dependabot[bot]
4cd8e0228b
Bump the github-actions group across 1 directory with 9 updates
Bumps the github-actions group with 9 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner ) | `2.5.1` | `2.11.0` |
| [actions/checkout](https://github.com/actions/checkout ) | `2.7.0` | `4.2.2` |
| [arduino/setup-protoc](https://github.com/arduino/setup-protoc ) | `1.3.0` | `3.0.0` |
| [github/codeql-action](https://github.com/github/codeql-action ) | `2.21.3` | `3.28.10` |
| [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) | `3.0.7` | `4.5.0` |
| [actions/setup-java](https://github.com/actions/setup-java ) | `3.12.0` | `4.7.0` |
| [google/osv-scanner-action](https://github.com/google/osv-scanner-action ) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `e6898c9042613f73c90501bfa535f3c2c73b9140` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action ) | `2.3.3` | `2.4.1` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact ) | `4.3.3` | `4.6.1` |
Updates `step-security/harden-runner` from 2.5.1 to 2.11.0
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](8ca2b8b2ec ...4d991eb9b905ef189e4c376166672c3f2f230481)
Updates `actions/checkout` from 2.7.0 to 4.2.2
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2.7.0...11bd71901bbe5b1630ceea73d27597364c9af683 )
Updates `arduino/setup-protoc` from 1.3.0 to 3.0.0
- [Release notes](https://github.com/arduino/setup-protoc/releases )
- [Commits](149f6c87b9 ...c65c819552d16ad3c9b72d9dfd5ba5237b9c906b)
Updates `github/codeql-action` from 2.21.3 to 3.28.10
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v2.21.3...b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d )
Updates `actions/dependency-review-action` from 3.0.7 to 4.5.0
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](7d90b4f05f ...3b139cfc5fae8b618d3eae3675e383bb1769c019)
Updates `actions/setup-java` from 3.12.0 to 4.7.0
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](cd89f46ac9 ...3a4f6e1af504cf6a31855fa899c6aa5355ba6c12)
Updates `google/osv-scanner-action` from 8bd1ce1c4b to e6898c9042
- [Release notes](https://github.com/google/osv-scanner-action/releases )
- [Commits](8bd1ce1c4b ...e6898c9042613f73c90501bfa535f3c2c73b9140)
Updates `ossf/scorecard-action` from 2.3.3 to 2.4.1
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](dc50aa9510 ...f49aabe0b5af0936a0987cfb85d86b75731b0186)
Updates `actions/upload-artifact` from 4.3.3 to 4.6.1
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](65462800fd ...4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: arduino/setup-protoc
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-java
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: google/osv-scanner-action
dependency-type: direct:production
dependency-group: github-actions
- dependency-name: ossf/scorecard-action
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
mandlil
c87e522a58
Revert Gpg plugin changes ( #3888 )
6 months ago
mandlil
528a831ce8
Mandlil maven update ( #3884 )
* update pom project name
* [maven-release-plugin] prepare release v9.0.9
* [maven-release-plugin] prepare for next development iteration
* Update java-unit-test.yml
Skip GPG Signing
6 months ago
Silvio Brändle
aef2fdc64e
Add CI workflow for C++ ( #3643 )
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
1 year ago
dependabot[bot]
e3b0e10884
Bump step-security/harden-runner from 2.5.0 to 2.5.1 ( #3168 )
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.5.0 to 2.5.1.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](cba0d00b1f ...8ca2b8b2ece13480cda6dacd3511b49857a23c09)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
3efe7291b0
Bump step-security/harden-runner from 2.2.1 to 2.5.0 ( #3132 )
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.2.1 to 2.5.0.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](1f99358870 ...cba0d00b1fc9a034e1e642ea0f1103c282990604)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
41b8c5de2d
Bump actions/setup-java from 2.5.1 to 3.12.0 ( #3133 )
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 2.5.1 to 3.12.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](91d3aa4956 ...cd89f46ac9d01407894225f350157564c9c7cee2)
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
StepSecurity Bot
64ddcd4dfe
[StepSecurity] Apply security best practices ( #2913 )
* [StepSecurity] Apply security best practices
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
* Update codeql.yml
* Update codeql.yml
---------
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: penmetsaa <penmetsaa@google.com>
3 years ago
penmetsaa
9970ea0431
Remove old ci/cd configs ( #2691 )
4 years ago
penmetsaa
a908dac441
Update event list for workflow triggering. ( #2665 )
- When configured "pull_request[type: opened] + push", workflow not getting triggered when there is a change in PR code/commits when the branch is from the parent's forked repo.
- Configured only pull_request event as any change can only go through PR.
- pull_request event by default happens when opened, synchronize (means whenever there is change/commit, sync happens), and reopened. So this should be good enough for our use cases.
More details in [approach doc](https://docs.google.com/document/d/1YNYUAlEUXTi4UZG5gEFZGQ7oe7LxNKh7FYSg2qtIUvI/edit#heading=h.1c7qt5y1jb9 )
4 years ago
penmetsaa
5b1e24628a
Configure CI flow in Github Actions ( #2664 )
Our objective is to (replicating the previous setup):
- Do Maven test of LPN tool modules common, data and java-build through a Maven profile.
- Also build and test run ant target “junit” that unit tests the java LPN api jar after being built.
- Check whether LPN’s JS API/files are in ascii format/not.
- More details are mentioned in [approach doc](https://docs.google.com/document/d/1YNYUAlEUXTi4UZG5gEFZGQ7oe7LxNKh7FYSg2qtIUvI/edit )
4 years ago