Commit Graph
489 Commits
Author SHA1 Message Date
dependabot[bot]andGitHub cc6f490671 build(deps): bump actions/checkout from 6.0.3 to 7.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6.0.3...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 18:22:09 +00:00
Jean-Philippe EvrardandGitHub 4800cf13b5 Merge pull request #1375 from kubereboot/dependabot/github_actions/jdx/mise-action-4.2.0
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
2026-06-29 20:20:13 +02:00
dependabot[bot]andGitHub 496c5061b1 build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jdx/mise-action/compare/v4.1.0...e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 17:52:56 +00:00
dependabot[bot]andGitHub 2c5e9b5009 build(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89...f06c13b6b1a9625abc9e6e439d9c05a8f2190e94)

---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
  dependency-version: 7.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 17:52:27 +00:00
Jean-Philippe EvrardandGitHub f2c74b3890 Merge pull request #1363 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.19.4
build(deps): bump step-security/harden-runner from 2.14.0 to 2.19.4
2026-06-29 18:57:35 +02:00
Jean-Philippe EvrardandGitHub c775910f6d Merge pull request #1355 from evrardjp/improve_testing
Simplify testing
2026-06-29 18:57:05 +02:00
Jean-Philippe EvrardandGitHub efdb3ab888 Merge pull request #1370 from kubereboot/dependabot/github_actions/jdx/mise-action-4.2.0
build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
2026-06-29 18:54:45 +02:00
dependabot[bot]andGitHub 5e19c8ac21 build(deps): bump actions/checkout from 6.0.1 to 7.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6.0.1...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-18 17:52:46 +00:00
dependabot[bot]andGitHub a9d8f3cf8e build(deps): bump jdx/mise-action from 4.1.0 to 4.2.0
Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jdx/mise-action/compare/dba19683ed58901619b14f395a24841710cb4925...e6a8b3978addb5a52f2b4cd9d91eafa7f0ab959d)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-18 17:52:24 +00:00
dependabot[bot]andGitHub 590101eb5f build(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.2.2
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 6.4.0 to 7.2.2.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/e435ccd777264be153ace6237001ef4d979d3a7a...5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89)

---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
  dependency-version: 7.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-11 16:29:26 +00:00
dependabot[bot]andGitHub 554421fd17 build(deps): bump step-security/harden-runner from 2.14.0 to 2.19.4
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.14.0 to 2.19.4.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](https://github.com/step-security/harden-runner/compare/v2.14.0...9af89fc71515a100421586dfdb3dc9c984fbf411)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.19.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-11 16:29:22 +00:00
Dharsan Baskar 162eb0a5f3 ci: unify YAML file extension to .yaml across config and workflows
Signed-off-by: Dharsan Baskar <git@dharsanb.com>
2026-06-11 13:57:28 +05:30
Dharsan Baskar 0f5cbf0b03 ci: add GoReleaser config verification on PRs and pushes
Signed-off-by: Dharsan Baskar <git@dharsanb.com>
2026-06-11 13:30:57 +05:30
Jean-Philippe EvrardandGitHub ca5b1015e8 Merge pull request #1358 from kubereboot/dependabot/github_actions/guyarb/golang-test-annoations-0.9.0
build(deps): bump guyarb/golang-test-annoations from 0.8.0 to 0.9.0
2026-06-10 20:17:58 +02:00
Jean-Philippe Evrard 48999c3d86 tests: Cleanup the test matrix for readability
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-10 20:04:41 +02:00
dependabot[bot]andGitHub c0db37c164 build(deps): bump guyarb/golang-test-annoations from 0.8.0 to 0.9.0
Bumps [guyarb/golang-test-annoations](https://github.com/guyarb/golang-test-annoations) from 0.8.0 to 0.9.0.
- [Release notes](https://github.com/guyarb/golang-test-annoations/releases)
- [Commits](https://github.com/guyarb/golang-test-annoations/compare/2941118d7ef622b1b3771d1ff6eae9e90659eb26...96fc379b171c49932041d6c789e73331a7bdeec1)

---
updated-dependencies:
- dependency-name: guyarb/golang-test-annoations
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-10 11:40:12 +00:00
dependabot[bot]andGitHub 260a3162af build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/ce360397dd3f832beb865e1373c09c0e9f86d70a...06116385d9baf250c9f4dcb4858b16962ea869c3)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-10 11:40:09 +00:00
Jean-Philippe Evrard 2a23325b81 chore(tests): Cleanup test matrix
There is no point of having a more complex series of jobs.
This puts all the manifests testing cases into one kind of
pipeline, simplifying debugging.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-09 09:25:47 +02:00
Jean-Philippe Evrard c36ae33c67 fix: stop building main branch containers
Without this, we will continue building and storing artifacts
that are used by less than 10% of our community. This means
maintaining different workflows and complicates goreleaser
for really no reason.

If someone has a strong opposition to this practice, please
tell me, I will revert this commit.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-09 09:20:06 +02:00
Jean-Philippe Evrard e531f64b85 feat(release): let GoReleaser manage artifacts
GoReleaser now builds the multi-arch images,
publishes SBOM/provenance metadata, signs image digests, and attaches
the generated combined Kubernetes manifest to tagged GitHub releases.

This is to have goReleaser as a single point of work for release
automation. With this, so tags and main commits follow one consistent
image pipeline.

We keep the CI and developer image builds intentionally local.
PR, periodic, main, and tag scan jobs build only `kured:dev` and scan that
local image with Trivy, which avoids pushing disposable images and keeps
the tested image identical to the one used by kind-based e2e tests.

Simplify the Makefile around the remaining artifact boundaries: `build` for a
local GoReleaser binary build, `dev-image` for local Docker/e2e/scan use, and
`release` for the GoReleaser publish path. Remove the old manual manifest
target because the release manifest is now generated during the tagged release
flow.

To avoid a mess with all the configuration files, I move everything into
a `.config` folder, for the tools supporting it.

This also meant updating golangci-lint to a valid v2 config, and simplify
the Dockerfile to the layout expected by GoReleaser `dockers_v2`
using `TARGETPLATFORM`.

Handle Prometheus client initialization errors explicitly so the stricter
errcheck configuration keeps the existing fail-closed reboot-blocking behavior,
to fix the golangci-lint issue that appeared.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-09 09:19:04 +02:00
Jean-Philippe EvrardandGitHub 20b968b224 Merge pull request #1353 from kubereboot/dependabot/github_actions/docker/login-action-4.2.0
build(deps): bump docker/login-action from 4.1.0 to 4.2.0
2026-06-09 09:12:56 +02:00
Jean-Philippe EvrardandGitHub 3d5d2865c9 Merge pull request #1354 from kubereboot/dependabot/github_actions/actions/checkout-6.0.3
build(deps): bump actions/checkout from 6.0.2 to 6.0.3
2026-06-09 09:11:34 +02:00
Jean-Philippe EvrardandGitHub b1f9863507 Merge pull request #1351 from kubereboot/dependabot/github_actions/jdx/mise-action-4.1.0
build(deps): bump jdx/mise-action from 4.0.1 to 4.1.0
2026-06-09 09:11:05 +02:00
dependabot[bot]andGitHub 4b8283b86e build(deps): bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 17:52:54 +00:00
dependabot[bot]andGitHub 4f624f7421 build(deps): bump docker/login-action from 4.1.0 to 4.2.0
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...650006c6eb7dba73a995cc03b0b2d7f5ca915bee)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 17:52:45 +00:00
dependabot[bot]andGitHub c5cb3b84a8 build(deps): bump actions/stale from 10.2.0 to 10.3.0
Bumps [actions/stale](https://github.com/actions/stale) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/stale/compare/b5d41d4e1d5dceea10e7104786b73624c18a190f...eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-version: 10.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 17:52:42 +00:00
dependabot[bot]andGitHub df57174e94 build(deps): bump jdx/mise-action from 4.0.1 to 4.1.0
Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.0.1 to 4.1.0.
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jdx/mise-action/compare/1648a7812b9aeae629881980618f079932869151...dba19683ed58901619b14f395a24841710cb4925)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 17:52:38 +00:00
Jean-Philippe Evrard b7f127b7ba Update Kured to latest kubernetes modules
Now that a new kind version is released supporting 1.36,
we can use it for our CI testing.

This commit:
- Bumps the kind version and its images to support the 1.36
- Ensure all the API calls are done with client-go 0.36
  (and dependent k8s deps), to allow future 1.37 release.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-08 19:03:13 +02:00
Jean-Philippe Evrard aa5e79531b Revert "chore: Bump mise"
This reverts the implementation of the bump mise, done
with commit 5c8754ceb2.

Instead of unfreezing the mise version completely, which could
expose us to supply chain attacks, we simply bump the version
manually.

It means we will have to fix the drift of mise versions using
another tool, as dependabot does not do it.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-08 14:41:25 +02:00
Jean-Philippe Evrard 5c8754ceb2 chore: Bump mise
Without this, mise will be stuck to a pre-defined version.
This auto bumps mise and will bump versions. It should not
be damaging for CI (quite the opposite, we will benefit
from cache).

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-08 14:02:01 +02:00
Jean-Philippe EvrardandGitHub 73712baba7 Merge pull request #1342 from evrardjp/get_rid_of_setup_go
Remove setup-go
2026-06-08 12:51:20 +02:00
Jean-Philippe EvrardandGitHub 3549e4475d Merge pull request #1335 from kubereboot/dependabot/github_actions/docker/build-push-action-7.2.0
build(deps): bump docker/build-push-action from 7.0.0 to 7.2.0
2026-06-08 12:51:01 +02:00
Jean-Philippe EvrardandGitHub 35d0dea4f7 Merge pull request #1334 from kubereboot/dependabot/github_actions/aquasecurity/trivy-action-0.36.0
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
2026-06-08 12:50:45 +02:00
Jean-Philippe EvrardandGitHub 42462f1ec8 Merge pull request #1333 from kubereboot/dependabot/github_actions/docker/setup-buildx-action-4.1.0
build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0
2026-06-08 12:50:28 +02:00
dependabot[bot]andGitHub 3b36f05a58 build(deps): bump docker/build-push-action from 7.0.0 to 7.2.0
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.0.0 to 7.2.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...f9f3042f7e2789586610d6e8b85c8f03e5195baf)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 10:29:39 +00:00
dependabot[bot]andGitHub c2da96ecb8 build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.35.0 to 0.36.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/57a97c7e7821a5776cebc9bb87c984fa69cba8f1...ed142fd0673e97e23eac54620cfb913e5ce36c25)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 10:29:32 +00:00
dependabot[bot]andGitHub 50728eca54 build(deps): bump github/codeql-action from 4.35.1 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.1 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...8aad20d150bbac5944a9f9d289da16a4b0d87c1e)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 10:29:18 +00:00
dependabot[bot]andGitHub c639d744c2 build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 10:29:14 +00:00
Jean-Philippe Evrard b5f6eca82e Remove setup-go
We use mise everywhere, so there is no need to setup go, mise
should take care of setting up all the go requirements.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-06-08 12:27:10 +02:00
dependabot[bot]andGitHub 3b7c3241ad build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.0 to 2.19.4.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...9af89fc71515a100421586dfdb3dc9c984fbf411)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.19.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-26 12:29:48 +00:00
Jean-Philippe Evrard 7f2d941c5c Alter bumping work of dependabot
Without this, dependabot would separate all the dependencies in
different PRs.

This is inefficient: The only group of PRs that need to be
separate, is kubernetes: We only want to bump them for a new
release.

On top of that, those kubernetes dependencies also need to be
bumped together.

This fixes the dependabot config to match that use case.

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-05-26 14:06:19 +02:00
Jean-Philippe Evrard 4f19b4d5fe Remove "next" test
During the policy change removing our "lagging behind", implemented
in 168fe81bb4 [1], we forgot to
remove one "next" test.

This should fix it.

[1]: https://github.com/kubereboot/kured/commit/168fe81bb40715b28a51e56ef10804e4275ff64c

Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party>
2026-05-26 13:14:01 +02:00
Jean-Philippe EvrardandGitHub 66d3ad3185 Merge pull request #1322 from kubereboot/dependabot/github_actions/actions/setup-go-6.4.0
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0
2026-05-26 10:35:03 +02:00
Jean-Philippe EvrardandGitHub 4bfa3363b7 Merge pull request #1321 from kubereboot/dependabot/github_actions/actions/upload-artifact-7.0.1
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
2026-05-26 10:34:28 +02:00
Jean-Philippe EvrardandGitHub 6f8c40f251 Merge pull request #1320 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.19.0
build(deps): bump step-security/harden-runner from 2.13.2 to 2.19.0
2026-05-26 10:34:00 +02:00
Jean-Philippe EvrardandGitHub afa59056b4 Merge pull request #1319 from kubereboot/dependabot/github_actions/docker/login-action-4.1.0
build(deps): bump docker/login-action from 4.0.0 to 4.1.0
2026-05-26 10:32:58 +02:00
Jean-Philippe EvrardandGitHub 086b3eee01 Merge pull request #1304 from kubereboot/dependabot/github_actions/actions/dependency-review-action-4.9.0
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.9.0
2026-05-26 10:31:52 +02:00
dependabot[bot]andGitHub 8d4c431949 build(deps): bump actions/setup-go from 6.3.0 to 6.4.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.3.0 to 6.4.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-23 18:07:11 +00:00
dependabot[bot]andGitHub fece55e37a build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-23 18:07:06 +00:00
dependabot[bot]andGitHub d062920e53 build(deps): bump step-security/harden-runner from 2.13.2 to 2.19.0
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.13.2 to 2.19.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](https://github.com/step-security/harden-runner/compare/95d9a5deda9de15063e7595e9719c11c38c90ae2...8d3c67de8e2fe68ef647c8db1e6a09f647780f40)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-23 18:07:02 +00:00