Bump the actions group across 1 directory with 10 updates #286
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 10 updates in the / directory:
2.12.22.13.25.3.15.5.12.3.02.4.04.5.04.8.24.6.05.0.02.0.02.1.04.1.86.0.0f456a002d58f0de60b44383d10ae82316b18a16684f9e705f303e1311e5263a61ce58bcb03804fcc2.2.12.4.22.4.02.4.3Updates
step-security/harden-runnerfrom 2.12.2 to 2.13.2Release notes
Sourced from step-security/harden-runner's releases.
Commits
95d9a5dMerge pull request #606 from step-security/rc-2887e429dUpdate limitations.mdef891c3feat: add support for custom vm image1fa8c8aupdate agent92c522aMerge pull request #593 from step-security/ak-readme-updates4719ad5README updates4fde639Merge pull request #591 from eromosele-stepsecurity/Updf682f2fUpdate README.mdf4a75cfMerge pull request #588 from step-security/rc-2695503d0ci: remove code-review workflowUpdates
codecov/codecov-actionfrom 5.3.1 to 5.5.1Release notes
Sourced from codecov/codecov-action's releases.
... (truncated)
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)a4803c1build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)3139621build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)fdcc847chore(release): 5.5.0 (#1865)Updates
theupdateframework/tuf-conformancefrom 2.3.0 to 2.4.0Release notes
Sourced from theupdateframework/tuf-conformance's releases.
Commits
500c525Prepare 2.4 release (#324)68e81e9Publish a conformance report (#322)daf5ad1Bump ruff from 0.14.2 to 0.14.3 in the python-dependencies group (#320)8b425a2Bump ruff from 0.14.1 to 0.14.2 in the python-dependencies group (#319)eaca9f1Bump actions/upload-artifact from 4.6.2 to 5.0.0 (#318)032d542Bump ruff from 0.14.0 to 0.14.1 in the python-dependencies group (#317)0e9e191Bump ruff from 0.13.3 to 0.14.0 in the python-dependencies group (#316)78f59abBump ruff from 0.13.2 to 0.13.3 in the python-dependencies group (#315)f678c10Bump the python-dependencies group with 2 updates (#314)f01395dBump the python-dependencies group with 2 updates (#312)Updates
actions/dependency-review-actionfrom 4.5.0 to 4.8.2Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
3c4e3dcMerge pull request #1016 from actions/dra-release02930b2Update CONTRIBUTING to reflect new guidelines49ffd9fUpdate CONTRIBUTING to reflect the need to build70cb25e4.8.2 releaseebabd31Merge pull request #1008 from danielhardej/danielhardej-patch-2025102319f9360Update package-lock.json5fd2f98Bump@types/jestto version 29.5.1428647f4Fix PURL parsing by removing encodeURIf620fd1Merge pull request #1013 from actions/dangoor/token-fix9b42b7eRemove bad token referenceUpdates
actions/upload-artifactfrom 4.6.0 to 5.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.mdUpdates
slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.ymlfrom 2.0.0 to 2.1.0Release notes
Sourced from slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml's releases.
... (truncated)
Changelog
Sourced from slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml's changelog.
Commits
f7dd8c5update the ref in the pre-submit0a5124bfix jq for the sigstore bundlesfbeecf0update docsf701310update workflows3618598v2.1.0-rc.346f81fcchore: update refs to v2.1.0-rc.1 (#4120)5d20c93chore: use builder tag v2.1.0-rc.0 (#4118)e27b237chore: braces and ejs vulns (#4116)8967e1cchore: Update CODEOWNERS (#4115)47d1954chore: update octokit deps (#4114)Updates
actions/download-artifactfrom 4.1.8 to 6.0.0Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
018cc2cMerge pull request #438 from actions/danwkennedy/prepare-6.0.0815651cRevert "Removegithub.dep.yml"bb3a066Removegithub.dep.ymlfa1ce46Preparev6.0.04a24838Merge pull request #431 from danwkennedy/patch-15e3251cReadme: spell out the first use of GHESabefc31Merge pull request #424 from actions/yacaovsnc/update_readmeac43a60Update README with artifact extraction detailsde96f46Merge pull request #417 from actions/yacaovsnc/update_readme7993cb4Remove migration guide for artifact download changesUpdates
rubygems/configure-rubygems-credentialsfrom f456a002d58f0de60b44383d10ae82316b18a166 to 84f9e705f303e1311e5263a61ce58bcb03804fccCommits
84f9e70Bump actions/checkout from 5.0.0 to 5.0.1 (#333)2304318Bump github/codeql-action from 4.31.2 to 4.31.3 (#332)5d91f7bBump actions/setup-node from 5 to 6 (#325)221a2c7Bump js-yaml from 4.1.0 to 4.1.1 (#331)66bb13fBump github/codeql-action from 4.31.0 to 4.31.2 (#330)89fa1f8Bump github/codeql-action from 4.30.8 to 4.31.0 (#328)21fa24aBump actions/upload-artifact from 4 to 5 (#327)fd89024Bump actions/download-artifact from 5 to 6 (#329)23d6a54Bump github/codeql-action from 3.30.6 to 4.30.8 (#323)1002289Bump github/codeql-action from 3.30.5 to 3.30.6 (#320)