Skip to content

build(deps): bump the cicd group with 4 updates - #3152

Open
dependabot[bot] wants to merge 18 commits into
mainfrom
dependabot/github_actions/cicd-f8996503e4
Open

dependabot[bot] wants to merge 18 commits into
mainfrom
dependabot/github_actions/cicd-f8996503e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the cicd group with 4 updates: actions/cache, actions/cache/save, hadolint/hadolint-action and trufflesecurity/trufflehog.

Updates actions/cache from 5.0.5 to 5.1.0

Release notes

Sourced from actions/cache's releases.

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

Commits
  • caa2961 Merge pull request #1775 from jasongin/readonly-cache-v5
  • 00c2da9 Bump @​actions/cache to v5.1.0 - handle read-only cache access
  • See full diff in compare view

Updates actions/cache/save from 5.0.5 to 5.1.0

Release notes

Sourced from actions/cache/save's releases.

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

Commits
  • caa2961 Merge pull request #1775 from jasongin/readonly-cache-v5
  • 00c2da9 Bump @​actions/cache to v5.1.0 - handle read-only cache access
  • See full diff in compare view

Updates hadolint/hadolint-action from 3.4.0 to 3.5.0

Release notes

Sourced from hadolint/hadolint-action's releases.

v3.5.0

3.5.0 (2026-08-24)

Features

  • Bump Hadolint to v2.15.1 (941db07)
Commits
  • 06be81b Merge pull request #107 from gizero/bump-hadolint-base-image-to-2.15.1
  • 941db07 feat: Bump Hadolint to v2.15.1
  • d0e9595 Merge pull request #106 from m-ildefons/gh-78
  • df662ab Problem Matcher: Capture code and severity
  • 32c6895 Merge pull request #85 from rjbell4/patch-1
  • 146301c Merge pull request #105 from m-ildefons/gh-100
  • df8eaaf CI: run integration tests with different runners
  • 75bb911 fixup! Update hadolint.sh
  • 631cc83 Update repository reference in problem-matcher.json
  • See full diff in compare view

Updates trufflesecurity/trufflehog from 3.97.0 to 3.97.1

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.1

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.0...v3.97.1

Commits
  • 20652fb Carry GitHub App installation ID on repo units (#5215)
  • 3ab759f Refine SECURITY.md (#5216)
  • 2cdb97d [SCAN-101] s3 source accept persisted unit envelopes in UnmarshalSourceUnit (...
  • 4ec7749 preallocate bindings capacity in dockerhub and groq, with unit tests (#5213)
  • 9610306 Doubled timeout, as MongoDB secrets are repeatedly hitting this and failing t...
  • 9d3f5d1 [SCAN-1020] neon scram pgx (#5217)
  • 925c1d0 fix(detectors/docker): don't greedy match in keyPat (#5214)
  • e12da3c docs: add generic config-secret custom detector example (#5195)
  • bcbcab2 Fix GHEC with Data Residency (*.ghe.com) base URL (#4777)
  • bc3a3ae Update module github.com/go-git/go-git/v5 to v5.19.2 [SECURITY] (#5196)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cicd group with 4 updates: [actions/cache](https://github.com/actions/cache), [actions/cache/save](https://github.com/actions/cache), [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) and [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog).


Updates `actions/cache` from 5.0.5 to 5.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...caa2961)

Updates `actions/cache/save` from 5.0.5 to 5.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...caa2961)

Updates `hadolint/hadolint-action` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/hadolint/hadolint-action/releases)
- [Commits](hadolint/hadolint-action@2a66e89...06be81b)

Updates `trufflesecurity/trufflehog` from 3.97.0 to 3.97.1
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@bcfcf73...20652fb)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: actions/cache/save
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: hadolint/hadolint-action
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file minor New features that do not break anything no-release Do not create a new release (wait for additional code changes) labels Sep 13, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 13, 2026 00:18
@dependabot @github

dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added no-release Do not create a new release (wait for additional code changes) minor New features that do not break anything dependencies Pull requests that update a dependency file labels Sep 13, 2026
@atmos-pro

atmos-pro Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Note

Atmos Pro  

Waiting for your GitHub Actions workflow to upload affected stacks.
Learn More.

@github-actions github-actions Bot added size/xs Extra small size PR and removed minor New features that do not break anything labels Sep 13, 2026
@github-actions

github-actions Bot commented Sep 13, 2026

Copy link
Copy Markdown

Warning

SHA Pin Verification Passed — with documented exceptions

All 234 third-party action reference(s) are covered, but 2 rely on a documented allowlist entry in allowlist.json and could not be automatically drift-checked. This does not fail CI, but should be reviewed.

Action Location Status Details
aquasecurity/trivy-action@v0.36.0 build.yml:144 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.
aquasecurity/trivy-action@v0.36.0 test.yml:1264 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.

See the action run for full details.

@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ❌ 1 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/trufflehog.yml

PackageVersionLicenseIssue Type
trufflesecurity/trufflehog20652fbbdefffcdaa493a5bf57ab2ac6b1db715bAGPL-3.0Incompatible License
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-2-Clause, BSD-2-Clause-Views, BSD-3-Clause, ISC, MPL-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, Python-2.0, OFL-1.1, LicenseRef-scancode-generic-cla, LicenseRef-scancode-unknown-license-reference, LicenseRef-scancode-unicode, LicenseRef-scancode-google-patent-license-golang
Excluded from license check: pkg:golang/github.com/antlr4-go/antlr/v4, pkg:golang/github.com/google/cel-go, pkg:golang/golang.org/x/image, pkg:golang/modernc.org/libc, pkg:golang/github.com/opencontainers/go-digest, pkg:npm/pako, pkg:npm/sax

Scanned Files

  • .github/workflows/trufflehog.yml

@mergify mergify Bot added the auto-update This PR was automatically generated label Sep 13, 2026
@mergify

mergify Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@mergify mergify Bot added the needs-cloudposse Needs Cloud Posse assistance label Sep 13, 2026
@codecov

codecov Bot commented Sep 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.29%. Comparing base (411f892) to head (f859b34).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #3152   +/-   ##
=======================================
  Coverage   84.29%   84.29%           
=======================================
  Files        2047     2047           
  Lines      202085   202085           
=======================================
+ Hits       170345   170352    +7     
+ Misses      23536    23527    -9     
- Partials     8204     8206    +2     
Flag Coverage Δ
unittests 84.29% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 7 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Sep 15, 2026

Copy link
Copy Markdown

CI timing summary

Latest completed GitHub Actions runs for f859b348bee5.

  • PR wall-clock time: 28m 47s
  • Aggregate runner time: 8h 50m 25s
  • Included: 14 workflows, 117 jobs (including matrix jobs)

Wall-clock time spans the earliest included workflow creation through the latest completion. Aggregate runner time adds each job's execution time, so concurrent jobs are counted separately.

Workflow Elapsed Runner time Jobs
Tests 28m 45s 8h 24m 17s 97
CodeQL 9m 56s 14m 59s 6
atmos.ci 4m 49s 4m 45s 1
Pre-commit 2m 41s 2m 37s 1
Verify SHA Pinning 51s 48s 1
TruffleHog secret scan 46s 41s 1
Validate Codeowners 29s 25s 1
vhs 28s 23s 3
Release Documentation Check 27s 22s 1
Dependency Review 26s 22s 1
PR Size Labeler 22s 18s 1
Verify Repository Symlinks 21s 17s 1
autofix.ci 13s 11s 1
⏭️ Feature release 1s 0s 1
Longest jobs (top 10)
Job Workflow Duration Conclusion
[race] non-acceptance test suite (shard 2/4) Tests 20m 15s ✅ success
[k3s-macos] helm Tests 15m 31s ✅ success
[floci] go e2e Tests 14m 59s ✅ success
Acceptance Tests (macos, shard 3/10) Tests 13m 39s ✅ success
Acceptance Tests (macos, shard 1/10) Tests 13m 31s ✅ success
Acceptance Tests (windows, shard 1/10) Tests 13m 30s ✅ success
Acceptance Tests (macos, shard 2/10) Tests 13m 26s ✅ success
[k3s-macos] demo-helmfile Tests 13m 25s ✅ success
Acceptance Tests (windows, shard 3/10) Tests 12m 43s ✅ success
[race] non-acceptance test suite (shard 1/4) Tests 12m 37s ✅ success

Updated automatically when a PR workflow finishes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-update This PR was automatically generated dependencies Pull requests that update a dependency file needs-cloudposse Needs Cloud Posse assistance no-release Do not create a new release (wait for additional code changes) size/xs Extra small size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants