build(deps): bump the dependencies group with 3 updates
Bumps the dependencies group with 3 updates: actions/upload-artifact, actions/download-artifact and docker/build-push-action.
Updates actions/upload-artifact from 3 to 4
Release notes
Sourced from actions/upload-artifact's releases.
v4.0.0
What's Changed
The release of upload-artifact@v4 and download-artifact@v4 are major changes to the backend architecture of Artifacts. They have numerous performance and behavioral improvements.
ℹ️ However, this is a major update that includes breaking changes. Artifacts created with versions v3 and below are not compatible with the v4 actions. Uploads and downloads must use the same actions versions. There are also key differences from previous versions that may require updates to your workflows.
For more information, please see:
- The changelog post.
- The README.
- The migration documentation.
- As well as the underlying npm package,
@actions/artifactdocumentation.New Contributors
@vmjosephmade their first contribution in actions/upload-artifact#464Full Changelog: https://github.com/actions/upload-artifact/compare/v3...v4.0.0
v3.1.3
What's Changed
- chore(github): remove trailing whitespaces by
@ljmf00in actions/upload-artifact#313- Bump
@actions/artifactversion to v1.1.2 by@bethanyj28in actions/upload-artifact#436Full Changelog: https://github.com/actions/upload-artifact/compare/v3...v3.1.3
v3.1.2
- Update all
@actions/*NPM packages to their latest versions- #374- Update all dev dependencies to their most recent versions - #375
v3.1.1
- Update actions/core package to latest version to remove
set-outputdeprecation warning #351v3.1.0
What's Changed
- Bump
@actions/artifactto v1.1.0 (actions/upload-artifact#327)
- Adds checksum headers on artifact upload (actions/toolkit#1095) (actions/toolkit#1063)
Commits
c7d193fMerge pull request #466 from actions/v4-beta13131bblicensed cache4a6c273Merge branch 'main' into v4-betaf391bb9Merge pull request #465 from actions/robherley/v4-documentation9653d03Apply suggestions from code review875b630add limitations sectionecb2146add compression example5e7604ftrim some repeated infod6437d0naming1b56155s/v4-beta/v4/g- Additional commits viewable in compare view
Updates actions/download-artifact from 3 to 4
Release notes
Sourced from actions/download-artifact's releases.
v4.0.0
What's Changed
The release of upload-artifact@v4 and download-artifact@v4 are major changes to the backend architecture of Artifacts. They have numerous performance and behavioral improvements.
For more information, see the
@actions/artifactdocumentation.New Contributors
@bfladmade their first contribution in actions/download-artifact#194Full Changelog: https://github.com/actions/download-artifact/compare/v3...v4.0.0
v3.0.2
- Bump
@actions/artifactto v1.1.1 - actions/download-artifact#195- Fixed a bug in Node16 where if an HTTP download finished too quickly (<1ms, e.g. when it's mocked) we attempt to delete a temp file that has not been created yet actions/toolkit#1278
v3.0.1
Commits
6b208aeMerge pull request #274 from actions/vmjoseph/timeout-patch6c5b580only adding updated license5f5015dreadding index1fddaafRevert "updating licenses"8aa9e21Revert "updating dist"657edd9updating licenses555a2fcupdating dist4fc4d70updating lock072ac9dupdating version no038dc03updating version no- Additional commits viewable in compare view
Updates docker/build-push-action from 4 to 5
Release notes
Sourced from docker/build-push-action's releases.
v5.0.0
- Node 20 as default runtime (requires Actions Runner v2.308.0 or later) by
@crazy-maxin docker/build-push-action#954- Bump
@actions/corefrom 1.10.0 to 1.10.1 in docker/build-push-action#959Full Changelog: https://github.com/docker/build-push-action/compare/v4.2.1...v5.0.0
v4.2.1
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- warn if docker config can't be parsed by
@crazy-maxin docker/build-push-action#957Full Changelog: https://github.com/docker/build-push-action/compare/v4.2.0...v4.2.1
v4.2.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- display proxy configuration by
@crazy-maxin docker/build-push-action#872- chore(deps): Bump
@docker/actions-toolkitfrom 0.6.0 to 0.8.0 in docker/build-push-action#930- chore(deps): Bump word-wrap from 1.2.3 to 1.2.5 in docker/build-push-action#925
- chore(deps): Bump semver from 6.3.0 to 6.3.1 in docker/build-push-action#902
Full Changelog: https://github.com/docker/build-push-action/compare/v4.1.1...v4.2.0
v4.1.1
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- Bump
@docker/actions-toolkitfrom 0.3.0 to 0.5.0 by@crazy-maxin docker/build-push-action#880Full Changelog: https://github.com/docker/build-push-action/compare/v4.1.0...v4.1.1
v4.1.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- Switch to actions-toolkit implementation by
@crazy-maxin docker/build-push-action#811 docker/build-push-action#838 docker/build-push-action#855 docker/build-push-action#860 docker/build-push-action#875- e2e: quay.io by
@crazy-maxin docker/build-push-action#799 docker/build-push-action#805- e2e: local harbor and nexus by
@crazy-maxin docker/build-push-action#800- e2e: add artifactory container registry to test against by
@jedevcin docker/build-push-action#804- e2e: add distribution tests by
@jedevcin docker/build-push-action#814 docker/build-push-action#815Full Changelog: https://github.com/docker/build-push-action/compare/v4.0.0...v4.1.0
Commits
4a13e50Merge pull request #1006 from docker/dependabot/npm_and_yarn/docker/actions-t...7416668chore: update generated contentb4f76a5chore(deps): Bump@docker/actions-toolkitfrom 0.13.0 to 0.14.0b7feb76Merge pull request #1005 from crazy-max/ci-inspectfae8018ci: inspect sbom and provenanceb625868Merge pull request #1004 from crazy-max/ci-update-buildx5193ef1ci: update buildx to latestd3afd77Merge pull request #991 from docker/dependabot/npm_and_yarn/babel/traverse-7....7a786bbMerge pull request #992 from crazy-max/annotationsc66ae3achore: update generated content- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
@dependabot this pr has compatibility issue and will break the cd
Looks like these dependencies are updatable in another way, so this is no longer needed.