Mend Renovate
|
59f6ba3e00
|
chore(deps): update github-actions (#651)
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://togithub.com/actions/setup-node) | action
| minor | `v3.6.0` -> `v3.7.0` |
| [github/codeql-action](https://togithub.com/github/codeql-action) |
action | minor | `v2.3.6` -> `v2.20.4` |
| [ossf/scorecard-action](https://togithub.com/ossf/scorecard-action) |
action | minor | `v2.1.3` -> `v2.2.0` |
---
### ⚠ Dependency Lookup Warnings ⚠
Warnings were logged while processing this repo. Please check the
Dependency Dashboard for more information.
---
### Release Notes
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
###
[`v3.7.0`](https://togithub.com/actions/setup-node/releases/tag/v3.7.0)
[Compare
Source](https://togithub.com/actions/setup-node/compare/v3.6.0...v3.7.0)
##### What's Changed
In scope of this release we added a logic to save an additional cache
path for yarn 3 ([related pull
request](https://togithub.com/actions/setup-node/pull/744) and [feature
request](https://togithub.com/actions/setup-node/issues/325)). Moreover,
we added functionality to use all the sub directories derived from
`cache-dependency-path` input and add detect all dependencies
directories to cache (related [pull
request](https://togithub.com/actions/setup-node/pull/735) and [feature
request](https://togithub.com/actions/setup-node/issues/488)).
##### Besides, we made such changes as:
- Replace workflow badge with new badge by
[@​jongwooo](https://togithub.com/jongwooo) in
[https://github.com/actions/setup-node/pull/653](https://togithub.com/actions/setup-node/pull/653)
- Fix a minor typo by [@​phanan](https://togithub.com/phanan) in
[https://github.com/actions/setup-node/pull/662](https://togithub.com/actions/setup-node/pull/662)
- docs: fix typo in advanced-usage.md by
[@​remarkablemark](https://togithub.com/remarkablemark) in
[https://github.com/actions/setup-node/pull/697](https://togithub.com/actions/setup-node/pull/697)
- bugfix: Don't attempt to use Windows fallbacks on non-Windows OSes by
[@​domdomegg](https://togithub.com/domdomegg) in
[https://github.com/actions/setup-node/pull/718](https://togithub.com/actions/setup-node/pull/718)
- Update to node 18.x by
[@​feelepxyz](https://togithub.com/feelepxyz) in
[https://github.com/actions/setup-node/pull/751](https://togithub.com/actions/setup-node/pull/751)
- Remove implicit dependencies by
[@​nikolai-laevskii](https://togithub.com/nikolai-laevskii) in
[https://github.com/actions/setup-node/pull/758](https://togithub.com/actions/setup-node/pull/758)
- Fix description about ensuring workflow access to private package by
[@​x86chi](https://togithub.com/x86chi) in
[https://github.com/actions/setup-node/pull/704](https://togithub.com/actions/setup-node/pull/704)
##### New Contributors
- [@​jongwooo](https://togithub.com/jongwooo) made their first
contribution in
[https://github.com/actions/setup-node/pull/653](https://togithub.com/actions/setup-node/pull/653)
- [@​phanan](https://togithub.com/phanan) made their first
contribution in
[https://github.com/actions/setup-node/pull/662](https://togithub.com/actions/setup-node/pull/662)
- [@​remarkablemark](https://togithub.com/remarkablemark) made
their first contribution in
[https://github.com/actions/setup-node/pull/697](https://togithub.com/actions/setup-node/pull/697)
- [@​domdomegg](https://togithub.com/domdomegg) made their first
contribution in
[https://github.com/actions/setup-node/pull/718](https://togithub.com/actions/setup-node/pull/718)
- [@​feelepxyz](https://togithub.com/feelepxyz) made their first
contribution in
[https://github.com/actions/setup-node/pull/751](https://togithub.com/actions/setup-node/pull/751)
- [@​nikolai-laevskii](https://togithub.com/nikolai-laevskii) made
their first contribution in
[https://github.com/actions/setup-node/pull/758](https://togithub.com/actions/setup-node/pull/758)
- [@​x86chi](https://togithub.com/x86chi) made their first
contribution in
[https://github.com/actions/setup-node/pull/704](https://togithub.com/actions/setup-node/pull/704)
**Full Changelog**:
https://github.com/actions/setup-node/compare/v3...v3.7.0
</details>
<details>
<summary>github/codeql-action (github/codeql-action)</summary>
###
[`v2.20.4`](https://togithub.com/github/codeql-action/compare/v2.20.3...v2.20.4)
[Compare
Source](https://togithub.com/github/codeql-action/compare/v2.20.3...v2.20.4)
###
[`v2.20.3`](https://togithub.com/github/codeql-action/compare/v2.20.2...v2.20.3)
[Compare
Source](https://togithub.com/github/codeql-action/compare/v2.20.2...v2.20.3)
###
[`v2.20.2`](https://togithub.com/github/codeql-action/compare/v2.20.1...v2.20.2)
[Compare
Source](https://togithub.com/github/codeql-action/compare/v2.20.1...v2.20.2)
###
[`v2.20.1`](https://togithub.com/github/codeql-action/compare/v2.20.0...v2.20.1)
[Compare
Source](https://togithub.com/github/codeql-action/compare/v2.20.0...v2.20.1)
###
[`v2.20.0`](https://togithub.com/github/codeql-action/compare/v2.3.6...v2.20.0)
[Compare
Source](https://togithub.com/github/codeql-action/compare/v2.3.6...v2.20.0)
</details>
<details>
<summary>ossf/scorecard-action (ossf/scorecard-action)</summary>
###
[`v2.2.0`](https://togithub.com/ossf/scorecard-action/releases/tag/v2.2.0)
[Compare
Source](https://togithub.com/ossf/scorecard-action/compare/v2.1.3...v2.2.0)
#### What's Changed
- 🌱 Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0
by [@​spencerschrock](https://togithub.com/spencerschrock) in
[https://github.com/ossf/scorecard-action/pull/1192](https://togithub.com/ossf/scorecard-action/pull/1192)
#### Scorecard Result Viewer
Thanks to contributions from
[@​cynthia-sg](https://togithub.com/cynthia-sg) and
[@​tegioz](https://togithub.com/tegioz) at
[CLOMonitor](https://togithub.com/cncf/clomonitor), there is a new
Scorecard Result visualization page at
`https://securityscorecards.dev/viewer/?uri=<project-url>`.
-
[https://github.com/ossf/scorecard-webapp/pull/406](https://togithub.com/ossf/scorecard-webapp/pull/406)
-
[https://github.com/ossf/scorecard-webapp/pull/422](https://togithub.com/ossf/scorecard-webapp/pull/422)
As an example, you can see our own score visualized
[here](https://securityscorecards.dev/viewer/?uri=github.com/ossf/scorecard)
Checkout our
[README](08b4669551/README.md (scorecard-badge))
to learn how to link your README badge to the new visualization page.
#### Publishing Results
This release contains two fixes which will improve the user experience
when `publish_results` is `true`
- Runs that fail our [workflow
restrictions](08b4669551/README.md (workflow-restrictions))
will fail with a 400 response indicating the problem, instead of a vague
500 status.
([https://github.com/ossf/scorecard-action/pull/1156](https://togithub.com/ossf/scorecard-action/pull/1156),
resolved
[https://github.com/ossf/scorecard-action/issues/1150](https://togithub.com/ossf/scorecard-action/issues/1150))
- Scorecard action will retry when signing results and submitting them
to our web API. This should help with flakiness from connection
failures.
([https://github.com/ossf/scorecard-action/pull/1191](https://togithub.com/ossf/scorecard-action/pull/1191))
#### Docs
- 📖 Update README to accept fine-grained tokens by
[@​pnacht](https://togithub.com/pnacht) in
[https://github.com/ossf/scorecard-action/pull/1175](https://togithub.com/ossf/scorecard-action/pull/1175)
- 📖 Update installation instructions to match current GitHub UI by
[@​joycebrum](https://togithub.com/joycebrum) in
[https://github.com/ossf/scorecard-action/pull/1153](https://togithub.com/ossf/scorecard-action/pull/1153)
- 📖 Document the GitHub action workflow restrictions when publishing
results. by
[@​spencerschrock](https://togithub.com/spencerschrock) in
#### New Contributors
- [@​bobcallaway](https://togithub.com/bobcallaway) made their
first contribution in
[https://github.com/ossf/scorecard-action/pull/1140](https://togithub.com/ossf/scorecard-action/pull/1140)
- [@​pnacht](https://togithub.com/pnacht) made their first
contribution in
[https://github.com/ossf/scorecard-action/pull/1175](https://togithub.com/ossf/scorecard-action/pull/1175)
**Full Changelog**:
https://github.com/ossf/scorecard-action/compare/v2.1.3...v2.2.0
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://togithub.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/slsa-framework/slsa-verifier).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNS4xNDQuMiIsInVwZGF0ZWRJblZlciI6IjM2LjUuMyIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->
Signed-off-by: Mend Renovate <bot@renovateapp.com>
|
2023-07-18 10:51:23 +09:00 |
|
Mend Renovate
|
3ee6cee147
|
chore(deps): update github-actions (#607)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-06-12 09:44:31 +09:00 |
|
Mend Renovate
|
8da58c6c6d
|
chore(deps): update github/codeql-action action to v2.3.3 (#585)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Co-authored-by: asraa <asraa@google.com>
|
2023-05-08 16:30:17 +00:00 |
|
Mend Renovate
|
515b41ca3f
|
chore(deps): update github/codeql-action action to v2.3.2 (#569)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-05-01 09:48:55 +09:00 |
|
Mend Renovate
|
e1ea1da472
|
chore(deps): update github-actions (#560)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-04-18 10:52:54 +09:00 |
|
Mend Renovate
|
9c3152fe9f
|
chore(deps): update github-actions (#544)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Co-authored-by: Ian Lewis <ianlewis@google.com>
|
2023-04-11 02:09:29 +00:00 |
|
Mend Renovate
|
ed7976a0d4
|
chore(deps): update github-actions (#529)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-03-24 14:36:38 +00:00 |
|
Mend Renovate
|
9f57e6add9
|
chore(deps): update github-actions (#502)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Co-authored-by: Ian Lewis <ianlewis@google.com>
|
2023-03-06 00:48:50 +00:00 |
|
Mend Renovate
|
13b4c3e75b
|
chore(deps): update github/codeql-action action to v2.2.4 (#480)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-02-13 14:36:07 +00:00 |
|
Mend Renovate
|
9578b3838e
|
chore(deps): update github-actions (#460)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-01-30 05:33:14 -08:00 |
|
Mend Renovate
|
5eea7c5537
|
chore(deps): update github/codeql-action action to v2.1.39 (#452)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Co-authored-by: asraa <asraa@google.com>
|
2023-01-25 15:59:45 +00:00 |
|
Mend Renovate
|
71e72f0a1f
|
chore(deps): update github/codeql-action action to v2.1.38 (#444)
Signed-off-by: Renovate Bot <bot@renovateapp.com>
|
2023-01-16 10:37:41 +09:00 |
|
Ian Lewis
|
1da39d7e06
|
ci: Add javascript to CodeQL analysis (#413)
Signed-off-by: Ian Lewis <ianlewis@google.com>
Signed-off-by: Ian Lewis <ianlewis@google.com>
|
2023-01-11 10:21:11 -06:00 |
|
Mend Renovate
|
b06fbf5b04
|
chore(deps): update github-actions (#436)
* chore(deps): update github-actions
Signed-off-by: Renovate Bot <bot@renovateapp.com>
* Use tag for actions/upload-artifact
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Co-authored-by: asraa <asraa@google.com>
|
2023-01-09 15:28:47 +00:00 |
|
Mend Renovate
|
b40d88c1e7
|
chore(deps): update github-actions (#384)
Co-authored-by: Ian Lewis <ianlewis@google.com>
|
2022-12-15 01:59:36 +00:00 |
|
Mend Renovate
|
0ef57a2b08
|
chore(deps): update github-actions (#359)
* chore(deps): update github-actions
* Update release.yml
Co-authored-by: asraa <asraa@google.com>
|
2022-11-28 18:02:24 +00:00 |
|
Ian Lewis
|
28b554f525
|
Add golangci-lint and yamllint (#365)
* Add Makefile and yamllint config
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
* Add golangci-lint config
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
* Add golangci-lint config
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
* add linters to pre-submit
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
* add issue link to todos
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
* Fix whitespace issue
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
Signed-off-by: Ian Lewis <ianmlewis@gmail.com>
|
2022-11-28 10:19:59 +09:00 |
|
Mend Renovate
|
6cd5d4ac68
|
chore(deps): update github-actions (#351)
Co-authored-by: Ian Lewis <ianlewis@google.com>
|
2022-11-14 22:55:08 +00:00 |
|
WhiteSource Renovate
|
1dfd8ba693
|
chore(deps): update github-actions (#342)
|
2022-10-31 18:13:42 +00:00 |
|
WhiteSource Renovate
|
b7b67c6740
|
chore(deps): update github-actions (#295)
|
2022-10-12 09:15:59 -05:00 |
|
WhiteSource Renovate
|
35fd91f381
|
chore(deps): update github-actions (#284)
|
2022-10-03 09:46:34 +09:00 |
|
WhiteSource Renovate
|
3ee3cca59d
|
chore(deps): update github-actions (#274)
Co-authored-by: asraa <asraa@google.com>
|
2022-09-26 11:22:46 +00:00 |
|
WhiteSource Renovate
|
aa75f1b7bb
|
chore(deps): update github/codeql-action action to v2.1.24 (#262)
|
2022-09-21 16:48:34 +00:00 |
|
WhiteSource Renovate
|
a040702c4e
|
chore(deps): update github/codeql-action action to v2.1.22 (#249)
|
2022-09-06 08:40:16 -05:00 |
|
WhiteSource Renovate
|
2adefa0e01
|
chore(deps): update github-actions (#240)
Co-authored-by: asraa <asraa@google.com>
|
2022-09-02 16:01:16 +00:00 |
|
WhiteSource Renovate
|
ab70a51d20
|
chore(deps): update github-actions (#222)
|
2022-08-22 14:47:52 -07:00 |
|
WhiteSource Renovate
|
691fbbe75b
|
chore(deps): update github/codeql-action action to v2.1.18 (#195)
Co-authored-by: asraa <asraa@google.com>
|
2022-08-08 16:51:08 +00:00 |
|
WhiteSource Renovate
|
ab278de311
|
chore(deps): update github-actions (#175)
Co-authored-by: asraa <asraa@google.com>
|
2022-08-02 19:28:36 +00:00 |
|
WhiteSource Renovate
|
6dc5a273c7
|
chore(deps): update github-actions (#165)
|
2022-07-25 20:31:40 +00:00 |
|
laurentsimon
|
05def419b2
|
update (#170)
|
2022-07-25 20:14:00 +00:00 |
|
laurentsimon
|
6a2f070bf8
|
feat: Group GHA removatebot updates (#153)
* update
* update
|
2022-07-18 16:32:46 +00:00 |
|
dependabot[bot]
|
54a8196e78
|
🌱 Bump github/codeql-action from 1 to 2 (#39)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v1...v2)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2022-04-27 17:44:31 -07:00 |
|
dependabot[bot]
|
32e4468647
|
🌱 Bump actions/checkout from 2 to 3 (#15)
* 🌱 Bump actions/checkout from 2 to 3
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...v3)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
* update version comment
Signed-off-by: Asra Ali <asraa@google.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Asra Ali <asraa@google.com>
|
2022-03-31 11:37:16 -05:00 |
|
Joshua Lock
|
25528e0083
|
fix(codeql): fix branch wildcard (#11)
* is a special character in YAML, so we must use quotes
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#filter-pattern-cheat-sheet
Signed-off-by: Joshua Lock <jlock@vmware.com>
|
2022-03-29 18:02:06 +01:00 |
|
laurentsimon
|
6cdcbf9a66
|
Transffer from github.com/gossts/slsa-provenance (#1)
|
2022-03-28 08:46:38 -07:00 |
|