Skip to content

Commit 8f97a91

Browse files
authored
Merge pull request #1465 from flux-iac/dependabot/github_actions/gh-minor-c9ad4c6b0d
Bump the gh-minor group with 12 updates
2 parents f288d0e + 0321b53 commit 8f97a91

File tree

9 files changed

+29
-29
lines changed

9 files changed

+29
-29
lines changed

.github/workflows/build-and-publish.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -57,16 +57,16 @@ jobs:
5757
echo "BUILD_VERSION=${BUILD_VERSION}" >> "$GITHUB_OUTPUT"
5858
echo "BUILD_SHA=${BUILD_SHA}" >> "$GITHUB_OUTPUT"
5959
- name: Setup QEMU
60-
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
60+
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
6161
with:
6262
platforms: all
6363
- name: Setup Docker Buildx
6464
id: buildx
65-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
65+
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
6666
with:
6767
buildkitd-flags: "--debug"
6868
- name: Login to GitHub Container Registry
69-
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
69+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
7070
with:
7171
registry: ghcr.io
7272
username: ${{ github.actor }}

.github/workflows/docs.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
contents: write
1919
steps:
2020
- uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.0.0
21-
- uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d # v5.1.0
21+
- uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
2222
with:
2323
python-version: 3.x
2424
- name: Install mkdocs

.github/workflows/e2e.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
**/go.sum
3535
**/go.mod
3636
- name: Cache Docker layers
37-
uses: actions/cache@0c45773b623bea8c8e75f6c82b208c3cf94ea4f9 # v4.0.2
37+
uses: actions/cache@3624ceb22c1c5a301c8db4169662070a689d9ea8 # v4.1.1
3838
id: cache
3939
with:
4040
path: /tmp/.buildx-cache

.github/workflows/helm-release.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
with:
2020
token: ${{ secrets.GITHUB_TOKEN }}
2121
- name: Login to GitHub Container Registry
22-
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
22+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
2323
with:
2424
registry: ghcr.io
2525
username: ${{ github.actor }}

.github/workflows/helm-test.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
with:
2424
version: latest
2525

26-
- uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d # v5.1.0
26+
- uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3 # v5.2.0
2727
with:
2828
python-version: "3.10"
2929

@@ -72,7 +72,7 @@ jobs:
7272
if: steps.list-changed.outputs.changed == 'true'
7373

7474
- name: Install Flux CLI
75-
uses: fluxcd/flux2/action@896e0fa46d5107a05e953dd0a5261d78a145ec8c # main
75+
uses: fluxcd/flux2/action@5350425cdcd5fa015337e09fa502153c0275bd4b # main
7676
if: steps.list-changed.outputs.changed == 'true'
7777

7878
- name: Install Source controller

.github/workflows/ossf.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
persist-credentials: false
2626

2727
- name: "Run analysis"
28-
uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
28+
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
2929
with:
3030
results_file: results.sarif
3131
results_format: sarif
@@ -34,14 +34,14 @@ jobs:
3434
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
3535
# format to the repository Actions tab.
3636
- name: "Upload artifact"
37-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
37+
uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
3838
with:
3939
name: SARIF file
4040
path: results.sarif
4141
retention-days: 5
4242

4343
# required for Code scanning alerts
4444
- name: "Upload SARIF results to code scanning"
45-
uses: github/codeql-action/upload-sarif@f079b8493333aace61c81488f8bd40919487bd9f # v3.25.7
45+
uses: github/codeql-action/upload-sarif@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
4646
with:
4747
sarif_file: results.sarif

.github/workflows/release-runners.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,16 +31,16 @@ jobs:
3131
- name: Check out
3232
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.0.0
3333
- name: Setup QEMU
34-
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
34+
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
3535
with:
3636
platforms: all
3737
- name: Setup Docker Buildx
3838
id: buildx
39-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
39+
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
4040
with:
4141
buildkitd-flags: "--debug"
4242
- name: Login to Docker Registry
43-
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
43+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
4444
with:
4545
registry: ghcr.io
4646
username: ${{ github.actor }}
@@ -80,16 +80,16 @@ jobs:
8080
- name: Check out
8181
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.0.0
8282
- name: Setup QEMU
83-
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
83+
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
8484
with:
8585
platforms: all
8686
- name: Setup Docker Buildx
8787
id: buildx
88-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
88+
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
8989
with:
9090
buildkitd-flags: "--debug"
9191
- name: Login to Docker Registry
92-
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
92+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
9393
with:
9494
registry: ghcr.io
9595
username: ${{ github.actor }}

.github/workflows/release.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,9 @@ jobs:
3434
- name: Setup Kustomize
3535
uses: fluxcd/pkg/actions/kustomize@30c101fc7c9fac4d84937ff4890a3da46a9db2dd # main
3636
- name: Setup Cosign
37-
uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # v3.5.0
37+
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
3838
- name: Setup Syft
39-
uses: anchore/sbom-action/download-syft@e8d2a6937ecead383dfe75190d104edd1f9c5751 # v0.16.0
39+
uses: anchore/sbom-action/download-syft@f5e124a5e5e1d497a692818ae907d3c45829d033 # v0.17.3
4040
- name: Prepare
4141
id: prep
4242
run: |
@@ -47,16 +47,16 @@ jobs:
4747
echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" >> "$GITHUB_OUTPUT"
4848
echo "VERSION=${VERSION}" >> "$GITHUB_OUTPUT"
4949
- name: Setup QEMU
50-
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
50+
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
5151
with:
5252
platforms: all
5353
- name: Setup Docker Buildx
5454
id: buildx
55-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
55+
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
5656
with:
5757
buildkitd-flags: "--debug"
5858
- name: Login to GitHub Container Registry
59-
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
59+
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
6060
with:
6161
registry: ghcr.io
6262
username: ${{ github.actor }}

.github/workflows/scan.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -39,13 +39,13 @@ jobs:
3939
**/go.sum
4040
**/go.mod
4141
- name: Initialize CodeQL
42-
uses: github/codeql-action/init@f079b8493333aace61c81488f8bd40919487bd9f # v3.25.7
42+
uses: github/codeql-action/init@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
4343
with:
4444
languages: go
4545
- name: Autobuild
46-
uses: github/codeql-action/autobuild@f079b8493333aace61c81488f8bd40919487bd9f # v3.25.7
46+
uses: github/codeql-action/autobuild@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@f079b8493333aace61c81488f8bd40919487bd9f # v3.25.7
48+
uses: github/codeql-action/analyze@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
4949

5050
trivy:
5151
name: Trivy
@@ -57,7 +57,7 @@ jobs:
5757
run: |
5858
make docker-buildx
5959
- name: Run Trivy vulnerability scanner on controller image
60-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
60+
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
6161
with:
6262
image-ref: 'ghcr.io/flux-iac/tofu-controller:latest'
6363
format: 'table'
@@ -66,7 +66,7 @@ jobs:
6666
vuln-type: 'os,library'
6767
severity: 'CRITICAL,HIGH'
6868
- name: Run Trivy vulnerability scanner on runner image
69-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
69+
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
7070
with:
7171
image-ref: 'ghcr.io/flux-iac/tf-runner:latest'
7272
format: 'table'
@@ -76,7 +76,7 @@ jobs:
7676
severity: 'CRITICAL,HIGH'
7777
skip-files: '/usr/local/bin/terraform' # false positive
7878
- name: Run Trivy vulnerability scanner on runner image
79-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
79+
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
8080
with:
8181
image-ref: 'ghcr.io/flux-iac/tf-runner-azure:latest'
8282
format: 'table'
@@ -86,7 +86,7 @@ jobs:
8686
severity: 'CRITICAL,HIGH'
8787
skip-files: '/usr/local/bin/terraform' # false positive
8888
- name: Run Trivy vulnerability scanner on planner image
89-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
89+
uses: aquasecurity/trivy-action@5681af892cd0f4997658e2bacc62bd0a894cf564 # v0.27.0
9090
with:
9191
image-ref: 'ghcr.io/flux-iac/branch-planner:latest'
9292
format: 'table'

0 commit comments

Comments
 (0)