `2.1.8` |
| [google-github-actions/setup-gcloud](https://github.com/google-github-actions/setup-gcloud) | `2.1.2` | `2.1.4` |
| [fluxcd/flux2](https://github.com/fluxcd/flux2) | `2.4.0` | `2.5.1` |
| [google-github-actions/get-gke-credentials](https://github.com/google-github-actions/get-gke-credentials) | `2.3.0` | `2.3.3` |
| [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2.2.0` | `2.3.0` |
| [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `45.0.6` | `45.0.7` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.8.0` | `3.10.0` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.1` |
| [github/codeql-action](https://github.com/github/codeql-action) | `3.28.1` | `3.28.11` |
| [umbrelladocs/action-linkspector](https://github.com/umbrelladocs/action-linkspector) | `1.2.4` | `1.2.5` |



Updates `step-security/harden-runner` from 2.10.4 to 2.11.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@cb605e5...4d991eb)

Updates `crate-ci/typos` from 1.29.4 to 1.30.1
- [Release notes](https://github.com/crate-ci/typos/releases)
- [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md)
- [Commits](crate-ci/typos@685eb3d...72f3776)

Updates `azure/setup-helm` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/azure/setup-helm/releases)
- [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md)
- [Commits](Azure/setup-helm@fe7b79c...b9e5190)

Updates `google-github-actions/auth` from 2.1.7 to 2.1.8
- [Release notes](https://github.com/google-github-actions/auth/releases)
- [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md)
- [Commits](google-github-actions/auth@6fc4af4...71f9864)

Updates `google-github-actions/setup-gcloud` from 2.1.2 to 2.1.4
- [Release notes](https://github.com/google-github-actions/setup-gcloud/releases)
- [Changelog](https://github.com/google-github-actions/setup-gcloud/blob/main/CHANGELOG.md)
- [Commits](google-github-actions/setup-gcloud@6189d56...77e7a55)

Updates `fluxcd/flux2` from 2.4.0 to 2.5.1
- [Release notes](https://github.com/fluxcd/flux2/releases)
- [Changelog](https://github.com/fluxcd/flux2/blob/main/.goreleaser.yml)
- [Commits](fluxcd/flux2@5350425...8d5f40d)

Updates `google-github-actions/get-gke-credentials` from 2.3.0 to 2.3.3
- [Release notes](https://github.com/google-github-actions/get-gke-credentials/releases)
- [Changelog](https://github.com/google-github-actions/get-gke-credentials/blob/main/CHANGELOG.md)
- [Commits](google-github-actions/get-gke-credentials@9025e8f...d0cee45)

Updates `dependabot/fetch-metadata` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@dbb049a...d7267f6)

Updates `tj-actions/changed-files` from 45.0.6 to 45.0.7
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](tj-actions/changed-files@d6e91a2...dcc7a0c)

Updates `docker/setup-buildx-action` from 3.8.0 to 3.10.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@6524bf6...b5ca514)

Updates `ossf/scorecard-action` from 2.4.0 to 2.4.1
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@62b2cac...f49aabe)

Updates `github/codeql-action` from 3.28.1 to 3.28.11
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b6a472f...6bb031a)

Updates `umbrelladocs/action-linkspector` from 1.2.4 to 1.2.5
- [Release notes](https://github.com/umbrelladocs/action-linkspector/releases)
- [Commits](UmbrellaDocs/action-linkspector@fc382e1...de84085)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: crate-ci/typos
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: azure/setup-helm
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: google-github-actions/auth
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: google-github-actions/setup-gcloud
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: fluxcd/flux2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: google-github-actions/get-gke-credentials
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: dependabot/fetch-metadata
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: umbrelladocs/action-linkspector
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Copy link
Author

dependabot bot commented on behalf of github Mar 17, 2025

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot bot closed this Mar 17, 2025
@dependabot dependabot bot deleted the dependabot/github_actions/github-actions-1ac3a17867 branch March 17, 2025 06:29
@github-actions github-actions bot locked and limited conversation to collaborators Mar 17, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants