Skip to content

Commit 558d6e5

Browse files
chore(deps): bump the github-actions group across 1 directory with 7 updates
Bumps the github-actions group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `5` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [actions/setup-go](https://github.com/actions/setup-go) | `5` | `6` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.8.2` | `3.10.0` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `6.5.1` | `8.0.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.3.0` | `6.4.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.30.0` | `0.33.1` | Updates `actions/checkout` from 4 to 5 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v5) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `actions/setup-go` from 5 to 6 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@v5...v6) Updates `sigstore/cosign-installer` from 3.8.2 to 3.10.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@v3.8.2...v3.10.0) Updates `golangci/golangci-lint-action` from 6.5.1 to 8.0.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@4696ba8...4afd733) Updates `goreleaser/goreleaser-action` from 6.3.0 to 6.4.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](goreleaser/goreleaser-action@9c156ee...e435ccd) Updates `aquasecurity/trivy-action` from 0.30.0 to 0.33.1 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@6c175e9...b6643a2) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: sigstore/cosign-installer dependency-version: 3.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: golangci/golangci-lint-action dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: goreleaser/goreleaser-action dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: aquasecurity/trivy-action dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
1 parent 1c308c6 commit 558d6e5

File tree

5 files changed

+32
-32
lines changed

5 files changed

+32
-32
lines changed

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,20 +25,20 @@ jobs:
2525

2626
steps:
2727
- name: Checkout repository
28-
uses: actions/checkout@v4
28+
uses: actions/checkout@v5
2929
with:
3030
# We must fetch at least the immediate parents so that if this is
3131
# a pull request then we can checkout the head.
3232
fetch-depth: 2
3333

3434
# Initializes the CodeQL tools for scanning.
3535
- name: Initialize CodeQL
36-
uses: github/codeql-action/init@v3
36+
uses: github/codeql-action/init@v4
3737
with:
3838
languages: go
3939
-
4040
name: Set up Go
41-
uses: actions/setup-go@v5
41+
uses: actions/setup-go@v6
4242
with:
4343
go-version-file: go.mod
4444
-
@@ -53,4 +53,4 @@ jobs:
5353
RELEASE: ${{ github.event.inputs.release }}
5454

5555
- name: Perform CodeQL Analysis
56-
uses: github/codeql-action/analyze@v3
56+
uses: github/codeql-action/analyze@v4

.github/workflows/docker.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
steps:
2222
-
2323
name: Checkout
24-
uses: actions/checkout@v4
24+
uses: actions/checkout@v5
2525
-
2626
name: Set up QEMU
2727
uses: docker/setup-qemu-action@v3
@@ -30,7 +30,7 @@ jobs:
3030
uses: docker/setup-buildx-action@v3
3131
-
3232
name: Install Cosign
33-
uses: sigstore/cosign-installer@v3.8.2
33+
uses: sigstore/cosign-installer@v3.10.0
3434
-
3535
name: Login to GHCR
3636
uses: docker/login-action@v3

.github/workflows/go.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -33,10 +33,10 @@ jobs:
3333
steps:
3434
-
3535
name: Checkout code
36-
uses: actions/checkout@v4
36+
uses: actions/checkout@v5
3737
-
3838
name: Install Go
39-
uses: actions/setup-go@v5
39+
uses: actions/setup-go@v6
4040
with:
4141
go-version-file: go.mod
4242
-
@@ -54,10 +54,10 @@ jobs:
5454
steps:
5555
-
5656
name: Checkout
57-
uses: actions/checkout@v4
57+
uses: actions/checkout@v5
5858
-
5959
name: Set up Go
60-
uses: actions/setup-go@v5
60+
uses: actions/setup-go@v6
6161
with:
6262
go-version-file: go.mod
6363
check-latest: true
@@ -84,15 +84,15 @@ jobs:
8484
steps:
8585
-
8686
name: Checkout
87-
uses: actions/checkout@v4
87+
uses: actions/checkout@v5
8888
-
8989
name: Install Go
90-
uses: actions/setup-go@v5
90+
uses: actions/setup-go@v6
9191
with:
9292
go-version-file: go.mod
9393
-
9494
name: Lint code
95-
uses: golangci/golangci-lint-action@4696ba8babb6127d732c3c6dde519db15edab9ea # v6.5.1
95+
uses: golangci/golangci-lint-action@4afd733a84b1f43292c63897423277bb7f4313a9 # v8.0.0
9696
with:
9797
version: latest
9898
args: --timeout=10m
@@ -104,10 +104,10 @@ jobs:
104104
steps:
105105
-
106106
name: Checkout
107-
uses: actions/checkout@v4
107+
uses: actions/checkout@v5
108108
-
109109
name: Install Go
110-
uses: actions/setup-go@v5
110+
uses: actions/setup-go@v6
111111
with:
112112
go-version-file: go.mod
113113
-
@@ -137,10 +137,10 @@ jobs:
137137
steps:
138138
-
139139
name: Checkout
140-
uses: actions/checkout@v4
140+
uses: actions/checkout@v5
141141
-
142142
name: Install Go
143-
uses: actions/setup-go@v5
143+
uses: actions/setup-go@v6
144144
with:
145145
go-version-file: go.mod
146146
-
@@ -170,10 +170,10 @@ jobs:
170170
steps:
171171
-
172172
name: Checkout
173-
uses: actions/checkout@v4
173+
uses: actions/checkout@v5
174174
-
175175
name: Install Go
176-
uses: actions/setup-go@v5
176+
uses: actions/setup-go@v6
177177
with:
178178
go-version-file: go.mod
179179
-

.github/workflows/releaser.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,13 @@ jobs:
2020
steps:
2121
-
2222
name: Checkout
23-
uses: actions/checkout@v4
23+
uses: actions/checkout@v5
2424
-
2525
name: Unshallow
2626
run: git fetch --prune --unshallow
2727
-
2828
name: Set up Go
29-
uses: actions/setup-go@v5
29+
uses: actions/setup-go@v6
3030
with:
3131
go-version-file: go.mod
3232
-
@@ -46,7 +46,7 @@ jobs:
4646
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
4747
-
4848
name: Install Cosign
49-
uses: sigstore/cosign-installer@v3.8.2
49+
uses: sigstore/cosign-installer@v3.10.0
5050
#-
5151
# name: Import Code-Signing Certificates
5252
# uses: Apple-Actions/import-codesign-certs@cfd6eb39a2c848ead8836bda6b56813585404ba7 # v5.0.0
@@ -59,7 +59,7 @@ jobs:
5959
brew install coreutils
6060
-
6161
name: Run GoReleaser
62-
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6.3.0
62+
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
6363
with:
6464
version: latest
6565
args: release --clean --skip=publish

.github/workflows/security.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,9 @@ jobs:
2020
runs-on: ubuntu-latest
2121
steps:
2222
-
23-
uses: actions/checkout@v4
23+
uses: actions/checkout@v5
2424
-
25-
uses: actions/setup-go@v5
25+
uses: actions/setup-go@v6
2626
with:
2727
go-version-file: go.mod
2828
-
@@ -43,10 +43,10 @@ jobs:
4343

4444
steps:
4545
-
46-
uses: actions/checkout@v4
46+
uses: actions/checkout@v5
4747
-
4848
name: Run Trivy vulnerability scanner in repo mode
49-
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
49+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
5050
with:
5151
scan-type: 'fs'
5252
ignore-unfixed: true
@@ -56,7 +56,7 @@ jobs:
5656
severity: 'CRITICAL'
5757
-
5858
name: Upload Trivy scan results to GitHub Security tab
59-
uses: github/codeql-action/upload-sarif@v3
59+
uses: github/codeql-action/upload-sarif@v4
6060
with:
6161
sarif_file: 'trivy-results.sarif'
6262

@@ -72,7 +72,7 @@ jobs:
7272
#
7373
# steps:
7474
# -
75-
# uses: actions/checkout@v4
75+
# uses: actions/checkout@v5
7676
# -
7777
# name: Run Snyk to check for vulnerabilities
7878
# uses: snyk/actions/golang@master
@@ -83,7 +83,7 @@ jobs:
8383
# args: --sarif-file-output=snyk-results.sarif
8484
# -
8585
# name: Upload result to GitHub Code Scanning
86-
# uses: github/codeql-action/upload-sarif@v3
86+
# uses: github/codeql-action/upload-sarif@v4
8787
# with:
8888
# sarif_file: snyk-results.sarif
8989

@@ -99,7 +99,7 @@ jobs:
9999

100100
steps:
101101
-
102-
uses: actions/checkout@v4
102+
uses: actions/checkout@v5
103103
-
104104
uses: returntocorp/semgrep-action@713efdd345f3035192eaa63f56867b88e63e4e5d # v1
105105
with:
@@ -113,6 +113,6 @@ jobs:
113113
p/trailofbits
114114
-
115115
name: Upload result to GitHub Code Scanning
116-
uses: github/codeql-action/upload-sarif@v3
116+
uses: github/codeql-action/upload-sarif@v4
117117
with:
118118
sarif_file: semgrep.sarif

0 commit comments

Comments
 (0)