dependabot[bot]
c6226e94d7
Bump the github-actions group across 1 directory with 8 updates
Bumps the github-actions group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner ) | `2.5.1` | `2.10.1` |
| [actions/checkout](https://github.com/actions/checkout ) | `2.7.0` | `4.2.2` |
| [arduino/setup-protoc](https://github.com/arduino/setup-protoc ) | `1` | `3` |
| [github/codeql-action](https://github.com/github/codeql-action ) | `2.21.3` | `3.27.0` |
| [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) | `3.0.7` | `4.4.0` |
| [actions/setup-java](https://github.com/actions/setup-java ) | `3.12.0` | `4.5.0` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action ) | `2.3.3` | `2.4.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact ) | `4.3.3` | `4.4.3` |
Updates `step-security/harden-runner` from 2.5.1 to 2.10.1
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](8ca2b8b2ec ...91182cccc01eb5e619899d80e4e971d6181294a7)
Updates `actions/checkout` from 2.7.0 to 4.2.2
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2.7.0...11bd71901bbe5b1630ceea73d27597364c9af683 )
Updates `arduino/setup-protoc` from 1 to 3
- [Release notes](https://github.com/arduino/setup-protoc/releases )
- [Commits](https://github.com/arduino/setup-protoc/compare/v1...v3 )
Updates `github/codeql-action` from 2.21.3 to 3.27.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v2.21.3...662472033e021d55d94146f66f6058822b0b39fd )
Updates `actions/dependency-review-action` from 3.0.7 to 4.4.0
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](7d90b4f05f ...4081bf99e2866ebe428fc0477b69eb4fcda7220a)
Updates `actions/setup-java` from 3.12.0 to 4.5.0
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](cd89f46ac9 ...8df1039502a15bceb9433410b1a100fbe190c53b)
Updates `ossf/scorecard-action` from 2.3.3 to 2.4.0
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](dc50aa9510 ...62b2cac7ed8198b15735ed49ab1e5cf35480ba46)
Updates `actions/upload-artifact` from 4.3.3 to 4.4.3
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](65462800fd ...b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: arduino/setup-protoc
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-java
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: ossf/scorecard-action
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
1 year ago
Silvio Brändle
aef2fdc64e
Add CI workflow for C++ ( #3643 )
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
1 year ago
mandlil
55716be400
Update scorecards.yml ( #3625 )
Fixing the issue based on info from Scorecard workflow is failing: error signing scorecard json results ossf/scorecard-action#997
1 year ago
Joyce
42831598ac
Update dependabot.yml to avoid multiple PRs ( #3360 )
Signed-off-by: Joyce <joycebrum@google.com>
Co-authored-by: Tijana Vislavski Gradina <tijanavg@google.com>
2 years ago
mandlil
5b36228e9f
Update dependabot.yml ( #3205 )
Dependabot schedule interval is updating daily to monthly, so that PR will create monthly
2 years ago
dependabot[bot]
e3b0e10884
Bump step-security/harden-runner from 2.5.0 to 2.5.1 ( #3168 )
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.5.0 to 2.5.1.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](cba0d00b1f ...8ca2b8b2ece13480cda6dacd3511b49857a23c09)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
2ad1f064fe
Bump github/codeql-action from 2.21.1 to 2.21.3 ( #3164 )
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 2.21.1 to 2.21.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](6ca1aa8c19 ...5b6282e01c62d02e720b81eb8a51204f527c3624)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
5a5d7cae41
Bump actions/dependency-review-action from 2.5.1 to 3.0.7 ( #3169 )
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 2.5.1 to 3.0.7.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](0efb1d1d84 ...7d90b4f05fea31dde1c4a1fb3fa787e197ea93ab)
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
mandlil
d2ba31a255
Revert "Bump ossf/scorecard-action from 2.0.6 to 2.2.0 ( #3130 )" ( #3137 )
This reverts commit 22d14ae838 .
2 years ago
dependabot[bot]
3efe7291b0
Bump step-security/harden-runner from 2.2.1 to 2.5.0 ( #3132 )
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.2.1 to 2.5.0.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](1f99358870 ...cba0d00b1fc9a034e1e642ea0f1103c282990604)
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
22d14ae838
Bump ossf/scorecard-action from 2.0.6 to 2.2.0 ( #3130 )
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action ) from 2.0.6 to 2.2.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](99c53751e0 ...08b4669551908b1024bb425080c797723083c031)
---
updated-dependencies:
- dependency-name: ossf/scorecard-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
41b8c5de2d
Bump actions/setup-java from 2.5.1 to 3.12.0 ( #3133 )
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 2.5.1 to 3.12.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](91d3aa4956 ...cd89f46ac9d01407894225f350157564c9c7cee2)
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: mandlil <138015259+mandlil@users.noreply.github.com>
2 years ago
dependabot[bot]
371883734c
Bump github/codeql-action from 2.2.9 to 2.21.1 ( #3136 )
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 2.2.9 to 2.21.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](04df1262e6 ...6ca1aa8c195c3ca3e77c174fe0356db1bce3b319)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
penmetsaa
c9d8ed077d
Adding Code Owners So the approvers were organized ( #2995 )
3 years ago
StepSecurity Bot
64ddcd4dfe
[StepSecurity] Apply security best practices ( #2913 )
* [StepSecurity] Apply security best practices
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
* Update codeql.yml
* Update codeql.yml
---------
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: penmetsaa <penmetsaa@google.com>
3 years ago
penmetsaa
9970ea0431
Remove old ci/cd configs ( #2691 )
4 years ago
penmetsaa
a908dac441
Update event list for workflow triggering. ( #2665 )
- When configured "pull_request[type: opened] + push", workflow not getting triggered when there is a change in PR code/commits when the branch is from the parent's forked repo.
- Configured only pull_request event as any change can only go through PR.
- pull_request event by default happens when opened, synchronize (means whenever there is change/commit, sync happens), and reopened. So this should be good enough for our use cases.
More details in [approach doc](https://docs.google.com/document/d/1YNYUAlEUXTi4UZG5gEFZGQ7oe7LxNKh7FYSg2qtIUvI/edit#heading=h.1c7qt5y1jb9 )
4 years ago
penmetsaa
5b1e24628a
Configure CI flow in Github Actions ( #2664 )
Our objective is to (replicating the previous setup):
- Do Maven test of LPN tool modules common, data and java-build through a Maven profile.
- Also build and test run ant target “junit” that unit tests the java LPN api jar after being built.
- Check whether LPN’s JS API/files are in ascii format/not.
- More details are mentioned in [approach doc](https://docs.google.com/document/d/1YNYUAlEUXTi4UZG5gEFZGQ7oe7LxNKh7FYSg2qtIUvI/edit )
4 years ago