Bump the github-actions-updates group with 5 updates - #30
Conversation
Bumps the github-actions-updates group with 5 updates: | Package | From | To | | --- | --- | --- | | [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) | `1.4.3` | `1.4.4` | | [1password/load-secrets-action](https://github.com/1password/load-secrets-action) | `4.0.1` | `4.1.1` | | [lfreleng-actions/maven-build-action](https://github.com/lfreleng-actions/maven-build-action) | `0.2.2` | `0.3.0` | | [lfreleng-actions/sonatype-lifecycle-scan-action](https://github.com/lfreleng-actions/sonatype-lifecycle-scan-action) | `0.1.4` | `0.2.0` | | [lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml](https://github.com/lfit/releng-reusable-workflows) | `0.9.1` | `0.10.0` | Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.3 to 1.4.4 - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Commits](lfreleng-actions/github2gerrit-action@dac8641...e06d6a2) Updates `1password/load-secrets-action` from 4.0.1 to 4.1.1 - [Release notes](https://github.com/1password/load-secrets-action/releases) - [Commits](1Password/load-secrets-action@3a12b0a...eb2efd0) Updates `lfreleng-actions/maven-build-action` from 0.2.2 to 0.3.0 - [Release notes](https://github.com/lfreleng-actions/maven-build-action/releases) - [Commits](lfreleng-actions/maven-build-action@c2ded37...79f0851) Updates `lfreleng-actions/sonatype-lifecycle-scan-action` from 0.1.4 to 0.2.0 - [Release notes](https://github.com/lfreleng-actions/sonatype-lifecycle-scan-action/releases) - [Commits](lfreleng-actions/sonatype-lifecycle-scan-action@974066f...f5b35cb) Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.9.1 to 0.10.0 - [Release notes](https://github.com/lfit/releng-reusable-workflows/releases) - [Commits](lfit/releng-reusable-workflows@973bba8...0688b11) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml dependency-version: 1.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions-updates - dependency-name: 1password/load-secrets-action dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/maven-build-action dependency-version: 0.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfreleng-actions/sonatype-lifecycle-scan-action dependency-version: 0.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml dependency-version: 0.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #30 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/api/+/146776 |
Bumps the github-actions-updates group with 5 updates: | Package | From | To | | --- | --- | --- | | lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml | `1.4.3` | `1.4.4` | | 1password/load-secrets-action | `4.0.1` | `4.1.1` | | lfreleng-actions/maven-build-action | `0.2.2` | `0.3.0` | | lfreleng-actions/sonatype-lifecycle-scan-action | `0.1.4` | `0.2.0` | | lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml | `0.9.1` | `0.10.0` | Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.3 to 1.4.4 ## Release notes Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases. v1.4.4 🔧 Maintenance 🔧 Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test.yaml from 0.1.1 to 0.2.0 @dependabot[bot] (#337) Chore: Bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 @dependabot[bot] (#338) Chore: Bump lfreleng-actions/python-workflows/.github/workflows/build-test-release.yaml from 0.1.1 to 0.2.0 @dependabot[bot] (#339) Chore: Bump ruff from 0.15.20 to 0.15.21 @dependabot[bot] (#340) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#341) Chore: Bump setuptools from 80.9.0 to 83.0.0 @dependabot[bot] (#343) Chore: Bump actions/setup-python from 6.3.0 to 7.0.0 @dependabot[bot] (#344) Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#345) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#346) Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#347) Chore: Bump mypy from 2.2.0 to 2.3.0 @dependabot[bot] (#348) Chore: Bump ruff from 0.15.21 to 0.15.22 @dependabot[bot] (#349) Chore: Bump typer from 0.26.8 to 0.27.0 @dependabot[bot] (#350) Chore: resolve aislop findings across codebase @ModeSevenIndustrialSolutions (#342) Links Submit bugs/feature requests ## Commits e06d6a2 Merge pull request #342 from modeseven-lfreleng-actions/fix/aislop-basedpyrig 5621bd3 Chore: resolve aislop findings across codebase 948b7f2 Merge pull request #350 from lfreleng-actions/dependabot/uv/typer-0.27.0 4f253d4 Merge pull request #349 from lfreleng-actions/dependabot/uv/ruff-0.15.22 f0296e7 Merge pull request #348 from lfreleng-actions/dependabot/uv/mypy-2.3.0 ad1905e Merge pull request #347 from lfreleng-actions/dependabot/github_actions/actio 3532167 Merge pull request #346 from lfreleng-actions/dependabot/github_actions/lfit/ 4bc7d71 Merge pull request #345 from lfreleng-actions/dependabot/github_actions/relea 9c24e49 Merge pull request #344 from lfreleng-actions/dependabot/github_actions/actio 2584d4b Merge pull request #343 from lfreleng-actions/dependabot/uv/setuptools-83.0.0 Additional commits viewable in compare view Updates `1password/load-secrets-action` from 4.0.1 to 4.1.1 ## Release notes Sourced from 1password/load-secrets-action's releases. v4.1.1 What's Changed Features Add fallback version resolution so if app-updates.agilebits.com is unavailable, the action now falls back to Docker Hub and then a baked-in pinned version. (#173 ) Security Harden CI security: add StepSecurity harden runner and pin GitHub Actions to commit SHAs across workflows, restrict workflow permissions, and add Dependabot config. (#174 ) Full Changelog: 1Password/load-secrets-action@v4.0.1...v4.1.1 ## Commits eb2efd0 Merge pull request #183 from 1Password/release/v4.1.1 22158bd Prepare release 19a016f Merge pull request #174 from 1Password/chore/GHA-151735-stepsecurity-remediation 01723ec Merge pull request #173 from 1Password/jill/add-docker-hub-fallback-for-cli-i 4eec4d1 Rebuild 2f9fe68 Add CI release check for op version c63b840 Apply GitHub Actions security best practices d97149e Refactor E2E b240826 Update E2E tests 759227f Add pinned version Additional commits viewable in compare view Updates `lfreleng-actions/maven-build-action` from 0.2.2 to 0.3.0 ## Release notes Sourced from lfreleng-actions/maven-build-action's releases. v0.3.0 ✨ New Features ✨ Feat: add build outputs, summary and artifacts @ModeSevenIndustrialSolutions (#106) 🐛 Bug Fixes 🐛 Fix: resolve Zizmor pin version-mismatch findings @ModeSevenIndustrialSolutions (#91) Fix: resolve zizmor auditor persona findings @ModeSevenIndustrialSolutions (#98) 🔧 Maintenance 🔧 Chore: pre-commit autoupdate @pre-commit-ci[bot] (#86) Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#90) Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#88) Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#87) Chore: Bump actions/setup-java from 5.2.0 to 5.3.0 @dependabot[bot] (#89) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#92) Chore: Bump actions/setup-go from 6.4.0 to 6.5.0 @dependabot[bot] (#93) Chore: Bump actions/setup-java from 5.3.0 to 5.4.0 @dependabot[bot] (#94) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.4 @dependabot[bot] (#95) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#97) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#99) Chore: Bump actions/setup-java from 5.4.0 to 5.5.0 @dependabot[bot] (#100) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#101) Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#102) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#103) Chore: Bump actions/setup-java from 5.5.0 to 5.6.0 @dependabot[bot] (#104) Chore: Bump actions/setup-go from 6.5.0 to 7.0.0 @dependabot[bot] (#105) 🎓 Code Quality 🎓 CI: Add OpenSSF Scorecard workflow @ModeSevenIndustrialSolutions (#96) Links Submit bugs/feature requests ## Commits 79f0851 Merge pull request #106 from modeseven-lfreleng-actions/feat/outputs-summary- ed42d66 Feat: add build outputs, summary and artifacts 3416a69 Merge pull request #105 from lfreleng-actions/dependabot/github_actions/actio 107d261 Merge pull request #104 from lfreleng-actions/dependabot/github_actions/actio 007d21f Chore: Bump actions/setup-go from 6.5.0 to 7.0.0 d7642af Chore: Bump actions/setup-java from 5.5.0 to 5.6.0 090634f Merge pull request #103 from lfreleng-actions/pre-commit-ci-update-config f6fefb9 Chore: pre-commit autoupdate 14e0dbb Merge pull request #102 from lfreleng-actions/dependabot/github_actions/step- b408291 Merge pull request #101 from lfreleng-actions/dependabot/github_actions/lfit/ Additional commits viewable in compare view Updates `lfreleng-actions/sonatype-lifecycle-scan-action` from 0.1.4 to 0.2.0 ## Release notes Sourced from lfreleng-actions/sonatype-lifecycle-scan-action's releases. v0.2.0 ✨ New Features ✨ Feat: Add error handling and CLI property inputs @ModeSevenIndustrialSolutions (#153) 🔧 Maintenance 🔧 Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#134) Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#136) Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#137) Chore: Bump actions/setup-java from 5.2.0 to 5.3.0 @dependabot[bot] (#135) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#138) Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.4 @dependabot[bot] (#139) Chore: Bump actions/setup-java from 5.3.0 to 5.4.0 @dependabot[bot] (#140) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#143) Chore: Bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @dependabot[bot] (#144) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#145) Chore: Bump actions/setup-java from 5.4.0 to 5.5.0 @dependabot[bot] (#146) Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#147) Chore: Bump sonatype/actions/run-iq-cli from 1.12.0 to 1.13.0 @dependabot[bot] (#148) Chore: Bump sonatype/actions/setup-iq-cli from 1.12.0 to 1.13.0 @dependabot[bot] (#149) Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#150) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#151) Chore: Bump actions/setup-java from 5.5.0 to 5.6.0 @dependabot[bot] (#152) 🎓 Code Quality 🎓 CI: Add OpenSSF Scorecard workflow @ModeSevenIndustrialSolutions (#141) CI(security): Resolve zizmor auditor findings @ModeSevenIndustrialSolutions (#142) Links Submit bugs/feature requests ## Commits f5b35cb Merge pull request #153 from modeseven-lfreleng-actions/feat/scan-error-handl 80f8bfb Feat: Add error handling and CLI property inputs 024307d Merge pull request #152 from lfreleng-actions/dependabot/github_actions/actio 683e96a Chore: Bump actions/setup-java from 5.5.0 to 5.6.0 03285ff Merge pull request #151 from lfreleng-actions/pre-commit-ci-update-config 0163d8a Chore: pre-commit autoupdate 409578b Merge pull request #150 from lfreleng-actions/dependabot/github_actions/lfit/ dc79fd9 Merge pull request #149 from lfreleng-actions/dependabot/github_actions/sonat b06c12a Merge pull request #148 from lfreleng-actions/dependabot/github_actions/sonat f2f8f72 Merge pull request #147 from lfreleng-actions/dependabot/github_actions/step- Additional commits viewable in compare view Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.9.1 to 0.10.0 ## Release notes Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases. v0.10.0 ✨ New Features ✨ Feat: Expose Sonatype scan error handling inputs @ModeSevenIndustrialSolutions (#812) 🐛 Bug Fixes 🐛 Fix: support private repos in change isolation @ModeSevenIndustrialSolutions (#813) Links Submit bugs/feature requests ## Commits 0688b11 Merge pull request #812 from modeseven-lfit/feat/sonatype-lifecycle-error-han 26b316b Merge pull request #813 from modeseven-lfit/fix/change-isolation-private-repo e592bab Fix: support private repos in change isolation a6249b8 Feat: Expose Sonatype scan error handling inputs See full diff in compare view Issue-ID: CIMAN-33 Signed-off-by: dependabot[bot] <support@github.com> Change-Id: Ic6e9b3eedb7d9937a3ae0bda493f74a6bcc6b035 GitHub-PR: #30 GitHub-Hash: 7436257b51fda80a Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the github-actions-updates group with 5 updates:
1.4.31.4.44.0.14.1.10.2.20.3.00.1.40.2.00.9.10.10.0Updates
lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yamlfrom 1.4.3 to 1.4.4Release notes
Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.
Commits
e06d6a2Merge pull request #342 from modeseven-lfreleng-actions/fix/aislop-basedpyrig...5621bd3Chore: resolve aislop findings across codebase948b7f2Merge pull request #350 from lfreleng-actions/dependabot/uv/typer-0.27.04f253d4Merge pull request #349 from lfreleng-actions/dependabot/uv/ruff-0.15.22f0296e7Merge pull request #348 from lfreleng-actions/dependabot/uv/mypy-2.3.0ad1905eMerge pull request #347 from lfreleng-actions/dependabot/github_actions/actio...3532167Merge pull request #346 from lfreleng-actions/dependabot/github_actions/lfit/...4bc7d71Merge pull request #345 from lfreleng-actions/dependabot/github_actions/relea...9c24e49Merge pull request #344 from lfreleng-actions/dependabot/github_actions/actio...2584d4bMerge pull request #343 from lfreleng-actions/dependabot/uv/setuptools-83.0.0Updates
1password/load-secrets-actionfrom 4.0.1 to 4.1.1Release notes
Sourced from 1password/load-secrets-action's releases.
Commits
eb2efd0Merge pull request #183 from 1Password/release/v4.1.122158bdPrepare release19a016fMerge pull request #174 from 1Password/chore/GHA-151735-stepsecurity-remediation01723ecMerge pull request #173 from 1Password/jill/add-docker-hub-fallback-for-cli-i...4eec4d1Rebuild2f9fe68Add CI release check for op versionc63b840Apply GitHub Actions security best practicesd97149eRefactor E2Eb240826Update E2E tests759227fAdd pinned versionUpdates
lfreleng-actions/maven-build-actionfrom 0.2.2 to 0.3.0Release notes
Sourced from lfreleng-actions/maven-build-action's releases.
Commits
79f0851Merge pull request #106 from modeseven-lfreleng-actions/feat/outputs-summary-...ed42d66Feat: add build outputs, summary and artifacts3416a69Merge pull request #105 from lfreleng-actions/dependabot/github_actions/actio...107d261Merge pull request #104 from lfreleng-actions/dependabot/github_actions/actio...007d21fChore: Bump actions/setup-go from 6.5.0 to 7.0.0d7642afChore: Bump actions/setup-java from 5.5.0 to 5.6.0090634fMerge pull request #103 from lfreleng-actions/pre-commit-ci-update-configf6fefb9Chore: pre-commit autoupdate14e0dbbMerge pull request #102 from lfreleng-actions/dependabot/github_actions/step-...b408291Merge pull request #101 from lfreleng-actions/dependabot/github_actions/lfit/...Updates
lfreleng-actions/sonatype-lifecycle-scan-actionfrom 0.1.4 to 0.2.0Release notes
Sourced from lfreleng-actions/sonatype-lifecycle-scan-action's releases.
Commits
f5b35cbMerge pull request #153 from modeseven-lfreleng-actions/feat/scan-error-handl...80f8bfbFeat: Add error handling and CLI property inputs024307dMerge pull request #152 from lfreleng-actions/dependabot/github_actions/actio...683e96aChore: Bump actions/setup-java from 5.5.0 to 5.6.003285ffMerge pull request #151 from lfreleng-actions/pre-commit-ci-update-config0163d8aChore: pre-commit autoupdate409578bMerge pull request #150 from lfreleng-actions/dependabot/github_actions/lfit/...dc79fd9Merge pull request #149 from lfreleng-actions/dependabot/github_actions/sonat...b06c12aMerge pull request #148 from lfreleng-actions/dependabot/github_actions/sonat...f2f8f72Merge pull request #147 from lfreleng-actions/dependabot/github_actions/step-...Updates
lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yamlfrom 0.9.1 to 0.10.0Release notes
Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases.
Commits
0688b11Merge pull request #812 from modeseven-lfit/feat/sonatype-lifecycle-error-han...26b316bMerge pull request #813 from modeseven-lfit/fix/change-isolation-private-repo...e592babFix: support private repos in change isolationa6249b8Feat: Expose Sonatype scan error handling inputsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions