From adec2673de6c727c8694baa722a5185904b010b6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 2 Sep 2024 18:17:38 +0000 Subject: [PATCH] Bump the actions-minor group across 1 directory with 5 updates Bumps the actions-minor group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [koalalab-inc/bolt](https://github.com/koalalab-inc/bolt) | `1.5.0` | `1.6.2` | | [actions/checkout](https://github.com/actions/checkout) | `4.1.1` | `4.1.7` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.4` | `4.4.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.25.15` | `3.26.6` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.5.0` | `3.6.0` | Updates `koalalab-inc/bolt` from 1.5.0 to 1.6.2 - [Release notes](https://github.com/koalalab-inc/bolt/releases) - [Commits](https://github.com/koalalab-inc/bolt/compare/7bc45c5036a248828c82447f9bb3fea35fe27c93...b7388cf6657068ee4d2b324a7a530a7ce203fd36) Updates `actions/checkout` from 4.1.1 to 4.1.7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4.1.1...692973e3d937129bcbf40652eb9f2f61becf3332) Updates `actions/upload-artifact` from 4.3.4 to 4.4.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/0b2256b8c012f0828dc542b3febcab082c67f72b...50769540e7f4bd5e21e526ee35c689e35e0d6874) Updates `github/codeql-action` from 3.25.15 to 3.26.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/afb54ba388a7dca6ecae48f608c4ff05ff4cc77a...4dd16135b69a43b6c8efb853346f8437d92d3c93) Updates `sigstore/cosign-installer` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](https://github.com/sigstore/cosign-installer/compare/59acb6260d9c0ba8f4a2f9d9b48431a222b68e20...4959ce089c160fddf62f7b42464195ba1a56d382) --- updated-dependencies: - dependency-name: koalalab-inc/bolt dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/check-dist.yml | 6 +++--- .github/workflows/ci.yml | 8 ++++---- .github/workflows/codeql.yml | 4 ++-- .github/workflows/linter.yml | 4 ++-- .github/workflows/ossf-scorecard.yml | 4 ++-- .github/workflows/release.yml | 16 ++++++++-------- 6 files changed, 21 insertions(+), 21 deletions(-) diff --git a/.github/workflows/check-dist.yml b/.github/workflows/check-dist.yml index 6c2ee32..f28fd53 100644 --- a/.github/workflows/check-dist.yml +++ b/.github/workflows/check-dist.yml @@ -29,10 +29,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Setup Node.js id: setup-node @@ -64,7 +64,7 @@ jobs: - if: ${{ failure() && steps.diff.outcome == 'failure' }} name: Upload Artifact id: upload - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | v4.4.0 with: name: dist path: dist/ diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0906417..98367a7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,10 +16,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Setup Node.js id: setup-node @@ -50,7 +50,7 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b913e08..bd1cdf5 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -54,7 +54,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # github/codeql-action/init@v3 + uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # github/codeql-action/init@v3 with: config-file: ./.github/codeql/codeql-config.yml languages: ${{ matrix.language }} @@ -82,6 +82,6 @@ jobs: # exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/init@afb54ba388a7dca6ecae48f608c4ff05ff4cc77a # github/codeql-action/init@v3 + uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # github/codeql-action/init@v3 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/linter.yml b/.github/workflows/linter.yml index 4515579..24f3eb2 100644 --- a/.github/workflows/linter.yml +++ b/.github/workflows/linter.yml @@ -19,10 +19,10 @@ jobs: steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout id: checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 with: fetch-depth: 0 diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index b44d9d9..a555a11 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -28,7 +28,7 @@ jobs: steps: - name: "Checkout code" - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 with: persist-credentials: false @@ -55,7 +55,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: SARIF file path: results.sarif diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2da0837..81a7b2c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,9 +21,9 @@ jobs: hashes: ${{ steps.hash.outputs.hashes }} steps: - name: Setup Bolt - uses: koalalab-inc/bolt@7bc45c5036a248828c82447f9bb3fea35fe27c93 # koalalab-inc/bolt@v1.3.0 | main + uses: koalalab-inc/bolt@b7388cf6657068ee4d2b324a7a530a7ce203fd36 # koalalab-inc/bolt@v1.3.0 | main - name: Checkout - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # actions/checkout@v4 | 1567,v4.1.2 + uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4 | 1567,v4.1.7 - name: Get release version id: releaseVersion shell: bash @@ -49,7 +49,7 @@ jobs: rm -rf mitmproxy bolt rm mitmproxy-10.2.2-linux-x86_64.tar.gz - name: Install Cosign - uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # sigstore/cosign-installer@v3.5.0 + uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # sigstore/cosign-installer@v3.6.0 with: cosign-release: 'v2.2.4' # optional - name: Sign Release @@ -75,7 +75,7 @@ jobs: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert | base64 -w0)" >> "$GITHUB_OUTPUT" - name: Upload tarball - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz @@ -83,7 +83,7 @@ jobs: retention-days: 5 - name: Upload signature - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.sig path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.sig @@ -91,7 +91,7 @@ jobs: retention-days: 5 - name: Upload certificate - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.cert @@ -99,7 +99,7 @@ jobs: retention-days: 5 - name: Upload verification bundle - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # actions/upload-artifact@v4 | main,v4.3.4 + uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # actions/upload-artifact@v4 | main,v4.4.0 with: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle path: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle @@ -150,7 +150,7 @@ jobs: name: bolt-${{ env.tag }}-${{ env.os }}-${{ env.arch }}.tar.gz.bundle - name: Install Cosign - uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # sigstore/cosign-installer@v3.5.0 + uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # sigstore/cosign-installer@v3.6.0 with: cosign-release: 'v2.2.4' # optional