chore(deps): update github actions minor and patch updates#210
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): update github actions minor and patch updates#210renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
2546ed9 to
6277d85
Compare
8ad3c23 to
4d3de7b
Compare
4d3de7b to
c358f94
Compare
71db183 to
cbe625f
Compare
cbe625f to
836356f
Compare
5b64611 to
c6cfebb
Compare
f1b9f0c to
35bccbd
Compare
35bccbd to
485ac74
Compare
1180446 to
ddd9bff
Compare
ddd9bff to
93dfdaf
Compare
93dfdaf to
aa1445e
Compare
aa1445e to
41e34df
Compare
41e34df to
cd33bc3
Compare
d583aac to
23c12ad
Compare
23c12ad to
d9a2033
Compare
d9a2033 to
658eddf
Compare
ccbd9b9 to
d498e3e
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
d498e3e to
067c260
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.2→v4.3.1v5.5.0→v5.6.0v0.20.0→v0.22.2v3.4.0→v3.7.0v6.3.0→v6.4.0v3.8.2→v3.10.1v2.7.0→v2.7.1v2.12.0→v2.14.1Release Notes
actions/checkout (actions/checkout)
v4.3.1Compare Source
What's Changed
Full Changelog: actions/checkout@v4...v4.3.1
v4.3.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/checkout@v4...v4.3.0
actions/setup-go (actions/setup-go)
v5.6.0Compare Source
What's Changed
Full Changelog: actions/setup-go@v5...v5.6.0
anchore/sbom-action (anchore/sbom-action)
v0.22.2Compare Source
v0.22.1Compare Source
v0.22.1
⬆️ Dependencies
v0.22.0Compare Source
Changes in v0.22.0
⬆️ Dependencies
v0.21.1Compare Source
Changes in v0.21.1
v0.21.0Compare Source
v0.20.11Compare Source
Changes in v0.20.11
v0.20.10Compare Source
Changes in v0.20.10
v0.20.9Compare Source
Changes in v0.20.9
v0.20.8Compare Source
Changes in v0.20.8
v0.20.7Compare Source
Changes in v0.20.7
v0.20.6Compare Source
Changes in v0.20.6
v0.20.5Compare Source
Changes in v0.20.5
v0.20.4Compare Source
Changes in v0.20.4
v0.20.3Compare Source
Changes in v0.20.3
v0.20.2Compare Source
Changes in v0.20.2
v0.20.1Compare Source
Changes in v0.20.1
docker/login-action (docker/login-action)
v3.7.0Compare Source
scopeinput to set scopes for the authentication token by @crazy-max in #912registry-authinput by @crazy-max in #911Full Changelog: docker/login-action@v3.6.0...v3.7.0
v3.6.0Compare Source
registry-authinput for raw authentication to registries by @crazy-max in #887Full Changelog: docker/login-action@v3.5.0...v3.6.0
v3.5.0Compare Source
Full Changelog: docker/login-action@v3.4.0...v3.5.0
goreleaser/goreleaser-action (goreleaser/goreleaser-action)
v6.4.0Compare Source
What's Changed
New Contributors
Full Changelog: goreleaser/goreleaser-action@v6.3.0...v6.4.0
sigstore/cosign-installer (sigstore/cosign-installer)
v3.10.1Compare Source
What's Changed?
Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.
Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.
v3.10.0Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0
v3.9.2Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.1...v3.9.2
v3.9.1Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.0...v3.9.1
v3.9.0Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3...v3.9.0
slsa-framework/slsa-verifier (slsa-framework/slsa-verifier)
v2.7.1Compare Source
What's Changed
cc458d7by @renovate-bot in #838dcc06eeby @renovate-bot in #839dd5cc4bby @renovate-bot in #8470a0dc20by @renovate-bot in #844New Contributors
Full Changelog: slsa-framework/slsa-verifier@v2.7.0...v2.7.1
step-security/harden-runner (step-security/harden-runner)
v2.14.1Compare Source
What's Changed
In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers.
Fixed npm audit vulnerabilities
Full Changelog: step-security/harden-runner@v2.14.0...v2.14.1
v2.14.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.3...v2.14.0
v2.13.3Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.2...v2.13.3
v2.13.2Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.1...v2.13.2
v2.13.1Compare Source
What's Changed
Graceful handling of HTTP errors: Improved error handling when fetching Harden Runner policies from the StepSecurity Policy Store API, ensuring more reliable execution even in case of temporary network/API issues.
Security updates for npm dependencies: Updated vulnerable npm package dependencies to the latest secure versions.
Faster enterprise agent downloads: The enterprise agent is now downloaded from GitHub Releases instead of packages.stepsecurity.io, improving download speed and reliability.
Full Changelog: step-security/harden-runner@v2.13.0...v2.13.1
v2.13.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.13.0
v2.12.2Compare Source
What's Changed
Added HTTPS Monitoring for additional destinations - *.githubusercontent.com
Bug fixes:
Full Changelog: step-security/harden-runner@v2...v2.12.2
v2.12.1Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.12.1
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.