chore(deps): bump the actions group across 1 directory with 5 updates - #73
Conversation
Bumps the actions group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.1` | `2.19.4` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.35.4` | `4.36.0` | | [opentofu/setup-opentofu](https://github.com/opentofu/setup-opentofu) | `2.0.0` | `2.0.1` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.1.1` | `6.1.2` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.3` | `0.5.6` | Updates `step-security/harden-runner` from 2.19.1 to 2.19.4 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a5ad31d...9af89fc) Updates `github/codeql-action` from 4.35.4 to 4.36.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...7211b7c) Updates `opentofu/setup-opentofu` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/opentofu/setup-opentofu/releases) - [Commits](opentofu/setup-opentofu@fc711fa...847eaa4) Updates `aws-actions/configure-aws-credentials` from 6.1.1 to 6.1.2 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@d979d5b...acca2b1) Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.5.6 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@b1d7e1f...5f14fd0) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action dependency-version: 4.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: opentofu/setup-opentofu dependency-version: 2.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.5.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
module.org_baseline.github_organization_settings.this: Refreshing state... [id=283017149] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and |
Review summary (/review-pr)Verdict: approve, merge after fresh checks go green. 5 action SHA bumps, all verified authentic against their upstream tags:
Prior red checks were two separate causes, both resolved:
No code fixes required. |
Bumps the actions group with 5 updates in the / directory:
2.19.12.19.44.35.44.36.02.0.02.0.16.1.16.1.20.5.30.5.6Updates
step-security/harden-runnerfrom 2.19.1 to 2.19.4Release notes
Sourced from step-security/harden-runner's releases.
Commits
9af89fcMerge pull request #667 from step-security/update-agent-v1.8.6485dce8Update agent to v1.8.6ab7a940Merge pull request #665 from step-security/fix/use-policy-store-default-auditec41b78Default to audit mode when api-key missing with use-policy-store9ca718dMerge pull request #664 from step-security/update-agent-v1.8.51dee3dfUpdate agent to v1.8.5Updates
github/codeql-actionfrom 4.35.4 to 4.36.0Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
7211b7cMerge pull request #3927 from github/update-v4.36.0-ebc2d9e2b7740f2fUpdate changelog for v4.36.0ebc2d9eMerge pull request #3926 from github/update-bundle/codeql-bundle-v2.25.5d1f74b7Add changelog note2dc40ceUpdate default bundle to codeql-bundle-v2.25.58449852Merge pull request #3910 from github/henrymercer/repo-size-diff-check72ac23cUpdate excluded required check listc5297a2Merge pull request #3919 from github/henrymercer/workflow-concurrency8ffeae7CI: Automatically cancel non-generated workflowsf3f52bfRevertgetErrorMessageimportUpdates
opentofu/setup-opentofufrom 2.0.0 to 2.0.1Release notes
Sourced from opentofu/setup-opentofu's releases.
Commits
847eaa4chore(deps): Bump@actions/http-clientfrom 4.0.0 to 4.0.1 (#114)34bf4e3feat(acc): Add provider_acceptance_tests input for automated acceptance test ...4bcfe8cfeat: added support for providing optional checksums for ZIP validation (#107)03a9076deps: picomatch in npm audit (#103)ba1f8b8chore(ci): dependabot actions ecosystem, conventional commits (#98)26ccb9bUpdate README with latest action versions. (#99)b572e07feat(error-handling): error notification for network failures (#94)4959f8ffix: npm auditUpdates
aws-actions/configure-aws-credentialsfrom 6.1.1 to 6.1.2Release notes
Sourced from aws-actions/configure-aws-credentials's releases.
Changelog
Sourced from aws-actions/configure-aws-credentials's changelog.
... (truncated)
Commits
acca2b1chore(main): release 6.1.2 (#1761)c329d24chore: Update distc39f282fix: additional filesystem checks (#1799)8188beechore(deps-dev): bump@types/nodefrom 25.6.0 to 25.9.1 (#1795)477988dchore(deps-dev): bump@smithy/property-providerfrom 4.2.14 to 4.3.4 (#1798)9a5ab5bchore: Update distbaa1fdfchore(deps): bump@aws-sdk/client-stsfrom 3.1038.0 to 3.1053.0 (#1793)4be0a3cchore(deps-dev): bump generate-license-file from 4.1.1 to 4.2.1 (#1794)f85f964chore: Update dist6fddd0cchore(deps-dev): bump@aws-sdk/credential-provider-env(#1791)Updates
zizmorcore/zizmor-actionfrom 0.5.3 to 0.5.6Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
5f14fd0Sync zizmor versions (#114)a16621bBump pins in README (#112)1c03e04chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 in the github-ac...b572f7bSync zizmor versions (#111)06928c5chore(deps): bump github/codeql-action in the github-actions group (#109)5ea8b96docs: Update link to GitHub docs (#108)849ac26chore(deps): bump the github-actions group with 2 updates (#106)814f977Bump pins in README (#103)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions