scorecard-webapp
scorecard-webapp copied to clipboard
:seedling: Bump github.com/rhysd/actionlint from 1.7.8 to 1.7.9 in the gomod group
Bumps the gomod group with 1 update: github.com/rhysd/actionlint.
Updates github.com/rhysd/actionlint from 1.7.8 to 1.7.9
Release notes
Sourced from github.com/rhysd/actionlint's releases.
v1.7.9
- Add support for
ubuntu-slimrunner label. (#585, thanks@cestorer)- Check input deprecation in action by checking
deprecationMessageproperty. Using a deprecated input is reported as error if it is not marked asrequired. See the document for more details. (#580)- uses: reviewdog/action-actionlint@v1 with: # ERROR: Using a deprecated input fail_on_error: true- Add support for the Custom images feature.
- Support
image_versionworkflow trigger.on: image_version: names: - "MyNewImage" - "MyOtherImage" versions: - 1.* - 2.*- Support
jobs.<job_id>.snapshotsyntax. To make actionlint recognize your own image generation runner, useself-hosted-runner.labelsconfig.jobs: build: runs-on: my-image-generation-runner snapshot: image-name: my-custom-image version: 2.*- Report constant conditions at
if:likeif: trueas error. Only very simple expressions liketrueorfalseare detected for now. See the document for more details.- Fix some invalid permissions are not reported as error in
id-tokenandmodelsscopes. (#582, thanks@holtkampjs)- Fix
argsandentrypointinputs are not recognized atuses:when it's not a Docker action. (#550)- Set correct column in source position of YAML parse error.
- Fix
credentialscannot be configured with${{ }}. (#590)- Improve messages in syntax errors on parsing steps (
run:anduses:). Available keys suggestion is now more accurate and unexpected keys are detected more accurately.- Fix the order of errors can be non-deterministic when multiple errors are caused at the same source positions.
- Improve error messages showing suggestions on detecting invalid permissions.
- Add instruction for installing actionlint with mise package manager. (#589, thanks
@jylenhof)- Fix outdated URLs in the document.
- Add new
actionlint.AllContextsmap constant in Go API that contains the information about all context availability.- Update popular actions data set to the latest with several major versions of actions and the following new actions.
anthropics/claude-code-actionopenai/codex-actiongoogle-github-actions/run-gemini-cli- Add
make covtask to easily generate a code coverage report.- Make installing the formula version of
actionlintpacakge from tap of this repository with Homebrew a hard error. Install the cask version instead following the instruction in the error message.
Changelog
Sourced from github.com/rhysd/actionlint's changelog.
v1.7.9 - 2025-11-21
- Add support for
ubuntu-slimrunner label. (#585, thanks@cestorer)- Check input deprecation in action by checking
deprecationMessageproperty. Using a deprecated input is reported as error if it is not marked asrequired. See the document for more details. (#580)- uses: reviewdog/action-actionlint@v1 with: # ERROR: Using a deprecated input fail_on_error: true- Add support for the Custom images feature.
- Support
image_versionworkflow trigger.on: image_version: names: - "MyNewImage" - "MyOtherImage" versions: - 1.* - 2.*- Support
jobs.<job_id>.snapshotsyntax. To make actionlint recognize your own image generation runner, useself-hosted-runner.labelsconfig.jobs: build: runs-on: my-image-generation-runner snapshot: image-name: my-custom-image version: 2.*- Report constant conditions at
if:likeif: trueas error. Only very simple expressions liketrueorfalseare detected for now. See the document for more details.- Fix some invalid permissions are not reported as error in
id-tokenandmodelsscopes. (#582, thanks@holtkampjs)- Fix
argsandentrypointinputs are not recognized atuses:when it's not a Docker action. (#550)- Set correct column in source position of YAML parse error.
- Fix
credentialscannot be configured with${{ }}. (#590)- Improve messages in syntax errors on parsing steps (
run:anduses:). Available keys suggestion is now more accurate and unexpected keys are detected more accurately.- Fix the order of errors can be non-deterministic when multiple errors are caused at the same source positions.
- Improve error messages showing suggestions on detecting invalid permissions.
- Add instruction for installing actionlint with mise package manager. (#589, thanks
@jylenhof)- Fix outdated URLs in the document.
- Add new
actionlint.AllContextsmap constant in Go API that contains the information about all context availability.- Update popular actions data set to the latest with several major versions of actions and the following new actions.
anthropics/claude-code-actionopenai/codex-actiongoogle-github-actions/run-gemini-cli- Add
make covtask to easily generate a code coverage report.- Make installing the formula version of
actionlintpacakge from tap of this repository with Homebrew a hard error. Install the cask version instead following the instruction in the error message.[Changes][v1.7.9]
... (truncated)
Commits
a443f34bump up version to v1.7.9c48cd05fix deprecated GoReleaser configa03892fupdate the popular actions data set foractions/checkout@v6c85ea65make installing formula version of actionlint erroreb4d397update playground npm dependenciesbaee0a7fix webhook generation script56ecc8caddanthropics/claude-code-action,openai/codex-action, `google-github-ac...5ed2da8add more tests for parsing and checkingcontainerandservicesdbcf56freportimageis missing in containere4ba27efix credentials cannot be initialized with${{ }}(fix #590)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
Deploy Preview for ossf-scorecard canceled.
| Name | Link |
|---|---|
| Latest commit | f8d3e81c878327521b6eb0a7e401820565ba1421 |
| Latest deploy log | https://app.netlify.com/projects/ossf-scorecard/deploys/6920a94c83299f0008cd5463 |
Looks like github.com/rhysd/actionlint is updatable in another way, so this is no longer needed.