Chore(deps): Bump the github_actions_dependencies group across 1 directory with 7 updates #3077
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github_actions_dependencies group with 7 updates in the / directory:
2.35.32.35.54.2.44.3.0455.3.06.0.00.28.00.33.12.4.22.4.334Updates
shivammathur/setup-phpfrom 2.35.3 to 2.35.5Release notes
Sourced from shivammathur/setup-php's releases.
... (truncated)
Commits
bf6b4fbImprove sorting in tools.getSemverVersion8f81967Fix sorting in tools.getSemverVersion06512d9Update macos-latest in README [skip ci]1c302aeMark macOS 26 as supported [skip ci]dcffe28Fix jit config on arm6ffdb3dBump version to 2.35.5c97dacbMerge pull request #995 from shivammathur/dependabot/github_actions/develop/a...34f574eBump actions/setup-node from 4 to 5317a051Add fallback cache for keys in ppa.shdfcda83Add fallback url for composerUpdates
actions/cachefrom 4.2.4 to 4.3.0Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
Commits
0057852Merge pull request #1655 from actions/Link-/prepare-4.3.04f5ea67Update licensed cache9fcad95Upgrade actions/cache to 4.1.0 and prepare 4.3.0 release638ed79Merge pull request #1642 from actions/GhadimiR-patch-13862dccAdd note on runner versionsUpdates
actions/upload-artifactfrom 4 to 5Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.mdUpdates
SonarSource/sonarqube-scan-actionfrom 5.3.0 to 6.0.0Release notes
Sourced from SonarSource/sonarqube-scan-action's releases.
... (truncated)
Commits
fd88b7dSQSCANGHA-119 New Readme structure27a157dSQSCANGHA-118 Update the README to document the breaking change for args parsinge327da8NO-JIRA Add documentation for contributionff001fdSQSCANGHA-107 Migrate install-build-wrappera88c96dSQSCANGHA-107 Make room for install-build-wrapper actiona642810SQSCANGHA-112 SQSCANGHA-113 Fixes from review and keytool refactor60aee70NO-JIRA Disable fail fast on matrix jobs502204eNO-JIRA Fix test assertion0b794a0SQSCANGHA-112 Delete legacy shell scriptece10dfSQSCANGHA-112 Extract installation step and other fixesUpdates
aquasecurity/trivy-actionfrom 0.28.0 to 0.33.1Release notes
Sourced from aquasecurity/trivy-action's releases.
... (truncated)
Commits
b6643a2Update setup-trivy action to version v0.2.4 (#486)f9424c1Merge pull request #481 from aquasecurity/bump-trivy-175589825185abccbdev: delete fanal.db before testsa169870ci: update golden files on Trivy bump71f6a8fdev: add update-golden goalbf330b1test: update golden files644762eMerge pull request #482 from aquasecurity/fix-gh-actionsf2e2851chore(ci): Add oras to correctly setup sync jobs636fd3cfix: update tests7c0244bchore(deps): Update trivy to v0.65.0Updates
ossf/scorecard-actionfrom 2.4.2 to 2.4.3Release notes
Sourced from ossf/scorecard-action's releases.
Commits
4eaacf0bump docker to ghcr v2.4.3 (#1587)42e3a01🌱 Bump the github-actions group with 3 updates (#1585)88c07ac🌱 Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.6.0 (#1579)6c690f2Bump github.com/ossf/scorecard/v5 from v5.2.1 to v5.3.0 (#1586)92083b5📖 Fix recommended command to test the image in development (#1583)7975ea6🌱 Bump the docker-images group across 1 directory with 2 updates (#1...0d1a743🌱 Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (#1575)46e6e0c🌱 Bump the github-actions group with 2 updates (#1580)c3f1350🌱 Improve printing options (#1584)43e475b🌱 Bump golang.org/x/net from 0.42.0 to 0.44.0 (#1578)Updates
github/codeql-actionfrom 3 to 4Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
8ff870aRename new input toprocessed-sarif-path6f0fcbeRenameuploadSarif89d3359Improve test named79c0a1Fix incomplete comment5e37670Usepost-process-outputin PR checkdef04c1Add test foruploadSarifwith output directoryDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions