chore(deps): bump the github-actions group with 6 updates #229
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 6 updates:
2.5.1
2.7.0
3.6.0
4.1.2
2.21.5
3.24.7
3.8.1
4.0.2
2.2.0
2.3.1
3.1.2
4.3.1
Updates
step-security/harden-runner
from 2.5.1 to 2.7.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
63c24ba
Merge pull request #376 from step-security/rc-795691d3
Update dist6339621
Update to node204a63cda
Add tls-inspection capability (#368)dece111
Merge pull request #372 from step-security/readme-update1952f97
Updates32f00ff
Update README.mdea8b747
Publish test results (#363)c0db65e
Merge pull request #359 from step-security/dependabot/github_actions/actions/...4151c05
Merge pull request #361 from step-security/dependabot/github_actions/step-sec...Updates
actions/checkout
from 3.6.0 to 4.1.2Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9bb5618
Prep for release of v4.1.2 (#1649)8eb1f6a
Bump@babel/traverse
from 7.20.5 to 7.24.0 (#1642)556e4c3
Bump tough-cookie from 4.0.0 to 4.1.3 (#1406)b32f140
Warn on attempts to publishtest-ubuntu-git
from non-main branch. (#1623)2650dbd
Givetest-ubuntu-git
its ownREADME
(#1620)aadec89
Explicitly disable sparse checkout unless asked for (#1598)df0bcdd
Refine workflow for generatingtest-ubuntu-git
(#1617)473055b
Createtest-ubuntu-git
Docker Container for Proxy Tests (#1616)b4ffde6
Link to release page from what's new section (#1514)8530928
Correct link to GitHub Docs (#1511)Updates
github/codeql-action
from 2.21.5 to 3.24.7Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
3ab4101
Merge pull request #2192 from github/update-v3.24.7-5e882999fa006adf
Update changelog for v3.24.75e88299
Bump the npm group with 2 updates (#2190)69e120d
Merge pull request #2191 from github/henrymercer/use-include-query-help-flag5ec06c7
Use the--sarif-include-query-help
option when supportedcaf3779
Update default bundle to 2.16.4 (#2185)532ca54
Failanalyze
step by passing an invalid option todatabase finalize
(#2189)2fa207a
Merge pull request #2188 from github/henrymercer/prepare-build-mode-help24c3eda
Escape named value in input description27a6cd0
Remove experimental qualifiers from build mode inputUpdates
actions/setup-node
from 3.8.1 to 4.0.2Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
60edb5d
Add support for arm64 Windows (#927)d86ebcd
Add support forvolta.extends
(#921)b39b52d
Fix node-version-file interprets entire package.json as a version (#865)7247617
Addpackage.json
tonode-version-file
list of examples. (#879)f3ec4ca
Fix README.md (#898)ec97f37
Add fix for cache (#917)5ef044f
Update reusable workflows to use Node.js v20 (#889)c45882a
update to setup-node@v4 in docs (#884)ee36e8b
Ignore engines check in Yarn 1 e2e-cache tests (#882)8f152de
Update actions/checkout for documentation and yaml (#876)Updates
ossf/scorecard-action
from 2.2.0 to 2.3.1Release notes
Sourced from ossf/scorecard-action's releases.
Commits
0864cf1
🌱 Bump docker tag to for v2.3.1 release (#1284)72df3bf
🌱 Bump github.com/ossf/scorecard/v4 from v4.13.0 to v4.13.1 (#1282)0ea411f
🌱 Bump the docker-images group with 1 update (#1281)dbfd042
🌱 Bump the github-actions group with 1 update (#1280)2fa1e2f
🌱 Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1278)652ddd0
🌱 Bump github.com/google/go-cmp from 0.5.9 to 0.6.0 (#1277)28d0c92
🌱 Group Dependabot updates for GitHub Actions and Dockerfiles (#1276)cb50491
🌱 Bump distroless/base froma35b652
tob31a6e0
(#1275)87157ac
🌱 Bump github/codeql-action from 2.21.9 to 2.22.1 (#1274)7c1648b
🌱 Bump step-security/harden-runner from 2.5.1 to 2.6.0 (#1273)Updates
actions/upload-artifact
from 3.1.2 to 4.3.1Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
5d5d22a
Merge pull request #515 from actions/eggyhead/update-artifact-v2.1.1f1e993d
update artifact license4881bfd
updating dist:a30777e
@eggyhead
3a80482
Merge pull request #511 from actions/robherley/migration-docs-typo9d63e3f
Merge branch 'main' into robherley/migration-docs-typodfa1ab2
fix typo with v3 artifact downloads in migration guided00351b
Merge pull request #509 from markmssd/patch-1707f5a7
Update limitation of10
artifacts upload to500
26f96df
Merge pull request #505 from actions/robherley/merge-artifactsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions