Skip to content

Commit 1024ff9

Browse files
authored
chore(deps): Update project dependencies (#155)
* chore(deps): Update project dependencies * chore(deps): Update pre-commit and actions * chore: Update deps and safety handling
1 parent 883ae73 commit 1024ff9

File tree

7 files changed

+561
-473
lines changed

7 files changed

+561
-473
lines changed

.github/workflows/pre-commit.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,14 +14,14 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Checkout Source
17-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
17+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1818
- name: Setup Dependencies
1919
uses: './.github/actions/deps'
2020
with:
2121
python-version: '3.11'
2222
- name: Install MDL
2323
run: echo $'source \'https://rubygems.org\'\ngem \'mdl\', \'~> 0.12.0\'' > Gemfile
24-
- uses: ruby/setup-ruby@d4526a55538b775af234ba4af27118ed6f8f6677 # v1.172.0
24+
- uses: ruby/setup-ruby@161cd54b698f1fb3ea539faab2e036d409550e3c # v1.187.0
2525
with:
2626
ruby-version: '3.2' # Not needed with a .ruby-version file
2727
bundler-cache: true # runs 'bundle install' and caches installed gems automatically

.github/workflows/publish.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Checkout Source
18-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
18+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1919
with:
2020
fetch-depth: 0
2121

@@ -46,7 +46,7 @@ jobs:
4646
POETRY_PYPI_TOKEN_PYPI: ${{ secrets.POETRY_PYPI_TOKEN_PYPI }}
4747

4848
- name: Release
49-
uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v1
49+
uses: softprops/action-gh-release@a74c6b72af54cfa997e81df42d94703d6313a2d0 # v2.0.6
5050
with:
5151
discussion_category_name: announcements
5252
generate_release_notes: true

.github/workflows/scorecard.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,12 +32,12 @@ jobs:
3232

3333
steps:
3434
- name: "Checkout code"
35-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
35+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
3636
with:
3737
persist-credentials: false
3838

3939
- name: "Run analysis"
40-
uses: ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86 # v2.1.2
40+
uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
4141
with:
4242
results_file: results.sarif
4343
results_format: sarif
@@ -59,14 +59,14 @@ jobs:
5959
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6060
# format to the repository Actions tab.
6161
- name: "Upload artifact"
62-
uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # v3.1.0
62+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
6363
with:
6464
name: SARIF file
6565
path: results.sarif
6666
retention-days: 5
6767

6868
# Upload the results to GitHub's code scanning dashboard.
6969
- name: "Upload to code-scanning"
70-
uses: github/codeql-action/upload-sarif@17573ee1cc1b9d061760f3a006fc4aac4f944fd5 # v2.2.4
70+
uses: github/codeql-action/upload-sarif@064a406de026ea27990a5b507b56911401ca2f95 # v2.18.0
7171
with:
7272
sarif_file: results.sarif

.github/workflows/validate.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Checkout Source
17-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
17+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1818
- name: Setup Dependencies
1919
uses: './.github/actions/deps'
2020
with:
@@ -37,7 +37,7 @@ jobs:
3737
runs-on: ${{ matrix.os }}
3838
steps:
3939
- name: Checkout Source
40-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
40+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
4141
- name: Setup Dependencies
4242
uses: './.github/actions/deps'
4343
with:
@@ -48,7 +48,7 @@ jobs:
4848
run: poetry run poe test
4949

5050
- name: Codecov
51-
uses: codecov/codecov-action@54bcd8715eee62d40e33596ef5e8f0f48dbbccab # v4.1.0
51+
uses: codecov/codecov-action@e28ff129e5465c2c0dcc6f003fc735cb6ae0c673 # v4.5.0
5252
with:
5353
token: ${{ secrets.CODECOV_TOKEN }}
5454

@@ -57,7 +57,7 @@ jobs:
5757
runs-on: ubuntu-latest
5858
steps:
5959
- name: Checkout Source
60-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
60+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
6161
- name: Setup Dependencies
6262
uses: './.github/actions/deps'
6363
with:

.pre-commit-config.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ minimum_pre_commit_version: "3.5.0"
55

66
repos:
77
- repo: https://github.com/pre-commit/pre-commit-hooks
8-
rev: c4a0b883114b00d8d76b479c820ce7950211c99b # frozen: v4.5.0
8+
rev: 2c9f875913ee60ca25ce70243dc24d5b6415598c # frozen: v4.6.0
99
hooks:
1010
- id: check-added-large-files
1111
- id: check-case-conflict
@@ -20,7 +20,7 @@ repos:
2020
- id: trailing-whitespace
2121

2222
- repo: https://github.com/PyCQA/bandit
23-
rev: 4c5b3c81e4356001b472849b05af902064d68515 # frozen: 1.7.7
23+
rev: 691f465b4bac758ea1d6dfa9b57d3881a12954fd # frozen: 1.7.9
2424
hooks:
2525
- id: bandit
2626
description: 'Bandit is a tool for finding common security issues in Python code'
@@ -29,13 +29,13 @@ repos:
2929

3030
- repo: https://github.com/astral-sh/ruff-pre-commit
3131
# Ruff version.
32-
rev: 0431f238e57190b696d22a57a87eb3d0b22c0036 # frozen: v0.3.1
32+
rev: f6793c73d53e659efecf3b3c38d122fb6a2a969f # frozen: v0.5.1
3333
hooks:
3434
- id: ruff
3535
args: [ --fix, --exit-non-zero-on-fix ]
3636

3737
- repo: https://github.com/psf/black
38-
rev: 6fdf8a4af28071ed1d079c01122b34c5d587207a # frozen: 24.2.0
38+
rev: 3702ba224ecffbcec30af640c149f231d90aebdb # frozen: 24.4.2
3939
hooks:
4040
- id: black
4141
language_version: python3.11

0 commit comments

Comments
 (0)