dependabot[bot]
|
8286473387
|
Bump the github-actions group across 1 directory with 10 updates
Bumps the github-actions group with 10 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.5.1` | `2.13.2` |
| [actions/checkout](https://github.com/actions/checkout) | `2.7.0` | `6.0.0` |
| [arduino/setup-protoc](https://github.com/arduino/setup-protoc) | `1.3.0` | `3.0.0` |
| [github/codeql-action](https://github.com/github/codeql-action) | `2.21.3` | `4.31.6` |
| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `3.0.7` | `4.8.2` |
| [actions/setup-java](https://github.com/actions/setup-java) | `3.12.0` | `5.0.0` |
| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `08b0aaeb6b6c6659ff98c5463e60e4b70008bfff` |
| [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `08b0aaeb6b6c6659ff98c5463e60e4b70008bfff` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.3` | `2.4.3` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `5.0.0` |
Updates `step-security/harden-runner` from 2.5.1 to 2.13.2
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](8ca2b8b2ec...95d9a5deda9de15063e7595e9719c11c38c90ae2)
Updates `actions/checkout` from 2.7.0 to 6.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2.7.0...1af3b93b6815bc44a9784bd300feb67ff0d1eeb3)
Updates `arduino/setup-protoc` from 1.3.0 to 3.0.0
- [Release notes](https://github.com/arduino/setup-protoc/releases)
- [Commits](149f6c87b9...c65c819552d16ad3c9b72d9dfd5ba5237b9c906b)
Updates `github/codeql-action` from 2.21.3 to 4.31.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v2.21.3...fe4161a26a8629af62121b670040955b330f9af2)
Updates `actions/dependency-review-action` from 3.0.7 to 4.8.2
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](7d90b4f05f...3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261)
Updates `actions/setup-java` from 3.12.0 to 5.0.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](cd89f46ac9...dded0888837ed1f317902acf8a20df0ad188d165)
Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 8bd1ce1c4b to 08b0aaeb6b
- [Release notes](https://github.com/google/osv-scanner-action/releases)
- [Commits](8bd1ce1c4b...08b0aaeb6b6c6659ff98c5463e60e4b70008bfff)
Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 8bd1ce1c4b to 08b0aaeb6b
- [Release notes](https://github.com/google/osv-scanner-action/releases)
- [Commits](8bd1ce1c4b...08b0aaeb6b6c6659ff98c5463e60e4b70008bfff)
Updates `ossf/scorecard-action` from 2.3.3 to 2.4.3
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](dc50aa9510...4eaacf0543bb3f2c246792bd56e8cdeffafb205a)
Updates `actions/upload-artifact` from 4.3.3 to 5.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](65462800fd...330a01c490aca151604b8cf639adc76d48f6c5d4)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-version: 2.13.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/checkout
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: arduino/setup-protoc
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: github/codeql-action
dependency-version: 4.31.6
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/dependency-review-action
dependency-version: 4.8.2
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-java
dependency-version: 5.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml
dependency-version: '08b0aaeb6b6c6659ff98c5463e60e4b70008bfff'
dependency-type: direct:production
dependency-group: github-actions
- dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml
dependency-version: '08b0aaeb6b6c6659ff98c5463e60e4b70008bfff'
dependency-type: direct:production
dependency-group: github-actions
- dependency-name: ossf/scorecard-action
dependency-version: 2.4.3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/upload-artifact
dependency-version: 5.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2 weeks ago |
Joyce
|
fe3b4eb2ab
|
Update codeql.yml (#3359)
Signed-off-by: Joyce <joycebrum@google.com>
Co-authored-by: Tijana Vislavski Gradina <tijanavg@google.com>
|
1 year ago |
dependabot[bot]
|
e3b0e10884
|
Bump step-security/harden-runner from 2.5.0 to 2.5.1 (#3168)
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.5.0 to 2.5.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](cba0d00b1f...8ca2b8b2ece13480cda6dacd3511b49857a23c09)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
|
2 years ago |
dependabot[bot]
|
2ad1f064fe
|
Bump github/codeql-action from 2.21.1 to 2.21.3 (#3164)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.21.1 to 2.21.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](6ca1aa8c19...5b6282e01c62d02e720b81eb8a51204f527c3624)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
|
2 years ago |
dependabot[bot]
|
3efe7291b0
|
Bump step-security/harden-runner from 2.2.1 to 2.5.0 (#3132)
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.2.1 to 2.5.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](1f99358870...cba0d00b1fc9a034e1e642ea0f1103c282990604)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
|
2 years ago |
dependabot[bot]
|
371883734c
|
Bump github/codeql-action from 2.2.9 to 2.21.1 (#3136)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.2.9 to 2.21.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](04df1262e6...6ca1aa8c195c3ca3e77c174fe0356db1bce3b319)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2 years ago |
StepSecurity Bot
|
64ddcd4dfe
|
[StepSecurity] Apply security best practices (#2913)
* [StepSecurity] Apply security best practices
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
* Update codeql.yml
* Update codeql.yml
---------
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: penmetsaa <penmetsaa@google.com>
|
3 years ago |