chore(deps): bump the actions group across 1 directory with 5 updates
Bumps the actions group with 5 updates in the / directory:
| Package | From | To |
|---|---|---|
| stefanzweifel/git-auto-commit-action | 5 |
6 |
| coursier/cache-action | 6.4.6 |
6.4.7 |
| golangci/golangci-lint-action | 6 |
8 |
| sigstore/cosign-installer | 3.8.1 |
3.8.2 |
| anchore/sbom-action | 0.18.0 |
0.20.0 |
Updates stefanzweifel/git-auto-commit-action from 5 to 6
Release notes
Sourced from stefanzweifel/git-auto-commit-action's releases.
v6.0.0
Added
- Throw error early if repository is in a detached state (#357)
Fixed
- Fix PAT instructions with Dependabot (#376)
@DreamsorcererRemoved
- Remove support for
create_branch,skip_checkout,skip_Fetch(#314)v5.2.0
Added
- Add
create_git_tag_onlyoption to skip commiting and always create a git-tag. (#364)@zMynxx- Add Test for
create_git_tag_onlyfeature (#367)@stefanzweifelFixed
v5.1.0
Changed
- Include
github.actor_idin defaultcommit_author(#354)@parkerbxyzFixed
- docs(README): fix broken protected branch docs link (#346)
@scarf005- Update README.md (#343)
@KludexDependency Updates
- Bump bats from 1.11.0 to 1.11.1 (#353)
@dependabot- Bump github/super-linter from 6 to 7 (#342)
@dependabot- Bump github/super-linter from 5 to 6 (#335)
@dependabotv5.0.1
Fixed
- Fail if attempting to execute git commands in a directory that is not a git-repo. (#326)
@ccomendantDependency Updates
- Bump bats from 1.10.0 to 1.11.0 (#325)
@dependabot- Bump release-drafter/release-drafter from 5 to 6 (#319)
@dependabotMisc
... (truncated)
Changelog
Sourced from stefanzweifel/git-auto-commit-action's changelog.
v5.0.0 - 2023-10-06
New major release that bumps the default runtime to Node 20. There are no other breaking changes.
Changed
- Update node version to node20 (#300)
@ryudaitakai- Add _log and _set_github_output functions (#273)
@stefanzweifelFixed
- Seems like there is an extra space (#288)
@pedroamador- Fix git-auto-commit.yml (#277)
@zcong1993Dependency Updates
- Bump actions/checkout from 3 to 4 (#302)
@dependabot- Bump bats from 1.9.0 to 1.10.0 (#293)
@dependabot- Bump github/super-linter from 4 to 5 (#289)
@dependabot- Bump bats from 1.8.2 to 1.9.0 (#282)
@dependabotv4.16.0 - 2022-12-02
Changed
- Don't commit files when only LF/CRLF changes (#265)
@ZeroRin- Update default email address of github-actions[bot] (#264)
@Teko012Fixed
Commits
3cc016cMerge pull request #375 from stefanzweifel/v6-nextddb7ae4Merge pull request #376 from Dreamsorcerer/patch-1b001e5fApply suggestions from code review6494dc6Fix PAT instructions with Dependabot7618051Add deprecated inputs to fix unbound variable issueae11462Merge pull request #371 from stefanzweifel/dependabot/npm_and_yarn/bats-1.12.03058f91Bump bats from 1.11.1 to 1.12.08ddf02dAdd git-auto-commit to warning texte7955f7Emit warning if deprecated/removed options are used739fd03Merge branch 'master' into v6-next- Additional commits viewable in compare view
Updates coursier/cache-action from 6.4.6 to 6.4.7
Release notes
Sourced from coursier/cache-action's releases.
v6.4.7
This release upgrades the
@actions/cachefrom 3.2.4 to 4.0.3. See the deprecation notice for cache v3:What's Changed
- Bump
@types/nodefrom 20.12.4 to 20.12.7 by@alexarchambaultin coursier/cache-action#667- Fix CI by
@alexarchambaultin coursier/cache-action#669- Bump
@types/nodefrom 20.12.4 to 22.14.1 by@dependabotin coursier/cache-action#664- Bump prettier from 3.2.5 to 3.5.3 by
@dependabotin coursier/cache-action#647- Bump peter-evans/create-pull-request from 6 to 7 by
@dependabotin coursier/cache-action#644- Bump
@actions/globfrom 0.4.0 to 0.5.0 by@dependabotin coursier/cache-action#641- Update dist by
@github-actionsin coursier/cache-action#670- Bump
@vercel/nccfrom 0.38.1 to 0.38.3 by@dependabotin coursier/cache-action#671- Update dist by
@github-actionsin coursier/cache-action#674- Bump
@actions/cachefrom 3.2.4 to 4.0.3 by@dependabotin coursier/cache-action#675- Update dist by
@github-actionsin coursier/cache-action#680Full Changelog: https://github.com/coursier/cache-action/compare/v6.4.6...6.4.7
Commits
4e26158Update dist (#680)c2b9068Bump@actions/cachefrom 3.2.4 to 4.0.3 (#675)f916ce2Update dist (#674)cd838abBump@vercel/nccfrom 0.38.1 to 0.38.3 (#671)f266508Update dist (#670)8a6e017Bump@actions/globfrom 0.4.0 to 0.5.0 (#641)42fb656Bump peter-evans/create-pull-request from 6 to 7 (#644)dfff62cBump prettier from 3.2.5 to 3.5.3 (#647)281c456Bump@types/nodefrom 20.12.4 to 22.14.1 (#664)fe9a235Fix CI (#669)- Additional commits viewable in compare view
Updates golangci/golangci-lint-action from 6 to 8
Release notes
Sourced from golangci/golangci-lint-action's releases.
v8.0.0
Requires
golangci-lintversion >=v2.1.0What's Changed
Changes
- feat: use absolute paths by default when using working-directory option by
@ldezin golangci/golangci-lint-action#1231Full Changelog: https://github.com/golangci/golangci-lint-action/compare/v7...v8.0.0
v7.0.1
What's Changed
Documentation
- docs: add note about github.workspace by
@mattjohnsonpintin golangci/golangci-lint-action#1218- docs: clarify that ’args: --path-mode=abs’ is needed for working-directory by
@HaraldNordgrenin golangci/golangci-lint-action#1230Dependencies
- build(deps): bump the dependencies group across 1 directory with 3 updates by
@dependabotin golangci/golangci-lint-action#1213- build(deps-dev): bump the dev-dependencies group with 3 updates by
@dependabotin golangci/golangci-lint-action#1215- build(deps-dev): bump the dev-dependencies group with 4 updates by
@dependabotin golangci/golangci-lint-action#1220- build(deps): bump
@types/nodefrom 22.13.14 to 22.14.0 in the dependencies group by@dependabotin golangci/golangci-lint-action#1221- build(deps-dev): bump the dev-dependencies group with 3 updates by
@dependabotin golangci/golangci-lint-action#1224- build(deps): bump
@types/nodefrom 22.14.0 to 22.14.1 in the dependencies group by@dependabotin golangci/golangci-lint-action#1225- build(deps-dev): bump the dev-dependencies group with 2 updates by
@dependabotin golangci/golangci-lint-action#1227New Contributors
@mattjohnsonpintmade their first contribution in golangci/golangci-lint-action#1218@HaraldNordgrenmade their first contribution in golangci/golangci-lint-action#1230Full Changelog: https://github.com/golangci/golangci-lint-action/compare/v7.0.0...v7.0.1
v7.0.0
⚠️ The GitHub Action v7 supports golangci-lint v2 only. ⚠️
What's Changed
Changes
- feat: golangci-lint v2 support by
@ldezin golangci/golangci-lint-action#1198Documentation
- docs: update annotation permissions by
@ldezin golangci/golangci-lint-action#1203- docs: fix checks permissions for annotations by
@kema-devin golangci/golangci-lint-action#1204Dependencies
- build(deps-dev): bump the dev-dependencies group with 3 updates by
@dependabotin golangci/golangci-lint-action#1207New Contributors
... (truncated)
Commits
4afd7338.0.07774f98feat: use absolute paths by default when using working-directory option (#1231)9fae48a7.0.116ece5edocs: clarify that ’args: --path-mode=abs’ is needed for working-directory (...a3942e2build(deps-dev): bump the dev-dependencies group with 2 updates (#1227)7ecb048build(deps): bump@types/nodefrom 22.14.0 to 22.14.1 in the dependencies gro...63a0d0ebuild(deps-dev): bump the dev-dependencies group with 3 updates (#1224)c2427fedocs: update problem matchers section642f8eebuild(deps): bump@types/nodefrom 22.13.14 to 22.14.0 in the dependencies gr...d84be92build(deps-dev): bump the dev-dependencies group with 4 updates (#1220)- Additional commits viewable in compare view
Updates sigstore/cosign-installer from 3.8.1 to 3.8.2
Release notes
Sourced from sigstore/cosign-installer's releases.
v3.8.2
What's Changed
- install cosign v2 from main in sigstore/cosign-installer#186
Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3...v3.8.2
Commits
3454372install cosign v2 from main (#186)b6ee8f8Bump actions/setup-go from 5.3.0 to 5.4.0 (#185)- See full diff in compare view
Updates anchore/sbom-action from 0.18.0 to 0.20.0
Release notes
Sourced from anchore/sbom-action's releases.
v0.20.0
Changes in v0.20.0
- chore(deps): update Syft to v1.24.0 (#522)
v0.19.0
Changes in v0.19.0
Commits
e11c554chore(deps): update Syft to v1.24.0 (#522)9f73021chore(deps): update Syft to v1.23.0 (#521)a669da5chore(deps): update Syft to v1.22.0 (#517)5aeee89chore(deps): bump peter-evans/create-pull-request from 7.0.6 to 7.0.8 (#519)79202aechore(deps): bump cross-spawn (#514)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
🛠 PR Checks Summary
🔴 Pending initial approval by a review team member, or review from tech-staff
Manual Checks (for Reviewers):
- [ ] IGNORE the bot requirements for this PR (force green CI check)
- [ ] Determine if infra needs to be updated before merging
Read More
🤖 This bot helps streamline PR reviews by verifying automated checks and providing guidance for contributors and reviewers.
✅ Automated Checks (for Contributors):
🔴 Pending initial approval by a review team member, or review from tech-staff
☑️ Contributor Actions:
- Fix any issues flagged by automated checks.
- Follow the Contributor Checklist to ensure your PR is ready for review.
- Add new tests, or document why they are unnecessary.
- Provide clear examples/screenshots, if necessary.
- Update documentation, if required.
- Ensure no breaking changes, or include
BREAKING CHANGEnotes. - Link related issues/PRs, where applicable.
☑️ Reviewer Actions:
- Complete manual checks for the PR, including the guidelines and additional checks if applicable.
📚 Resources:
Debug
Automated Checks
Pending initial approval by a review team member, or review from tech-staff
If
🟢 Condition met └── 🟢 And ├── 🟢 The base branch matches this pattern: ^master$ └── 🟢 Not (🔴 Pull request author is a member of the team: tech-staff)Then
🔴 Requirement not satisfied └── 🔴 If ├── 🟢 Condition │ └── 🟢 Or │ ├── 🟢 At least 1 user(s) of the organization reviewed the pull request (with state "APPROVED") │ ├── 🔴 At least 1 user(s) of the team tech-staff reviewed pull request │ └── 🔴 This pull request is a draft └── 🔴 Then └── 🔴 And ├── 🟢 Not (🔴 This label is applied to pull request: review/triage-pending) └── 🔴 At least 1 user(s) of the team tech-staff reviewed pull requestManual Checks
**IGNORE** the bot requirements for this PR (force green CI check)
If
🟢 Condition met └── 🟢 On every pull requestCan be checked by
- Any user with comment edit permission
Determine if infra needs to be updated before merging
If
🟢 Condition met └── 🟢 And ├── 🟢 The base branch matches this pattern: ^master$ └── 🟢 Or ├── 🔴 A changed file matches this pattern: Dockerfile ├── 🔴 A changed file matches this pattern: ^misc/deployments ├── 🔴 A changed file matches this pattern: ^misc/docker- ├── 🟢 A changed file matches this pattern: ^.github/workflows/releaser.*\.yml$ (filename: .github/workflows/releaser-master.yml) └── 🔴 A changed file matches this pattern: ^.github/workflows/staging\.yml$Can be checked by
- team devops
Codecov Report
:white_check_mark: All modified and coverable lines are covered by tests.
:loudspeaker: Thoughts on this report? Let us know!
Looks like these dependencies are updatable in another way, so this is no longer needed.