Skip to content
This repository was archived by the owner on Oct 22, 2024. It is now read-only.

Bump hashicorp/vault-action from 2.4.0 to 2.7.1 - #42

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashicorp/vault-action-2.7.1
Closed

Bump hashicorp/vault-action from 2.4.0 to 2.7.1#42
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashicorp/vault-action-2.7.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 4, 2023

Copy link
Copy Markdown

Bumps hashicorp/vault-action from 2.4.0 to 2.7.1.

Release notes

Sourced from hashicorp/vault-action's releases.

v2.7.1

2.7.1 (July 3, 2023)

Bugs:

  • Revert GH-466 which caused a regression in secrets stored as JSON strings GH-471

v2.7.0

Bugs:

  • Fix a regression that broke support for secrets in JSON format GH-466

Improvements:

  • Fix a warning about outputToken being an unexpected input GH-461

v2.6.0

2.6.0 (June 7, 2023)

Features:

  • Add ability to set the vault_token output to contain the Vault token after authentication GH-441
  • Add support for userpass and ldap authentication methods GH-440
  • Define an output, errorMessage, for vault-action's error messages so subsequent steps can read the errors GH-446

Bugs:

  • Handle undefined response in getSecrets error handler GH-431

v2.5.0

Features:

  • Adds ability to automatically decode secrets from base64, hex, and utf8 encodings. GH-408

Improvements:

  • Improves error messages for Vault authentication failures GH-409
  • bump jest from 28.1.1 to 29.3.1 GH-397
  • bump @​types/jest from 28.1.3 to 29.2.6 GH-397, GH-413
  • bump jsrsasign from 10.5.27 to 10.6.1 GH-401
  • bump json5 from 2.2.1 to 2.2.3 GH-404
  • bump minimatch from 3.0.4 to 3.1.2 GH-410

v2.4.3

Improvements

  • bump jest-when from 3.5.1 to 3.5.2 GH-388
  • bump semantic-release from 19.0.3 to 19.0.5 GH-360
  • bump jsrsasign from 10.5.25 to 10.5.27 GH-358
  • bump @​actions/core from 1.9.0 to 1.10.0 GH-371

... (truncated)

Changelog

Sourced from hashicorp/vault-action's changelog.

2.7.1 (July 3, 2023)

Bugs:

  • Revert GH-466 which caused a regression in secrets stored as JSON strings GH-471

2.7.0 (June 21, 2023)

Bugs:

  • Fix a regression that broke support for secrets in JSON format GH-466

Improvements:

  • Fix a warning about outputToken being an unexpected input GH-461

2.6.0 (June 7, 2023)

Features:

  • Add ability to set the vault_token output to contain the Vault token after authentication GH-441
  • Add support for userpass and ldap authentication methods GH-440
  • Define an output, errorMessage, for vault-action's error messages so subsequent steps can read the errors GH-446

Bugs:

  • Handle undefined response in getSecrets error handler GH-431

2.5.0 (Jan 26th, 2023)

Features:

  • Adds ability to automatically decode secrets from base64, hex, and utf8 encodings. GH-408

Improvements:

  • Improves error messages for Vault authentication failures GH-409
  • bump jest from 28.1.1 to 29.3.1 GH-397
  • bump @​types/jest from 28.1.3 to 29.2.6 GH-397, GH-413
  • bump jsrsasign from 10.5.27 to 10.6.1 GH-401
  • bump json5 from 2.2.1 to 2.2.3 GH-404
  • bump minimatch from 3.0.4 to 3.1.2 GH-410

2.4.3 (Nov 8th, 2022)

Improvements:

  • bump jest-when from 3.5.1 to 3.5.2 GH-388
  • bump semantic-release from 19.0.3 to 19.0.5 GH-360
  • bump jsrsasign from 10.5.25 to 10.5.27 GH-358

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hashicorp/vault-action](https://github.com/hashicorp/vault-action) from 2.4.0 to 2.7.1.
- [Release notes](https://github.com/hashicorp/vault-action/releases)
- [Changelog](https://github.com/hashicorp/vault-action/blob/main/CHANGELOG.md)
- [Commits](hashicorp/vault-action@v2.4.0...v2.7.1)

---
updated-dependencies:
- dependency-name: hashicorp/vault-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 4, 2023
@dependabot @github

dependabot Bot commented on behalf of github Jul 7, 2023

Copy link
Copy Markdown
Author

Superseded by #45.

@dependabot dependabot Bot closed this Jul 7, 2023
@dependabot
dependabot Bot deleted the dependabot/github_actions/hashicorp/vault-action-2.7.1 branch July 7, 2023 11:15
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants