-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(gha)(deps): bump the github-actions group with 22 updates #1004
fix(gha)(deps): bump the github-actions group with 22 updates #1004
Conversation
Bumps the github-actions group with 22 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `3` | `4` | | [codacy/codacy-analysis-cli-action](https://github.com/codacy/codacy-analysis-cli-action) | `4.4.1` | `4.4.5` | | [github/codeql-action](https://github.com/github/codeql-action) | `2` | `3` | | [actions/cache](https://github.com/actions/cache) | `1` | `4` | | [jurplel/install-qt-action](https://github.com/jurplel/install-qt-action) | `2` | `4` | | [wagoid/commitlint-github-action](https://github.com/wagoid/commitlint-github-action) | `6.0.1` | `6.1.2` | | [microsoft/security-devops-action](https://github.com/microsoft/security-devops-action) | `1.10.0` | `1.11.0` | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2.1.0` | `2.2.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.3.2` | `4.3.5` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `5` | `6` | | [eps1lon/actions-label-merge-conflict](https://github.com/eps1lon/actions-label-merge-conflict) | `3.0.1` | `3.0.2` | | [codelytv/pr-size-labeler](https://github.com/codelytv/pr-size-labeler) | `1.10.0` | `1.10.1` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `7.13.0` | `8.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `4.4.3` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `6.1.0` | `7.0.5` | | [withastro/action](https://github.com/withastro/action) | `2.0.0` | `3.0.0` | | [actions/configure-pages](https://github.com/actions/configure-pages) | `4.0.0` | `5.0.0` | | [fsfe/reuse-action](https://github.com/fsfe/reuse-action) | `3.0.0` | `4.0.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.3` | `2.4.0` | | [check-spelling/check-spelling](https://github.com/check-spelling/check-spelling) | `0.0.22` | `0.0.23` | | [yokawasa/action-sqlcheck](https://github.com/yokawasa/action-sqlcheck) | `1.3.0` | `1.5.0` | | [DoozyX/clang-format-lint-action](https://github.com/doozyx/clang-format-lint-action) | `0.13` | `0.18` | Updates `actions/checkout` from 3 to 4 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v3...v4) Updates `codacy/codacy-analysis-cli-action` from 4.4.1 to 4.4.5 - [Release notes](https://github.com/codacy/codacy-analysis-cli-action/releases) - [Commits](codacy/codacy-analysis-cli-action@3ff8e64...97bf5df) Updates `github/codeql-action` from 2 to 3 - [Release notes](https://github.com/github/codeql-action/releases) - [Commits](github/codeql-action@v2...v3) Updates `actions/cache` from 1 to 4 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v1...v4) Updates `jurplel/install-qt-action` from 2 to 4 - [Release notes](https://github.com/jurplel/install-qt-action/releases) - [Commits](jurplel/install-qt-action@v2.0.0...v4) Updates `wagoid/commitlint-github-action` from 6.0.1 to 6.1.2 - [Changelog](https://github.com/wagoid/commitlint-github-action/blob/master/CHANGELOG.md) - [Commits](wagoid/commitlint-github-action@7f0a61d...3d28780) Updates `microsoft/security-devops-action` from 1.10.0 to 1.11.0 - [Release notes](https://github.com/microsoft/security-devops-action/releases) - [Commits](microsoft/security-devops-action@v1.10.0...v1.11.0) Updates `dependabot/fetch-metadata` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@5e5f996...dbb049a) Updates `actions/dependency-review-action` from 4.3.2 to 4.3.5 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@0c155c5...a6993e2) Updates `docker/build-push-action` from 5 to 6 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@v5...v6) Updates `eps1lon/actions-label-merge-conflict` from 3.0.1 to 3.0.2 - [Release notes](https://github.com/eps1lon/actions-label-merge-conflict/releases) - [Changelog](https://github.com/eps1lon/actions-label-merge-conflict/blob/main/CHANGELOG.md) - [Commits](eps1lon/actions-label-merge-conflict@6d74047...1b1b1fc) Updates `codelytv/pr-size-labeler` from 1.10.0 to 1.10.1 - [Release notes](https://github.com/codelytv/pr-size-labeler/releases) - [Commits](CodelyTV/pr-size-labeler@56f6f0f...c7a55a0) Updates `oxsecurity/megalinter` from 7.13.0 to 8.1.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@bacb5f8...b38cdf1) Updates `actions/upload-artifact` from 4.3.3 to 4.4.3 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4.3.3...b4b15b8) Updates `peter-evans/create-pull-request` from 6.1.0 to 7.0.5 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@c5a7806...5e91468) Updates `withastro/action` from 2.0.0 to 3.0.0 - [Release notes](https://github.com/withastro/action/releases) - [Commits](withastro/action@acfe56d...44cbafd) Updates `actions/configure-pages` from 4.0.0 to 5.0.0 - [Release notes](https://github.com/actions/configure-pages/releases) - [Commits](actions/configure-pages@v4.0.0...v5.0.0) Updates `fsfe/reuse-action` from 3.0.0 to 4.0.0 - [Release notes](https://github.com/fsfe/reuse-action/releases) - [Commits](fsfe/reuse-action@a46482c...3ae3c6b) Updates `ossf/scorecard-action` from 2.3.3 to 2.4.0 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@dc50aa9...62b2cac) Updates `check-spelling/check-spelling` from 0.0.22 to 0.0.23 - [Release notes](https://github.com/check-spelling/check-spelling/releases) - [Changelog](https://github.com/check-spelling/check-spelling/blob/main/gh-release-downloader) - [Commits](check-spelling/check-spelling@00c989c...2c9e4a8) Updates `yokawasa/action-sqlcheck` from 1.3.0 to 1.5.0 - [Release notes](https://github.com/yokawasa/action-sqlcheck/releases) - [Commits](yokawasa/action-sqlcheck@v1.3.0...v1.5.0) Updates `DoozyX/clang-format-lint-action` from 0.13 to 0.18 - [Release notes](https://github.com/doozyx/clang-format-lint-action/releases) - [Commits](DoozyX/clang-format-lint-action@v0.13...v0.18) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: codacy/codacy-analysis-cli-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: jurplel/install-qt-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: wagoid/commitlint-github-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: microsoft/security-devops-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dependabot/fetch-metadata dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: docker/build-push-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: eps1lon/actions-label-merge-conflict dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: codelytv/pr-size-labeler dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: withastro/action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/configure-pages dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: fsfe/reuse-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: check-spelling/check-spelling dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: yokawasa/action-sqlcheck dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: DoozyX/clang-format-lint-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Merging to
|
Dependency ReviewThe following issues were found:
License Issues.github/workflows/labeler.yml
.github/workflows/reuse-check.yml
.github/workflows/pages-astro.yml
OpenSSF ScorecardScorecard details
Scanned Files
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
check-spelling found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
@check-spelling-bot Report🔴 Please reviewSee the 📂 files view, the 📜action log, or 📝 job summary for details. Unrecognized words (2099)
Some files were automatically ignored 🙈These sample patterns would exclude them:
You should consider excluding directory paths (e.g. You should consider adding them to:
File matching is via Perl regular expressions. To check these files, more of their words need to be in the dictionary than not. You can use To accept these unrecognized words as correct and update file exclusions, you could run the following commands... in a clone of the [email protected]:jmuelbert/jmbde-QT.git repository curl -s -S -L 'https://raw.githubusercontent.com/check-spelling/check-spelling/00c989c97749eb0cb2d256bdc55ac61b0096c6d3/apply.pl' |
perl - 'https://github.com/jmuelbert/jmbde-QT/actions/runs/11552634310/attempts/1' OR To have the bot accept them for you, reply quoting the following line: Available 📚 dictionaries could cover words not in the 📘 dictionary
Consider adding them (in with:
extra_dictionaries:
cspell:python/src/python/python-lib.txt
cspell:python/src/python/python.txt
cspell:python/src/common/extra.txt
cspell:cpp/src/ecosystem.txt
cspell:php/dict/php.txt To stop checking additional dictionaries, add (in check_extra_dictionaries: '' Pattern suggestions ✂️ (37)You could add these patterns to
Errors (7)See the 📂 files view, the 📜action log, or 📝 job summary for details.
See ❌ Event descriptions for more information. If the flagged items are 🤯 false positivesIf items relate to a ...
🚂 If you're seeing this message and your PR is from a branch that doesn't have |
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the github-actions group with 22 updates:
3
4
4.4.1
4.4.5
2
3
1
4
2
4
6.0.1
6.1.2
1.10.0
1.11.0
2.1.0
2.2.0
4.3.2
4.3.5
5
6
3.0.1
3.0.2
1.10.0
1.10.1
7.13.0
8.1.0
4.3.3
4.4.3
6.1.0
7.0.5
2.0.0
3.0.0
4.0.0
5.0.0
3.0.0
4.0.0
2.3.3
2.4.0
0.0.22
0.0.23
1.3.0
1.5.0
0.13
0.18
Updates
actions/checkout
from 3 to 4Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
11bd719
Prepare 4.2.2 Release (#1953)e3d2460
Expand unit test coverage (#1946)163217d
url-helper.ts
now leverages well-known environment variables. (#1941)eef6144
Prepare 4.2.1 release (#1925)6b42224
Add workflow file for publishing releases to immutable action package (#1919)de5a000
Check out other refs/* by commit if provided, fall back to ref (#1924)d632683
Prepare 4.2.0 release (#1878)6d193bf
Bump braces from 3.0.2 to 3.0.3 (#1777)db0cee9
Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)b684943
Add Ref and Commit outputs (#1180)Updates
codacy/codacy-analysis-cli-action
from 4.4.1 to 4.4.5Release notes
Sourced from codacy/codacy-analysis-cli-action's releases.
... (truncated)
Commits
97bf5df
feat: build for release3ad04f4
feat: build for release3987b1d
feat: build for release55bddef
feat: build for releaseUpdates
github/codeql-action
from 2 to 3Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Commits
d591d17
Fix name of Python stdlib extraction feature flagc470063
Merge pull request #2549 from github/henrymercer/remove-support-2.13.5ad94f2f
Merge pull request #2548 from github/angelapwen/fix-prepare-test57f465f
Add changelog note9ccb1b7
Bump version to 3.27.04f2715b
Update supported GHES versions tableUpdates
actions/cache
from 1 to 4Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
6849a64
Release 4.1.2 #14775a1720c
Merge branch 'Link-/prep-4.1.2' of https://github.com/actions/cache into Link...d9fef48
Merge branch 'main' into Link-/prep-4.1.2a50e8d0
Merge branch 'main' into Link-/prep-4.1.2acc9ae5
Merge pull request #1481 from actions/dependabot/github_actions/actions/setup...1ea5f18
Merge branch 'main' into Link-/prep-4.1.2cc679ff
Merge branch 'main' into dependabot/github_actions/actions/setup-node-4366d43d
Merge pull request #1483 from actions/dependabot/github_actions/github/codeql...02bf319
Bump github/codeql-action from 2 to 36f6220b
Merge branch 'main' into dependabot/github_actions/actions/setup-node-4Updates
jurplel/install-qt-action
from 2 to 4Release notes
Sourced from jurplel/install-qt-action's releases.
... (truncated)
Commits
f03f055
Merge remote-tracking branch 'origin/master' into v4b514934
Forgot action.yml workaround0fe81f8
Update README_upgrade_guide.md6d100a7
Merge remote-tracking branch 'origin/master' into v499da6f4
Forgot to add node_modules518d652
Update README.mddbcedf9
Build v43254977
Update packages8c7ed71
fix lints45ea618
Exit process after running, workaround for #236Updates
wagoid/commitlint-github-action
from 6.0.1 to 6.1.2Changelog
Sourced from wagoid/commitlint-github-action's changelog.
... (truncated)
Commits
3d28780
chore(release): publish 6.1.2 [skip-ci]47ff131
fix: using compareCommits for push event commit query (#801)a2bc521
chore(release): publish 6.1.1 [skip-ci]bc25072
Merge pull request #800 from wagoid/revert-798-feat/using-rest-for-push09a8abb
Revert "feat: updating push event trigger to use rest API (OctoKit) vs push e...dbd4ecd
chore(release): publish 6.1.0 [skip-ci]0de1544
Merge pull request #798 from ncino/feat/using-rest-for-pushc3ab7fd
fix: updating unit tests with mocking push octokit list commits70e22e9
feat: updating push event trigger to use rest API (OctoKit) vs push eventbaa1b23
chore(release): publish 6.0.2 [skip-ci]Updates
microsoft/security-devops-action
from 1.10.0 to 1.11.0Release notes
Sourced from microsoft/security-devops-action's releases.
Commits
cc007d0
Merge pull request #100 from microsoft/serait/containerMappingDefault481b67d
Update documentation416e86d
Update documentation2cc7798
Cleanup codec23429e
Cleanup code25574b7
Cleanup codea956936
Cleanup codeb0ce45b
Cleanup codedaf2549
Cleanup code3d86faf
Merge pull request #99 from sethRait/serait/checkCallerIsOnboardedUpdates
dependabot/fetch-metadata
from 2.1.0 to 2.2.0Release notes
Sourced from dependabot/fetch-metadata's releases.
Commits
dbb049a
v2.2.0 (#520)36bf1f9
Merge pull request #532 from dependabot/dependabot/npm_and_yarn/braces-3.0.3a3420b5
Bump braces from 3.0.2 to 3.0.3006e43f
Merge pull request #534 from dependabot/dependabot/github_actions/actions/cre...9c55ebe
Bump actions/create-github-app-token from 1.10.0 to 1.10.2325b863
Merge pull request #523 from dependabot/dependabot/github_actions/actions/cre...aec2f3e
Bump actions/create-github-app-token from 1.9.0 to 1.10.0Updates
actions/dependency-review-action
from 4.3.2 to 4.3.5Release notes
Sourced from actions/dependency-review-action's releases.