Skip to content

Commit d0a4fbb

Browse files
authored
Merge pull request #1336 from flux-iac/dependabot/github_actions/gh-minor-e15f0431c8
Bump the gh-minor group across 1 directory with 8 updates
2 parents 9b79e61 + 59428b7 commit d0a4fbb

File tree

8 files changed

+29
-29
lines changed

8 files changed

+29
-29
lines changed

.github/workflows/build-and-publish.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -62,17 +62,17 @@ jobs:
6262
platforms: all
6363
- name: Setup Docker Buildx
6464
id: buildx
65-
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
65+
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
6666
with:
6767
buildkitd-flags: "--debug"
6868
- name: Login to GitHub Container Registry
69-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
69+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
7070
with:
7171
registry: ghcr.io
7272
username: ${{ github.actor }}
7373
password: ${{ secrets.GITHUB_TOKEN }}
7474
- name: Publish multi-arch tf-controller container image
75-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
75+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
7676
with:
7777
push: true
7878
builder: ${{ steps.buildx.outputs.name }}
@@ -91,7 +91,7 @@ jobs:
9191
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
9292
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
9393
- name: Build multi-arch tf-runner base image
94-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
94+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
9595
with:
9696
push: true
9797
builder: ${{ steps.buildx.outputs.name }}
@@ -112,7 +112,7 @@ jobs:
112112
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
113113
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
114114
- name: Publish multi-arch tf-runner container image
115-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
115+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
116116
with:
117117
push: true
118118
builder: ${{ steps.buildx.outputs.name }}
@@ -131,7 +131,7 @@ jobs:
131131
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
132132
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
133133
- name: Publish multi-arch branch-planner container image
134-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
134+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
135135
with:
136136
push: true
137137
builder: ${{ steps.buildx.outputs.name }}

.github/workflows/e2e.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ jobs:
4242
restore-keys: |
4343
${{ runner.os }}-buildx-ghcache-
4444
- name: Setup Kubernetes
45-
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
45+
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
4646
with:
4747
version: v0.18.0
4848
node_image: kindest/node:v1.24.12@sha256:1e12918b8bc3d4253bc08f640a231bb0d3b2c5a9b28aa3f2ca1aee93e1e8db16

.github/workflows/helm-release.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
with:
2020
token: ${{ secrets.GITHUB_TOKEN }}
2121
- name: Login to GitHub Container Registry
22-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
22+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
2323
with:
2424
registry: ghcr.io
2525
username: ${{ github.actor }}

.github/workflows/helm-test.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ jobs:
6262
if: steps.list-changed.outputs.changed == 'true'
6363

6464
- name: Create kind cluster
65-
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
65+
uses: helm/kind-action@0025e74a8c7512023d06dc019c617aa3cf561fde # v1.10.0
6666
if: steps.list-changed.outputs.changed == 'true'
6767

6868
- name: Load test images into KIND

.github/workflows/ossf.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
persist-credentials: false
2626

2727
- name: "Run analysis"
28-
uses: ossf/scorecard-action@08b4669551908b1024bb425080c797723083c031 # v2.2.0
28+
uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
2929
with:
3030
results_file: results.sarif
3131
results_format: sarif

.github/workflows/release-runners.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -36,17 +36,17 @@ jobs:
3636
platforms: all
3737
- name: Setup Docker Buildx
3838
id: buildx
39-
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
39+
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
4040
with:
4141
buildkitd-flags: "--debug"
4242
- name: Login to Docker Registry
43-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
43+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
4444
with:
4545
registry: ghcr.io
4646
username: ${{ github.actor }}
4747
password: ${{ secrets.GITHUB_TOKEN }}
4848
- name: Publish multi-arch tf-runner base image
49-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
49+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
5050
with:
5151
push: true
5252
no-cache: true
@@ -85,17 +85,17 @@ jobs:
8585
platforms: all
8686
- name: Setup Docker Buildx
8787
id: buildx
88-
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
88+
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
8989
with:
9090
buildkitd-flags: "--debug"
9191
- name: Login to Docker Registry
92-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
92+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
9393
with:
9494
registry: ghcr.io
9595
username: ${{ github.actor }}
9696
password: ${{ secrets.GITHUB_TOKEN }}
9797
- name: Publish multi-arch tf-runner MPL images
98-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
98+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
9999
with:
100100
push: true
101101
no-cache: true

.github/workflows/release.yaml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,9 @@ jobs:
3434
- name: Setup Kustomize
3535
uses: fluxcd/pkg/actions/kustomize@1bfad582060d2d6e464756fbd5d7a2b2fa4f75b9 # main
3636
- name: Setup Cosign
37-
uses: sigstore/cosign-installer@11086d25041f77fe8fe7b9ea4e48e3b9192b8f19 # v3.1.2
37+
uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # v3.5.0
3838
- name: Setup Syft
39-
uses: anchore/sbom-action/download-syft@78fc58e266e87a38d4194b2137a3d4e9bcaf7ca1 # v0.14.3
39+
uses: anchore/sbom-action/download-syft@e8d2a6937ecead383dfe75190d104edd1f9c5751 # v0.16.0
4040
- name: Prepare
4141
id: prep
4242
run: |
@@ -52,17 +52,17 @@ jobs:
5252
platforms: all
5353
- name: Setup Docker Buildx
5454
id: buildx
55-
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
55+
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
5656
with:
5757
buildkitd-flags: "--debug"
5858
- name: Login to GitHub Container Registry
59-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
59+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446 # v3.2.0
6060
with:
6161
registry: ghcr.io
6262
username: ${{ github.actor }}
6363
password: ${{ secrets.GITHUB_TOKEN }}
6464
- name: Publish multi-arch tofu-controller container image
65-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
65+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
6666
with:
6767
push: true
6868
no-cache: true
@@ -83,7 +83,7 @@ jobs:
8383
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
8484
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
8585
- name: Publish multi-arch tf-runner base image
86-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
86+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
8787
with:
8888
push: true
8989
builder: ${{ steps.buildx.outputs.name }}
@@ -102,7 +102,7 @@ jobs:
102102
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
103103
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
104104
- name: Publish multi-arch tf-runner container image
105-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
105+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
106106
with:
107107
push: true
108108
no-cache: true
@@ -123,7 +123,7 @@ jobs:
123123
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
124124
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
125125
- name: Publish multi-arch tf-runner-azure container image
126-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
126+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
127127
with:
128128
push: true
129129
no-cache: true
@@ -144,7 +144,7 @@ jobs:
144144
org.opencontainers.image.version=${{ steps.prep.outputs.VERSION }}
145145
org.opencontainers.image.created=${{ steps.prep.outputs.BUILD_DATE }}
146146
- name: Publish multi-arch branch-planner container image
147-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
147+
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
148148
with:
149149
push: true
150150
no-cache: true

.github/workflows/scan.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ jobs:
5757
run: |
5858
make docker-buildx
5959
- name: Run Trivy vulnerability scanner on controller image
60-
uses: aquasecurity/trivy-action@fbd16365eb88e12433951383f5e99bd901fc618f # v0.12.0
60+
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
6161
with:
6262
image-ref: 'ghcr.io/flux-iac/tofu-controller:latest'
6363
format: 'table'
@@ -66,7 +66,7 @@ jobs:
6666
vuln-type: 'os,library'
6767
severity: 'CRITICAL,HIGH'
6868
- name: Run Trivy vulnerability scanner on runner image
69-
uses: aquasecurity/trivy-action@fbd16365eb88e12433951383f5e99bd901fc618f # v0.12.0
69+
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
7070
with:
7171
image-ref: 'ghcr.io/flux-iac/tf-runner:latest'
7272
format: 'table'
@@ -76,7 +76,7 @@ jobs:
7676
severity: 'CRITICAL,HIGH'
7777
skip-files: '/usr/local/bin/terraform' # false positive
7878
- name: Run Trivy vulnerability scanner on runner image
79-
uses: aquasecurity/trivy-action@fbd16365eb88e12433951383f5e99bd901fc618f # v0.12.0
79+
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
8080
with:
8181
image-ref: 'ghcr.io/flux-iac/tf-runner-azure:latest'
8282
format: 'table'
@@ -86,7 +86,7 @@ jobs:
8686
severity: 'CRITICAL,HIGH'
8787
skip-files: '/usr/local/bin/terraform' # false positive
8888
- name: Run Trivy vulnerability scanner on planner image
89-
uses: aquasecurity/trivy-action@fbd16365eb88e12433951383f5e99bd901fc618f # v0.12.0
89+
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
9090
with:
9191
image-ref: 'ghcr.io/flux-iac/branch-planner:latest'
9292
format: 'table'

0 commit comments

Comments
 (0)