Skip to content

Commit 3de570d

Browse files
build(deps): bump the ci group across 1 directory with 12 updates
Bumps the ci group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/setup-go](https://github.com/actions/setup-go) | `5.1.0` | `5.3.0` | | [helm/kind-action](https://github.com/helm/kind-action) | `1.10.0` | `1.12.0` | | [fluxcd/pkg](https://github.com/fluxcd/pkg) | `1.0.0` | `1.2.0` | | [replicatedhq/replicated-actions](https://github.com/replicatedhq/replicated-actions) | `1.16.2` | `1.17.0` | | [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.7` | `2.1.8` | | [google-github-actions/setup-gcloud](https://github.com/google-github-actions/setup-gcloud) | `2.1.2` | `2.1.4` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.2.0` | `3.3.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.7.1` | `3.8.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.3` | `4.6.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.27.6` | `3.28.8` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.17.8` | `0.18.0` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.5` | `7.0.6` | Updates `actions/setup-go` from 5.1.0 to 5.3.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@41dfa10...f111f33) Updates `helm/kind-action` from 1.10.0 to 1.12.0 - [Release notes](https://github.com/helm/kind-action/releases) - [Commits](helm/kind-action@0025e74...a1b0e39) Updates `fluxcd/pkg` from 1.0.0 to 1.2.0 - [Commits](fluxcd/pkg@5bf9095...c964ce7) Updates `replicatedhq/replicated-actions` from 1.16.2 to 1.17.0 - [Release notes](https://github.com/replicatedhq/replicated-actions/releases) - [Commits](replicatedhq/replicated-actions@7712178...c98ab3b) Updates `google-github-actions/auth` from 2.1.7 to 2.1.8 - [Release notes](https://github.com/google-github-actions/auth/releases) - [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md) - [Commits](google-github-actions/auth@6fc4af4...71f9864) Updates `google-github-actions/setup-gcloud` from 2.1.2 to 2.1.4 - [Release notes](https://github.com/google-github-actions/setup-gcloud/releases) - [Changelog](https://github.com/google-github-actions/setup-gcloud/blob/main/CHANGELOG.md) - [Commits](google-github-actions/setup-gcloud@6189d56...77e7a55) Updates `docker/setup-qemu-action` from 3.2.0 to 3.3.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@49b3bc8...53851d1) Updates `docker/setup-buildx-action` from 3.7.1 to 3.8.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@c47758b...6524bf6) Updates `actions/upload-artifact` from 4.4.3 to 4.6.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b4b15b8...65c4c4a) Updates `github/codeql-action` from 3.27.6 to 3.28.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@aa57810...dd74661) Updates `anchore/sbom-action` from 0.17.8 to 0.18.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@55dc4ee...f325610) Updates `peter-evans/create-pull-request` from 7.0.5 to 7.0.6 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@5e91468...67ccf78) --- updated-dependencies: - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: helm/kind-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: fluxcd/pkg dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: replicatedhq/replicated-actions dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: google-github-actions/auth dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: google-github-actions/setup-gcloud dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci - dependency-name: docker/setup-qemu-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: anchore/sbom-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ci - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ci ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent cfd369d commit 3de570d

9 files changed

+41
-41
lines changed

.github/workflows/conformance.yaml

+10-10
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
- name: Checkout
2626
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2727
- name: Setup Go
28-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
28+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2929
with:
3030
go-version: ${{ env.GO_VERSION }}
3131
cache-dependency-path: |
@@ -40,7 +40,7 @@ jobs:
4040
run: |
4141
make build
4242
- name: Setup Kubernetes
43-
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
43+
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
4444
with:
4545
version: v0.22.0
4646
cluster_name: ${{ steps.prep.outputs.CLUSTER }}
@@ -82,7 +82,7 @@ jobs:
8282
- name: Checkout
8383
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8484
- name: Setup Go
85-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
85+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
8686
with:
8787
go-version: ${{ env.GO_VERSION }}
8888
cache-dependency-path: |
@@ -97,7 +97,7 @@ jobs:
9797
KUBECONFIG_PATH="$(git rev-parse --show-toplevel)/bin/kubeconfig.yaml"
9898
echo "kubeconfig-path=${KUBECONFIG_PATH}" >> $GITHUB_OUTPUT
9999
- name: Setup Kustomize
100-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
100+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
101101
- name: Build
102102
run: make build-dev
103103
- name: Create repository
@@ -107,7 +107,7 @@ jobs:
107107
GITHUB_TOKEN: ${{ secrets.GITPROVIDER_BOT_TOKEN }}
108108
- name: Create cluster
109109
id: create-cluster
110-
uses: replicatedhq/replicated-actions/create-cluster@77121785951d05387334b773644c356885191f14 # v1.16.2
110+
uses: replicatedhq/replicated-actions/create-cluster@c98ab3b97925af5db9faf3f9676df7a9c6736985 # v1.17.0
111111
with:
112112
api-token: ${{ secrets.REPLICATED_API_TOKEN }}
113113
kubernetes-distribution: "k3s"
@@ -151,7 +151,7 @@ jobs:
151151
kubectl delete ns flux-system --wait
152152
- name: Delete cluster
153153
if: ${{ always() }}
154-
uses: replicatedhq/replicated-actions/remove-cluster@77121785951d05387334b773644c356885191f14 # v1.16.2
154+
uses: replicatedhq/replicated-actions/remove-cluster@c98ab3b97925af5db9faf3f9676df7a9c6736985 # v1.17.0
155155
continue-on-error: true
156156
with:
157157
api-token: ${{ secrets.REPLICATED_API_TOKEN }}
@@ -175,7 +175,7 @@ jobs:
175175
- name: Checkout
176176
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
177177
- name: Setup Go
178-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
178+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
179179
with:
180180
go-version: ${{ env.GO_VERSION }}
181181
cache-dependency-path: |
@@ -190,7 +190,7 @@ jobs:
190190
KUBECONFIG_PATH="$(git rev-parse --show-toplevel)/bin/kubeconfig.yaml"
191191
echo "kubeconfig-path=${KUBECONFIG_PATH}" >> $GITHUB_OUTPUT
192192
- name: Setup Kustomize
193-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
193+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
194194
- name: Build
195195
run: make build-dev
196196
- name: Create repository
@@ -200,7 +200,7 @@ jobs:
200200
GITHUB_TOKEN: ${{ secrets.GITPROVIDER_BOT_TOKEN }}
201201
- name: Create cluster
202202
id: create-cluster
203-
uses: replicatedhq/replicated-actions/create-cluster@77121785951d05387334b773644c356885191f14 # v1.16.2
203+
uses: replicatedhq/replicated-actions/create-cluster@c98ab3b97925af5db9faf3f9676df7a9c6736985 # v1.17.0
204204
with:
205205
api-token: ${{ secrets.REPLICATED_API_TOKEN }}
206206
kubernetes-distribution: "openshift"
@@ -242,7 +242,7 @@ jobs:
242242
kubectl delete ns flux-system --wait
243243
- name: Delete cluster
244244
if: ${{ always() }}
245-
uses: replicatedhq/replicated-actions/remove-cluster@77121785951d05387334b773644c356885191f14 # v1.16.2
245+
uses: replicatedhq/replicated-actions/remove-cluster@c98ab3b97925af5db9faf3f9676df7a9c6736985 # v1.17.0
246246
continue-on-error: true
247247
with:
248248
api-token: ${{ secrets.REPLICATED_API_TOKEN }}

.github/workflows/e2e-azure.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
- name: CheckoutD
3333
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3434
- name: Setup Go
35-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
35+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
3636
with:
3737
go-version: 1.23.x
3838
cache-dependency-path: tests/integration/go.sum

.github/workflows/e2e-bootstrap.yaml

+4-4
Original file line numberDiff line numberDiff line change
@@ -19,14 +19,14 @@ jobs:
1919
- name: Checkout
2020
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2121
- name: Setup Go
22-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
22+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2323
with:
2424
go-version: 1.23.x
2525
cache-dependency-path: |
2626
**/go.sum
2727
**/go.mod
2828
- name: Setup Kubernetes
29-
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
29+
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
3030
with:
3131
version: v0.24.0
3232
cluster_name: kind
@@ -35,9 +35,9 @@ jobs:
3535
node_image: ghcr.io/fluxcd/kindest/node:v1.31.0-amd64
3636
kubectl_version: v1.31.0
3737
- name: Setup Kustomize
38-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
38+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
3939
- name: Setup yq
40-
uses: fluxcd/pkg/actions/yq@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
40+
uses: fluxcd/pkg/actions/yq@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
4141
- name: Build
4242
run: make build-dev
4343
- name: Set outputs

.github/workflows/e2e-gcp.yaml

+5-5
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
- name: Checkout
3232
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3333
- name: Setup Go
34-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
34+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
3535
with:
3636
go-version: 1.23.x
3737
cache-dependency-path: tests/integration/go.sum
@@ -48,17 +48,17 @@ jobs:
4848
env:
4949
SOPS_VER: 3.7.1
5050
- name: Authenticate to Google Cloud
51-
uses: google-github-actions/auth@6fc4af4b145ae7821d527454aa9bd537d1f2dc5f # v2.1.7
51+
uses: google-github-actions/auth@71f986410dfbc7added4569d411d040a91dc6935 # v2.1.8
5252
id: 'auth'
5353
with:
5454
credentials_json: '${{ secrets.FLUX2_E2E_GOOGLE_CREDENTIALS }}'
5555
token_format: 'access_token'
5656
- name: Setup gcloud
57-
uses: google-github-actions/setup-gcloud@6189d56e4096ee891640bb02ac264be376592d6a # v2.1.2
57+
uses: google-github-actions/setup-gcloud@77e7a554d41e2ee56fc945c52dfd3f33d12def9a # v2.1.4
5858
- name: Setup QEMU
59-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
59+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3.3.0
6060
- name: Setup Docker Buildx
61-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
61+
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3.8.0
6262
- name: Log into us-central1-docker.pkg.dev
6363
uses: docker/#-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
6464
with:

.github/workflows/e2e.yaml

+3-3
Original file line numberDiff line numberDiff line change
@@ -25,14 +25,14 @@ jobs:
2525
- name: Checkout
2626
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2727
- name: Setup Go
28-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
28+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2929
with:
3030
go-version: 1.23.x
3131
cache-dependency-path: |
3232
**/go.sum
3333
**/go.mod
3434
- name: Setup Kubernetes
35-
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
35+
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
3636
with:
3737
version: v0.24.0
3838
cluster_name: kind
@@ -46,7 +46,7 @@ jobs:
4646
run: |
4747
kubectl apply -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.3/manifests/calico.yaml
4848
- name: Setup Kustomize
49-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
49+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
5050
- name: Run tests
5151
run: make test
5252
- name: Run e2e tests

.github/workflows/ossf.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -28,12 +28,12 @@ jobs:
2828
repo_token: ${{ secrets.GITHUB_TOKEN }}
2929
publish_results: true
3030
- name: Upload artifact
31-
uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
31+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
3232
with:
3333
name: SARIF file
3434
path: results.sarif
3535
retention-days: 5
3636
- name: Upload SARIF results
37-
uses: github/codeql-action/upload-sarif@aa578102511db1f4524ed59b8cc2bae4f6e88195 # v3.27.6
37+
uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
3838
with:
3939
sarif_file: results.sarif

.github/workflows/release.yaml

+7-7
Original file line numberDiff line numberDiff line change
@@ -24,21 +24,21 @@ jobs:
2424
- name: Unshallow
2525
run: git fetch --prune --unshallow
2626
- name: Setup Go
27-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
27+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2828
with:
2929
go-version: 1.23.x
3030
cache: false
3131
- name: Setup QEMU
32-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
32+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3.3.0
3333
- name: Setup Docker Buildx
3434
id: buildx
35-
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
35+
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3.8.0
3636
- name: Setup Syft
37-
uses: anchore/sbom-action/download-syft@55dc4ee22412511ee8c3142cbea40418e6cec693 # v0.17.8
37+
uses: anchore/sbom-action/download-syft@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
3838
- name: Setup Cosign
3939
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
4040
- name: Setup Kustomize
41-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
41+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
4242
- name: Login to GitHub Container Registry
4343
uses: docker/#-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
4444
with:
@@ -59,7 +59,7 @@ jobs:
5959
run: |
6060
kustomize build manifests/crds > all-crds.yaml
6161
- name: Generate OpenAPI JSON schemas from CRDs
62-
uses: fluxcd/pkg/actions/crdjsonschema@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
62+
uses: fluxcd/pkg/actions/crdjsonschema@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
6363
with:
6464
crd: all-crds.yaml
6565
output: schemas
@@ -112,7 +112,7 @@ jobs:
112112
steps:
113113
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
114114
- name: Setup Kustomize
115-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
115+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
116116
- name: Setup Flux CLI
117117
uses: ./action/
118118
- name: Prepare

.github/workflows/scan.yaml

+7-7
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,9 @@ jobs:
3333
steps:
3434
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3535
- name: Setup Kustomize
36-
uses: fluxcd/pkg/actions/kustomize@5bf9095331052934ae6b4585b8632c0e5b0a2106 # main
36+
uses: fluxcd/pkg/actions/kustomize@c964ce7b91949ff4b5e3959db4f1d7bb2e029a49 # main
3737
- name: Setup Go
38-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
38+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
3939
with:
4040
go-version-file: 'go.mod'
4141
cache-dependency-path: |
@@ -54,7 +54,7 @@ jobs:
5454
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
5555
- name: Upload result to GitHub Code Scanning
5656
continue-on-error: true
57-
uses: github/codeql-action/upload-sarif@aa578102511db1f4524ed59b8cc2bae4f6e88195 # v3.27.6
57+
uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
5858
with:
5959
sarif_file: snyk.sarif
6060

@@ -67,20 +67,20 @@ jobs:
6767
- name: Checkout repository
6868
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6969
- name: Setup Go
70-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
70+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
7171
with:
7272
go-version-file: 'go.mod'
7373
cache-dependency-path: |
7474
**/go.sum
7575
**/go.mod
7676
- name: Initialize CodeQL
77-
uses: github/codeql-action/init@aa578102511db1f4524ed59b8cc2bae4f6e88195 # v3.27.6
77+
uses: github/codeql-action/init@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
7878
with:
7979
languages: go
8080
# xref: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
8181
# xref: https://codeql.github.com/codeql-query-help/go/
8282
queries: security-and-quality
8383
- name: Autobuild
84-
uses: github/codeql-action/autobuild@aa578102511db1f4524ed59b8cc2bae4f6e88195 # v3.27.6
84+
uses: github/codeql-action/autobuild@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
8585
- name: Perform CodeQL Analysis
86-
uses: github/codeql-action/analyze@aa578102511db1f4524ed59b8cc2bae4f6e88195 # v3.27.6
86+
uses: github/codeql-action/analyze@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8

.github/workflows/update.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
- name: Check out code
2121
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
2222
- name: Setup Go
23-
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
23+
uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
2424
with:
2525
go-version: 1.23.x
2626
cache-dependency-path: |
@@ -84,7 +84,7 @@ jobs:
8484
8585
- name: Create Pull Request
8686
id: cpr
87-
uses: peter-evans/create-pull-request@5e914681df9dc83aa4e4905692ca88beb2f9e91f # v7.0.5
87+
uses: peter-evans/create-pull-request@67ccf781d68cd99b580ae25a5c18a1cc84ffff1f # v7.0.6
8888
with:
8989
token: ${{ secrets.BOT_GITHUB_TOKEN }}
9090
commit-message: |

0 commit comments

Comments
 (0)