deps: bump the production-dependencies group across 1 directory with 27 updates#5
Open
dependabot[bot] wants to merge 1 commit into
Conversation
…27 updates Bumps the production-dependencies group with 27 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `7` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [actions/github-script](https://github.com/actions/github-script) | `7` | `9` | | [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain) | `56f84321dbccf38fb67ce29ab63e4754056677e0` | `3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9` | | [actions/cache](https://github.com/actions/cache) | `4` | `5` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.10.0` | `4.1.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `4.2.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.7.0` | `6.1.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.15.0` | `7.2.0` | | [advanced-security/spdx-dependency-submission-action](https://github.com/advanced-security/spdx-dependency-submission-action) | `0.1.1` | `0.2.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `2.2.3` | `4.1.0` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `6.1.0` | `7.4.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4` | `5` | | [actions/labeler](https://github.com/actions/labeler) | `5` | `6` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `3.0.2` | `4.0.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `6` | | [advanced-security/reusable-workflows/.github/workflows/release.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.8` | `8.1.1` | | [advanced-security/reusable-workflows/.github/workflows/python-testing.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [advanced-security/reusable-workflows/.github/workflows/python-linting.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [advanced-security/reusable-workflows/.github/workflows/python-vendor.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [advanced-security/reusable-workflows/.github/workflows/python-release.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [42ByteLabs/patch-release-me](https://github.com/42bytelabs/patch-release-me) | `0.5.3` | `0.6.6` | | [peter-murray/semver-action](https://github.com/peter-murray/semver-action) | `1.0.1` | `2.0.0` | | [advanced-security/reusable-workflows/.github/workflows/dependency-review.yml](https://github.com/advanced-security/reusable-workflows) | `0.3.0` | `0.3.4` | | [Andrew-Chen-Wang/github-wiki-action](https://github.com/andrew-chen-wang/github-wiki-action) | `4.4.0` | `5.0.4` | Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v7...v9) Updates `dtolnay/rust-toolchain` from 56f84321dbccf38fb67ce29ab63e4754056677e0 to 3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](dtolnay/rust-toolchain@56f8432...3c5f7ea) Updates `actions/cache` from 4 to 5 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v5) Updates `docker/setup-buildx-action` from 3.10.0 to 4.1.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@b5ca514...d7f5e7f) Updates `docker/login-action` from 3.4.0 to 4.2.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...650006c) Updates `docker/metadata-action` from 5.7.0 to 6.1.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@902fa8e...80c7e94) Updates `docker/build-push-action` from 6.15.0 to 7.2.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@471d1dc...f9f3042) Updates `advanced-security/spdx-dependency-submission-action` from 0.1.1 to 0.2.0 - [Release notes](https://github.com/advanced-security/spdx-dependency-submission-action/releases) - [Commits](advanced-security/spdx-dependency-submission-action@5530bab...169d224) Updates `actions/attest-build-provenance` from 2.2.3 to 4.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@c074443...a2bbfa2) Updates `anchore/scan-action` from 6.1.0 to 7.4.0 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@7c05671...e116508) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) Updates `actions/dependency-review-action` from 4 to 5 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@v4...v5) Updates `actions/labeler` from 5 to 6 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@v5...v6) Updates `dorny/paths-filter` from 3.0.2 to 4.0.1 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](dorny/paths-filter@de90cc6...fbd0ab8) Updates `actions/setup-python` from 5 to 6 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v6) Updates `advanced-security/reusable-workflows/.github/workflows/release.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `peter-evans/create-pull-request` from 7.0.8 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@271a8d0...5f6978f) Updates `advanced-security/reusable-workflows/.github/workflows/python-testing.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `advanced-security/reusable-workflows/.github/workflows/python-linting.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `advanced-security/reusable-workflows/.github/workflows/python-vendor.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `advanced-security/reusable-workflows/.github/workflows/python-release.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `42ByteLabs/patch-release-me` from 0.5.3 to 0.6.6 - [Release notes](https://github.com/42bytelabs/patch-release-me/releases) - [Commits](42ByteLabs/patch-release-me@f950db6...04ea0a6) Updates `peter-murray/semver-action` from 1.0.1 to 2.0.0 - [Release notes](https://github.com/peter-murray/semver-action/releases) - [Commits](peter-murray/semver-data-action@5a07021...0965343) Updates `advanced-security/reusable-workflows/.github/workflows/dependency-review.yml` from 0.3.0 to 0.3.4 - [Release notes](https://github.com/advanced-security/reusable-workflows/releases) - [Commits](advanced-security/reusable-workflows@v0.3.0...v0.3.4) Updates `Andrew-Chen-Wang/github-wiki-action` from 4.4.0 to 5.0.4 - [Release notes](https://github.com/andrew-chen-wang/github-wiki-action/releases) - [Commits](Andrew-Chen-Wang/github-wiki-action@50650fc...64efa0a) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: dtolnay/rust-toolchain dependency-version: 3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 dependency-type: direct:production dependency-group: production-dependencies - dependency-name: actions/cache dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: docker/setup-buildx-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: docker/metadata-action dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: docker/build-push-action dependency-version: 7.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: advanced-security/spdx-dependency-submission-action dependency-version: 0.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: actions/attest-build-provenance dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: anchore/scan-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: actions/dependency-review-action dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: actions/labeler dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: dorny/paths-filter dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: actions/setup-python dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/release.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/python-testing.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/python-linting.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/python-vendor.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/python-release.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: 42ByteLabs/patch-release-me dependency-version: 0.6.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: peter-murray/semver-action dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: advanced-security/reusable-workflows/.github/workflows/dependency-review.yml dependency-version: 0.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: Andrew-Chen-Wang/github-wiki-action dependency-version: 5.0.4 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Dependency ReviewThe following issues were found:
License Issues.github/workflows/container-publish.yml
.github/workflows/language-detection-and-assignment.yml
.github/workflows/python-testing.yml
.github/workflows/self-dependency-review.yml
.github/workflows/self-wiki.yml
OpenSSF ScorecardScorecard details
Scanned Files
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production-dependencies group with 27 updates in the / directory:
47347956f84321dbccf38fb67ce29ab63e4754056677e03c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9453.10.04.1.03.4.04.2.05.7.06.1.06.15.07.2.00.1.10.2.02.2.34.1.06.1.07.4.04745563.0.24.0.1560.3.00.3.47.0.88.1.10.3.00.3.40.3.00.3.40.3.00.3.40.3.00.3.40.5.30.6.61.0.12.0.00.3.00.3.44.4.05.0.4Updates
actions/checkoutfrom 4 to 7Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)df4cb1cUpdate changelog for v6.0.3 (#2446)Updates
github/codeql-actionfrom 3 to 4Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
0ad7c1fRebuild25c25b5Update changelog and version after v4.36.187557b9Merge pull request #3940 from github/update-v4.36.1-2a1689ed49431011Update changelog for v4.36.12a1689eMerge pull request #3939 from github/henrymercer/skip-overlay-revert-when-exp...d40e417Only do initial wait when not running tests5245323Disable missing diff-ranges fallback when overlay enabled manually948a63aAdd FF to force JGit-based Git backendUpdates
actions/github-scriptfrom 7 to 9Release notes
Sourced from actions/github-script's releases.
... (truncated)
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionUpdates
dtolnay/rust-toolchainfrom 56f84321dbccf38fb67ce29ab63e4754056677e0 to 3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9Commits
3c5f7eaAdd 1.94.1 patch releaseefa25f7Add 1.93.1 patch releasef7ccc83Merge pull request #177 from dtolnay/permitcopyrename1c0547fPermit cross-device copy0b1efabUpdate actions/checkout@v5 -> v60f44b27Add 1.91.1 patch release6d653acMerge pull request #171 from dtolnay/up30dc51dUpdate Linux arm64 runner to Ubuntu 24.04e97e2d8Update actions/checkout@v4 -> v53bd6ba1Merge pull request #168 from dtolnay/sedUpdates
actions/cachefrom 4 to 5Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
27d5ce7Merge pull request #1747 from actions/yacaovsnc/update-dependencyf280785licensed changes619aeb1npm run build generated dist filesbcf16c2Update ts-http-runtime to 0.3.56682284Merge pull request #1738 from actions/prepare-v5.0.4e340396Update RELEASES8a67110Add licenses1865903Update dependencies & patch security vulnerabilities5656298Merge pull request #1722 from RyPeck/patch-14e380d1Fix cache key in examples.md for bun.lockUpdates
docker/setup-buildx-actionfrom 3.10.0 to 4.1.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
d7f5e7fMerge pull request #489 from docker/dependabot/npm_and_yarn/docker/actions-to...92bc5c9chore: update generated contentda11e35build(deps): bump@docker/actions-toolkitfrom 0.79.0 to 0.90.0f021e16Merge pull request #492 from docker/dependabot/npm_and_yarn/undici-6.24.1b5af94fchore: update generated content16ad977build(deps): bump undici from 6.23.0 to 6.25.0d7a12d7Merge pull request #495...Description has been truncated