build(deps): bump the actions-deps group across 1 directory with 11 updates
Bumps the actions-deps group with 11 updates in the / directory:
| Package | From | To |
|---|---|---|
| actions/checkout | 5.0.0 |
6.0.0 |
| github/ai-moderator | 1.1.2 |
1.1.4 |
| step-security/harden-runner | 2.13.1 |
2.13.2 |
| actions/setup-go | 6.0.0 |
6.1.0 |
| actions/upload-artifact | 4.6.2 |
5.0.0 |
| golangci/golangci-lint-action | 8.0.0 |
9.1.0 |
| actions/dependency-review-action | 4.8.0 |
4.8.2 |
| sigstore/cosign-installer | 3.10.0 |
4.0.0 |
| anchore/sbom-action | 0.20.6 |
0.20.10 |
| peter-evans/repository-dispatch | 4.0.0 |
4.0.1 |
| github/codeql-action | 3.30.5 |
4.31.6 |
Updates actions/checkout from 5.0.0 to 6.0.0
Release notes
Sourced from actions/checkout's releases.
v6.0.0
What's Changed
- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- v6-beta by
@ericsciplein actions/checkout#2298- update readme/changelog for v6 by
@ericsciplein actions/checkout#2311Full Changelog: https://github.com/actions/checkout/compare/v5.0.0...v6.0.0
v6-beta
What's Changed
Updated persist-credentials to store the credentials under
$RUNNER_TEMPinstead of directly in the local git config.This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.
v5.0.1
What's Changed
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301Full Changelog: https://github.com/actions/checkout/compare/v5...v5.0.1
Changelog
Sourced from actions/checkout's changelog.
Changelog
V6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248V5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301V5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226V4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305V4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924v4.2.0
- Add Ref and Commit outputs by
@lucacomein actions/checkout#1180- Dependency updates by
@dependabot- actions/checkout#1777, actions/checkout#1872v4.1.7
- Bump the minor-npm-dependencies group across 1 directory with 4 updates by
@dependabotin actions/checkout#1739- Bump actions/checkout from 3 to 4 by
@dependabotin actions/checkout#1697- Check out other refs/* by commit by
@orhantoyin actions/checkout#1774- Pin actions/checkout's own workflows to a known, good, stable version. by
@jww3in actions/checkout#1776v4.1.6
- Check platform to set archive extension appropriately by
@cory-millerin actions/checkout#1732v4.1.5
- Update NPM dependencies by
@cory-millerin actions/checkout#1703- Bump github/codeql-action from 2 to 3 by
@dependabotin actions/checkout#1694- Bump actions/setup-node from 1 to 4 by
@dependabotin actions/checkout#1696- Bump actions/upload-artifact from 2 to 4 by
@dependabotin actions/checkout#1695
... (truncated)
Commits
Updates github/ai-moderator from 1.1.2 to 1.1.4
Release notes
Sourced from github/ai-moderator's releases.
v1.1.4
What's Changed
- Add input for dry-run mode by
@dsanders11in github/ai-moderator#42Full Changelog: https://github.com/github/ai-moderator/compare/v1...v1.1.4
v1.1.3
What's Changed
- Update ai-moderator action version in README by
@castrojoin github/ai-moderator#17- Bump openai from 4.104.0 to 5.12.2 by
@dependabot[bot] in github/ai-moderator#15- Bump actions/checkout from 4 to 5 by
@dependabot[bot] in github/ai-moderator#19- Bump the npm-development group across 1 directory with 17 updates by
@dependabot[bot] in github/ai-moderator#9- Bump
@rollup/rollup-linux-x64-gnufrom 4.46.2 to 4.48.1 by@dependabot[bot] in github/ai-moderator#21- Add input for endpoint by
@dsanders11in github/ai-moderator#43New Contributors
@castrojomade their first contribution in github/ai-moderator#17@dsanders11made their first contribution in github/ai-moderator#43Full Changelog: https://github.com/github/ai-moderator/compare/v1...v1.1.3
Commits
81159c3Merge pull request #42 from dsanders11/feat/dry-run-input4d26b05Add input for dry-run mode6cac571Merge pull request #43 from dsanders11/feat/endpoint-input675bfa2Add input for endpointa230e1eMerge pull request #21 from github/dependabot/npm_and_yarn/rollup/rollup-linu...6746ca1Bump@rollup/rollup-linux-x64-gnufrom 4.46.2 to 4.48.14b03900Merge pull request #9 from github/dependabot/npm_and_yarn/npm-development-8d5...527b1b7update licenses cache532c0a4update dist fileae1832cMerge pull request #19 from github/dependabot/github_actions/actions/checkout-5- Additional commits viewable in compare view
Updates step-security/harden-runner from 2.13.1 to 2.13.2
Release notes
Sourced from step-security/harden-runner's releases.
v2.13.2
What's Changed
- Fixed an issue where there was a limit of 512 allowed endpoints when using block egress policy. This restriction has been removed, allowing for an unlimited number of endpoints to be configured.
- Harden Runner now automatically detects if the agent is already pre-installed on a custom VM image used by a GitHub-hosted runner. When detected, the action will skip reinstallation and use the existing agent.
Full Changelog: https://github.com/step-security/harden-runner/compare/v2.13.1...v2.13.2
Commits
95d9a5dMerge pull request #606 from step-security/rc-2887e429dUpdate limitations.mdef891c3feat: add support for custom vm image1fa8c8aupdate agent92c522aMerge pull request #593 from step-security/ak-readme-updates4719ad5README updates4fde639Merge pull request #591 from eromosele-stepsecurity/Updf682f2fUpdate README.md- See full diff in compare view
Updates actions/setup-go from 6.0.0 to 6.1.0
Release notes
Sourced from actions/setup-go's releases.
v6.1.0
What's Changed
Enhancements
- Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by
@nicholasngaiin actions/setup-go#665- Add support for .tool-versions file and update workflow by
@priya-kinthaliin actions/setup-go#673- Add comprehensive breaking changes documentation for v6 by
@mahabaleshwarsin actions/setup-go#674Dependency updates
- Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by
@dependabotin actions/setup-go#617- Upgrade actions/publish-action from 0.3.0 to 0.4.0 by
@dependabotin actions/setup-go#641- Upgrade semver and
@types/semverby@dependabotin actions/setup-go#652New Contributors
@nicholasngaimade their first contribution in actions/setup-go#665@priya-kinthalimade their first contribution in actions/setup-go#673@mahabaleshwarsmade their first contribution in actions/setup-go#674Full Changelog: https://github.com/actions/setup-go/compare/v6...v6.1.0
Commits
4dc6199Bump semver and@types/semver(#652)f3787beAdd comprehensive breaking changes documentation for v6 (#674)3a0c2c8Bump actions/publish-action from 0.3.0 to 0.4.0 (#641)faf5242Add support for .tool-versions file in setup-go, update workflow (#673)7bc60dbFall back to downloading from go.dev/dl instead of storage.googleapis.com/gol...c0137caBump eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking chang...- See full diff in compare view
Updates actions/upload-artifact from 4.6.2 to 5.0.0
Release notes
Sourced from actions/upload-artifact's releases.
v5.0.0
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.
- Update README.md by
@GhadimiRin actions/upload-artifact#681- Update README.md by
@nebuk89in actions/upload-artifact#712- Readme: spell out the first use of GHES by
@danwkennedyin actions/upload-artifact#727- Update GHES guidance to include reference to Node 20 version by
@patrikpolyakin actions/upload-artifact#725- Bump
@actions/artifacttov4.0.0- Prepare
v5.0.0by@danwkennedyin actions/upload-artifact#734New Contributors
@GhadimiRmade their first contribution in actions/upload-artifact#681@nebuk89made their first contribution in actions/upload-artifact#712@danwkennedymade their first contribution in actions/upload-artifact#727@patrikpolyakmade their first contribution in actions/upload-artifact#725Full Changelog: https://github.com/actions/upload-artifact/compare/v4...v5.0.0
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.md- Additional commits viewable in compare view
Updates golangci/golangci-lint-action from 8.0.0 to 9.1.0
Release notes
Sourced from golangci/golangci-lint-action's releases.
v9.1.0
What's Changed
Changes
- feat: automatic module directories by
@ldezin golangci/golangci-lint-action#1315Documentation
- docs: organize options by
@ldezin golangci/golangci-lint-action#1314Dependencies
- build(deps-dev): bump the dev-dependencies group with 2 updates by
@dependabot[bot] in golangci/golangci-lint-action#1307- build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 by
@dependabot[bot] in golangci/golangci-lint-action#1309- build(deps-dev): bump the dev-dependencies group with 2 updates by
@dependabot[bot] in golangci/golangci-lint-action#1310- build(deps): bump the dependencies group with 2 updates by
@dependabot[bot] in golangci/golangci-lint-action#1311Full Changelog: https://github.com/golangci/golangci-lint-action/compare/v9.0.0...v9.1.0
v9.0.0
In the scope of this release, we change Nodejs runtime from node20 to node24 (https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/).
What's Changed
Changes
- feat: add install-only option by
@ldezin golangci/golangci-lint-action#1305- feat: support Module Plugin System by
@ldezin golangci/golangci-lint-action#1306Full Changelog: https://github.com/golangci/golangci-lint-action/compare/v8.0.0...v9.0.0
Commits
e7fa5acfeat: automatic module directories (#1315)f3ae99fdocs: organize options (#1314)1dfda28docs: update readme8b0f942build(deps): bump the dependencies group with 2 updates (#1311)a77756cbuild(deps-dev): bump the dev-dependencies group with 2 updates (#1310)37a9fafbuild(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (#1309)199a9c2build(deps-dev): bump the dev-dependencies group with 2 updates (#1307)c7c1219chore: simplify0a35821docs: update readme043b1b8feat: support Module Plugin System (#1306)- Additional commits viewable in compare view
Updates actions/dependency-review-action from 4.8.0 to 4.8.2
Release notes
Sourced from actions/dependency-review-action's releases.
v4.8.2
Minor fixes:
- Fix PURL parsing for scoped packages (#1008 from
@danielhardej)- Fix for large summaries (#1007 from
@gitulisca)- README includes a working example for allow-dependencies-licenses (#1009 from
@danielhardej)Dependency Review Action v4.8.1
What's Changed
- (bug) Fix spamming link test in deprecation warning (again) by
@ahpookin actions/dependency-review-action#1000- Bump version for 4.8.1 release by
@ahpookin actions/dependency-review-action#1001Full Changelog: https://github.com/actions/dependency-review-action/compare/v4...v4.8.1
Commits
3c4e3dcMerge pull request #1016 from actions/dra-release02930b2Update CONTRIBUTING to reflect new guidelines49ffd9fUpdate CONTRIBUTING to reflect the need to build70cb25e4.8.2 releaseebabd31Merge pull request #1008 from danielhardej/danielhardej-patch-2025102319f9360Update package-lock.json5fd2f98Bump@types/jestto version 29.5.1428647f4Fix PURL parsing by removing encodeURIf620fd1Merge pull request #1013 from actions/dangoor/token-fix9b42b7eRemove bad token reference- Additional commits viewable in compare view
Updates sigstore/cosign-installer from 3.10.0 to 4.0.0
Release notes
Sourced from sigstore/cosign-installer's releases.
v4.0.0
What's Changed?
Note: You must upgrade to cosign-installer v4 if you want to install Cosign v3+. You may still install Cosign v2.x with cosign-installer v4.
In version v3+, using
cosign sign-blobrequires adding the--bundleflag which may require you to update your signing command.
- Add support for Cosign v3 releases (#201)
v3.10.1
What's Changed?
Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.
Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.
- Bump default Cosign to v2.6.1 (#203)
Commits
faadad0add support for cosign v3 releases (#201)- See full diff in compare view
Updates anchore/sbom-action from 0.20.6 to 0.20.10
Release notes
Sourced from anchore/sbom-action's releases.
v0.20.10
Changes in v0.20.10
- chore(deps): update Syft to v1.38.0 (#548) [[anchore-actions-token-generator[bot]](https://github.com/[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator))]
v0.20.9
Changes in v0.20.9
- chore(deps): update Syft to v1.36.0 (#546) [[anchore-actions-token-generator[bot]](https://github.com/[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator))]
v0.20.8
Changes in v0.20.8
- chore(deps): update Syft to v1.34.2 (#545) [[anchore-actions-token-generator[bot]](https://github.com/[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator))]
v0.20.7
Changes in v0.20.7
- chore(deps): update Syft to v1.34.1 (#544)
Commits
fbfd9c6chore(deps): update Syft to v1.38.0 (#548)8e94d75chore(deps): update Syft to v1.36.0 (#546)aa0e114chore(deps): update Syft to v1.34.2 (#545)d8a2c01chore(deps): update Syft to v1.34.1 (#544)c73dd3fAdd llms.txt to describe this repo to our AI overlords 🤖 (#534)- See full diff in compare view
Updates peter-evans/repository-dispatch from 4.0.0 to 4.0.1
Release notes
Sourced from peter-evans/repository-dispatch's releases.
v4.0.1
What's Changed
- build(deps): bump peter-evans/repository-dispatch from 3 to 4 by
@dependabot[bot] in peter-evans/repository-dispatch#428- build(deps-dev): bump
@types/nodefrom 18.19.127 to 18.19.129 by@dependabot[bot] in peter-evans/repository-dispatch#429- build(deps): bump the github-actions group with 3 updates by
@dependabot[bot] in peter-evans/repository-dispatch#431- build(deps-dev): bump
@types/nodefrom 18.19.129 to 18.19.130 in the npm group by@dependabot[bot] in peter-evans/repository-dispatch#432- Fix node version in actions.yml by
@peter-evansin peter-evans/repository-dispatch#433Full Changelog: https://github.com/peter-evans/repository-dispatch/compare/v4.0.0...v4.0.1
Commits
28959ceFix node version in actions.yml (#433)25d29c2build(deps-dev): bump@types/nodein the npm group (#432)830136cbuild(deps): bump the github-actions group with 3 updates (#431)2c856c6ci: update dependabot config6673907build(deps-dev): bump@types/nodefrom 18.19.127 to 18.19.129 (#429)952a211build(deps): bump peter-evans/repository-dispatch from 3 to 4 (#428)- See full diff in compare view
Updates github/codeql-action from 3.30.5 to 4.31.6
Release notes
Sourced from github/codeql-action's releases.
v4.31.6
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.6 - 01 Dec 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v4.31.5
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.5 - 24 Nov 2025
- Update default CodeQL bundle version to 2.23.6. #3321
See the full CHANGELOG.md for more information.
v4.31.4
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.4 - 18 Nov 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v4.31.3
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.3 - 13 Nov 2025
- CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
- Update default CodeQL bundle version to 2.23.5. #3288
See the full CHANGELOG.md for more information.
v4.31.2
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.31.6 - 01 Dec 2025
No user facing changes.
4.31.5 - 24 Nov 2025
- Update default CodeQL bundle version to 2.23.6. #3321
4.31.4 - 18 Nov 2025
No user facing changes.
4.31.3 - 13 Nov 2025
- CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
- Update default CodeQL bundle version to 2.23.5. #3288
4.31.2 - 30 Oct 2025
No user facing changes.
4.31.1 - 30 Oct 2025
- The
add-snippetsinput has been removed from theanalyzeaction. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.4.31.0 - 24 Oct 2025
- Bump minimum CodeQL bundle version to 2.17.6. #3223
- When SARIF files are uploaded by the
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #32224.30.9 - 17 Oct 2025
- Update default CodeQL bundle version to 2.23.3. #3205
- Experimental: A new
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #32044.30.8 - 10 Oct 2025
No user facing changes.
4.30.7 - 06 Oct 2025
- [v4+ only] The CodeQL Action now runs on Node.js v24. #3169
... (truncated)
Commits
fe4161aMerge pull request #3336 from github/update-v4.31.6-ecec1f88788c2ab5Update changelog for v4.31.6ecec1f8Merge pull request #3335 from github/mbg/ci/run-codeql-on-all-prs23da732Merge pull request #3334 from github/kaspersv/overlay-minor-commentsf7abc74Remove branch filter for PR event in CodeQL workflow32ada5eMerge branch 'main' into kaspersv/overlay-minor-comments75b2f49Merge pull request #3333 from github/kaspersv/overlay-no-resource-checks-optionf036b1cMerge branch 'main' into kaspersv/overlay-no-resource-checks-option58c5954Add comment to runnerSupportsOverlayAnalysisb02fa13Order feature flags alphabetically- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) -
@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) -
@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) -
@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency -
@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
We need to update our usage of cosign before merging this, otherwise the release flow will fail.
Reference: sigstore/cosign#4354