Jean-Philippe Evrard and GitHub
5d048d7e22
Merge pull request #1402 from kubereboot/dependabot/github_actions/actions/checkout-7.0.1
...
build(deps): bump actions/checkout from 7.0.0 to 7.0.1
2026-08-10 11:49:48 +02:00
Jean-Philippe Evrard and GitHub
ace7ad747a
Merge pull request #1403 from kubereboot/dependabot/github_actions/jdx/mise-action-4.2.3
...
build(deps): bump jdx/mise-action from 4.2.0 to 4.2.3
2026-08-10 11:49:32 +02:00
dependabot[bot] and GitHub
6cf396e51b
build(deps): bump jdx/mise-action from 4.2.0 to 4.2.3
...
Bumps [jdx/mise-action](https://github.com/jdx/mise-action ) from 4.2.0 to 4.2.3.
- [Release notes](https://github.com/jdx/mise-action/releases )
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jdx/mise-action/compare/e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d...9e7f7633ff6f6d6048a9418a68d48f288f50eb14 )
---
updated-dependencies:
- dependency-name: jdx/mise-action
dependency-version: 4.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-29 06:48:25 +00:00
dependabot[bot] and GitHub
4d985c7c70
build(deps): bump actions/checkout from 7.0.0 to 7.0.1
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-29 06:48:18 +00:00
Jean-Philippe Evrard and GitHub
1f7f15f25e
Merge pull request #1389 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.20.0
2026-07-29 08:47:37 +02:00
Jean-Philippe Evrard and GitHub
ec37867496
Merge pull request #1398 from evrardjp/coherent-go-mod-and-mise-update
2026-07-29 08:46:47 +02:00
dependabot[bot] and GitHub
07d5f1fd21
build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0
...
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.19.4 to 2.20.0.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](https://github.com/step-security/harden-runner/compare/9af89fc71515a100421586dfdb3dc9c984fbf411...bf7454d06d71f1098171f2acdf0cd4708d7b5920 )
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-version: 2.20.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-28 17:32:54 +00:00
Jean-Philippe Evrard
253038c5d7
Bump codeql together
...
Without this, multiple codeql actions are bumped separately,
and there is a risk of failure like in [0][1][2].
[0]: https://github.com/kubereboot/kured/pull/1381
[1]: https://github.com/kubereboot/kured/pull/1384
[2]: https://github.com/kubereboot/kured/pull/1386
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-07-28 17:51:52 +02:00
Jean-Philippe Evrard
18d163a2b1
Ensure mise and go.mod are aligned
...
go.mod and the tool versions (here, mise) need to be in sync.
This creates a test to verify they are aligned.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-07-28 17:51:27 +02:00
dependabot[bot] and GitHub
e45faee425
build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-03 16:37:30 +00:00
Jean-Philippe Evrard and GitHub
3993e90d6d
Merge pull request #1383 from kubereboot/dependabot/github_actions/github/codeql-action/upload-sarif-4.36.3
...
build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.36.3
2026-07-03 18:36:24 +02:00
dependabot[bot] and GitHub
a278d5bee5
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.36.2 to 4.36.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:52:50 +00:00
dependabot[bot] and GitHub
a1baec89fd
build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-01 17:52:36 +00:00
dependabot[bot] and GitHub
cc6f490671
build(deps): bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v6.0.3...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 18:22:09 +00:00
Jean-Philippe Evrard and GitHub
4800cf13b5
Merge pull request #1375 from kubereboot/dependabot/github_actions/jdx/mise-action-4.2.0
...
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
2026-06-29 20:20:13 +02:00
dependabot[bot] and GitHub
496c5061b1
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
...
Bumps [jdx/mise-action](https://github.com/jdx/mise-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/jdx/mise-action/releases )
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jdx/mise-action/compare/v4.1.0...e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d )
---
updated-dependencies:
- dependency-name: jdx/mise-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 17:52:56 +00:00
dependabot[bot] and GitHub
2c5e9b5009
build(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3
...
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 7.2.2 to 7.2.3.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89...f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-version: 7.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 17:52:27 +00:00
Jean-Philippe Evrard and GitHub
f2c74b3890
Merge pull request #1363 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.19.4
...
build(deps): bump step-security/harden-runner from 2.14.0 to 2.19.4
2026-06-29 18:57:35 +02:00
Jean-Philippe Evrard and GitHub
c775910f6d
Merge pull request #1355 from evrardjp/improve_testing
...
Simplify testing
2026-06-29 18:57:05 +02:00
Jean-Philippe Evrard and GitHub
efdb3ab888
Merge pull request #1370 from kubereboot/dependabot/github_actions/jdx/mise-action-4.2.0
...
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
2026-06-29 18:54:45 +02:00
dependabot[bot] and GitHub
5e19c8ac21
build(deps): bump actions/checkout from 6.0.1 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v6.0.1...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-18 17:52:46 +00:00
dependabot[bot] and GitHub
a9d8f3cf8e
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
...
Bumps [jdx/mise-action](https://github.com/jdx/mise-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/jdx/mise-action/releases )
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jdx/mise-action/compare/dba19683ed58901619b14f395a24841710cb4925...e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d )
---
updated-dependencies:
- dependency-name: jdx/mise-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-18 17:52:24 +00:00
dependabot[bot] and GitHub
590101eb5f
build(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.2.2
...
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 6.4.0 to 7.2.2.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/e435ccd777264be153ace6237001ef4d979d3a7a...5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-version: 7.2.2
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-11 16:29:26 +00:00
dependabot[bot] and GitHub
554421fd17
build(deps): bump step-security/harden-runner from 2.14.0 to 2.19.4
...
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.14.0 to 2.19.4.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](https://github.com/step-security/harden-runner/compare/v2.14.0...9af89fc71515a100421586dfdb3dc9c984fbf411 )
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-version: 2.19.4
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-11 16:29:22 +00:00
Dharsan Baskar
162eb0a5f3
ci: unify YAML file extension to .yaml across config and workflows
...
Signed-off-by: Dharsan Baskar <git@dharsanb.com >
2026-06-11 13:57:28 +05:30
Dharsan Baskar
0f5cbf0b03
ci: add GoReleaser config verification on PRs and pushes
...
Signed-off-by: Dharsan Baskar <git@dharsanb.com >
2026-06-11 13:30:57 +05:30
Jean-Philippe Evrard and GitHub
ca5b1015e8
Merge pull request #1358 from kubereboot/dependabot/github_actions/guyarb/golang-test-annoations-0.9.0
...
build(deps): bump guyarb/golang-test-annoations from 0.8.0 to 0.9.0
2026-06-10 20:17:58 +02:00
Jean-Philippe Evrard
48999c3d86
tests: Cleanup the test matrix for readability
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-10 20:04:41 +02:00
dependabot[bot] and GitHub
c0db37c164
build(deps): bump guyarb/golang-test-annoations from 0.8.0 to 0.9.0
...
Bumps [guyarb/golang-test-annoations](https://github.com/guyarb/golang-test-annoations ) from 0.8.0 to 0.9.0.
- [Release notes](https://github.com/guyarb/golang-test-annoations/releases )
- [Commits](https://github.com/guyarb/golang-test-annoations/compare/2941118d7ef622b1b3771d1ff6eae9e90659eb26...96fc379b171c49932041d6c789e73331a7bdeec1 )
---
updated-dependencies:
- dependency-name: guyarb/golang-test-annoations
dependency-version: 0.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-10 11:40:12 +00:00
dependabot[bot] and GitHub
260a3162af
build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/ce360397dd3f832beb865e1373c09c0e9f86d70a...06116385d9baf250c9f4dcb4858b16962ea869c3 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-10 11:40:09 +00:00
Jean-Philippe Evrard
2a23325b81
chore(tests): Cleanup test matrix
...
There is no point of having a more complex series of jobs.
This puts all the manifests testing cases into one kind of
pipeline, simplifying debugging.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-09 09:25:47 +02:00
Jean-Philippe Evrard
c36ae33c67
fix: stop building main branch containers
...
Without this, we will continue building and storing artifacts
that are used by less than 10% of our community. This means
maintaining different workflows and complicates goreleaser
for really no reason.
If someone has a strong opposition to this practice, please
tell me, I will revert this commit.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-09 09:20:06 +02:00
Jean-Philippe Evrard
e531f64b85
feat(release): let GoReleaser manage artifacts
...
GoReleaser now builds the multi-arch images,
publishes SBOM/provenance metadata, signs image digests, and attaches
the generated combined Kubernetes manifest to tagged GitHub releases.
This is to have goReleaser as a single point of work for release
automation. With this, so tags and main commits follow one consistent
image pipeline.
We keep the CI and developer image builds intentionally local.
PR, periodic, main, and tag scan jobs build only `kured:dev` and scan that
local image with Trivy, which avoids pushing disposable images and keeps
the tested image identical to the one used by kind-based e2e tests.
Simplify the Makefile around the remaining artifact boundaries: `build` for a
local GoReleaser binary build, `dev-image` for local Docker/e2e/scan use, and
`release` for the GoReleaser publish path. Remove the old manual manifest
target because the release manifest is now generated during the tagged release
flow.
To avoid a mess with all the configuration files, I move everything into
a `.config` folder, for the tools supporting it.
This also meant updating golangci-lint to a valid v2 config, and simplify
the Dockerfile to the layout expected by GoReleaser `dockers_v2`
using `TARGETPLATFORM`.
Handle Prometheus client initialization errors explicitly so the stricter
errcheck configuration keeps the existing fail-closed reboot-blocking behavior,
to fix the golangci-lint issue that appeared.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-09 09:19:04 +02:00
Jean-Philippe Evrard and GitHub
20b968b224
Merge pull request #1353 from kubereboot/dependabot/github_actions/docker/login-action-4.2.0
...
build(deps): bump docker/login-action from 4.1.0 to 4.2.0
2026-06-09 09:12:56 +02:00
Jean-Philippe Evrard and GitHub
3d5d2865c9
Merge pull request #1354 from kubereboot/dependabot/github_actions/actions/checkout-6.0.3
...
build(deps): bump actions/checkout from 6.0.2 to 6.0.3
2026-06-09 09:11:34 +02:00
Jean-Philippe Evrard and GitHub
b1f9863507
Merge pull request #1351 from kubereboot/dependabot/github_actions/jdx/mise-action-4.1.0
...
build(deps): bump jdx/mise-action from 4.0.1 to 4.1.0
2026-06-09 09:11:05 +02:00
dependabot[bot] and GitHub
4b8283b86e
build(deps): bump actions/checkout from 6.0.2 to 6.0.3
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 17:52:54 +00:00
dependabot[bot] and GitHub
4f624f7421
build(deps): bump docker/login-action from 4.1.0 to 4.2.0
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...650006c6eb7dba73a995cc03b0b2d7f5ca915bee )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 17:52:45 +00:00
dependabot[bot] and GitHub
c5cb3b84a8
build(deps): bump actions/stale from 10.2.0 to 10.3.0
...
Bumps [actions/stale](https://github.com/actions/stale ) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/stale/compare/b5d41d4e1d5dceea10e7104786b73624c18a190f...eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899 )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 10.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 17:52:42 +00:00
dependabot[bot] and GitHub
df57174e94
build(deps): bump jdx/mise-action from 4.0.1 to 4.1.0
...
Bumps [jdx/mise-action](https://github.com/jdx/mise-action ) from 4.0.1 to 4.1.0.
- [Release notes](https://github.com/jdx/mise-action/releases )
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jdx/mise-action/compare/1648a7812b9aeae629881980618f079932869151...dba19683ed58901619b14f395a24841710cb4925 )
---
updated-dependencies:
- dependency-name: jdx/mise-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 17:52:38 +00:00
Jean-Philippe Evrard
b7f127b7ba
Update Kured to latest kubernetes modules
...
Now that a new kind version is released supporting 1.36,
we can use it for our CI testing.
This commit:
- Bumps the kind version and its images to support the 1.36
- Ensure all the API calls are done with client-go 0.36
(and dependent k8s deps), to allow future 1.37 release.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-08 19:03:13 +02:00
Jean-Philippe Evrard
aa5e79531b
Revert "chore: Bump mise"
...
This reverts the implementation of the bump mise, done
with commit 5c8754ceb2 .
Instead of unfreezing the mise version completely, which could
expose us to supply chain attacks, we simply bump the version
manually.
It means we will have to fix the drift of mise versions using
another tool, as dependabot does not do it.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-08 14:41:25 +02:00
Jean-Philippe Evrard
5c8754ceb2
chore: Bump mise
...
Without this, mise will be stuck to a pre-defined version.
This auto bumps mise and will bump versions. It should not
be damaging for CI (quite the opposite, we will benefit
from cache).
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-08 14:02:01 +02:00
Jean-Philippe Evrard and GitHub
73712baba7
Merge pull request #1342 from evrardjp/get_rid_of_setup_go
...
Remove setup-go
2026-06-08 12:51:20 +02:00
Jean-Philippe Evrard and GitHub
3549e4475d
Merge pull request #1335 from kubereboot/dependabot/github_actions/docker/build-push-action-7.2.0
...
build(deps): bump docker/build-push-action from 7.0.0 to 7.2.0
2026-06-08 12:51:01 +02:00
Jean-Philippe Evrard and GitHub
35d0dea4f7
Merge pull request #1334 from kubereboot/dependabot/github_actions/aquasecurity/trivy-action-0.36.0
...
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
2026-06-08 12:50:45 +02:00
Jean-Philippe Evrard and GitHub
42462f1ec8
Merge pull request #1333 from kubereboot/dependabot/github_actions/docker/setup-buildx-action-4.1.0
...
build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0
2026-06-08 12:50:28 +02:00
dependabot[bot] and GitHub
3b36f05a58
build(deps): bump docker/build-push-action from 7.0.0 to 7.2.0
...
Bumps [docker/build-push-action](https://github.com/docker/build-push-action ) from 7.0.0 to 7.2.0.
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...f9f3042f7e2789586610d6e8b85c8f03e5195baf )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-version: 7.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 10:29:39 +00:00
dependabot[bot] and GitHub
c2da96ecb8
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.35.0 to 0.36.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/57a97c7e7821a5776cebc9bb87c984fa69cba8f1...ed142fd0673e97e23eac54620cfb913e5ce36c25 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 10:29:32 +00:00
dependabot[bot] and GitHub
50728eca54
build(deps): bump github/codeql-action from 4.35.1 to 4.36.2
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 4.35.1 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...8aad20d150bbac5944a9f9d289da16a4b0d87c1e )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 10:29:18 +00:00