Skip to content

Commit 7b3a8b5

Browse files
Bump the github-actions group across 1 directory with 13 updates
Bumps the github-actions group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.5.1` | `2.8.1` | | [actions/checkout](https://github.com/actions/checkout) | `3.5.3` | `4.1.7` | | [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `1.5.5` | `1.6.3` | | [docker/login-action](https://github.com/docker/login-action) | `3.0.0` | `3.2.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.0.0` | `5.5.1` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `5.0.0` | `6.1.0` | | [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description) | `3.4.2` | `4.0.0` | | [fsfe/reuse-action](https://github.com/fsfe/reuse-action) | `2` | `3` | | [github/codeql-action](https://github.com/github/codeql-action) | `2.22.5` | `3.25.10` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.1` | `2.3.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `3.1.2` | `4.3.3` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.16.21` | `1.22.9` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `3` | `4` | Updates `step-security/harden-runner` from 2.5.1 to 2.8.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@v2.5.1...17d0e2b) Updates `actions/checkout` from 3.5.3 to 4.1.7 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v3.5.3...v4.1.7) Updates `EmbarkStudios/cargo-deny-action` from 1.5.5 to 1.6.3 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@1e59595...3f4a782) Updates `docker/login-action` from 3.0.0 to 3.2.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@343f7c4...0d4c9c5) Updates `docker/metadata-action` from 5.0.0 to 5.5.1 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@96383f4...8e5442c) Updates `docker/build-push-action` from 5.0.0 to 6.1.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@0565240...31159d4) Updates `peter-evans/dockerhub-description` from 3.4.2 to 4.0.0 - [Release notes](https://github.com/peter-evans/dockerhub-description/releases) - [Commits](peter-evans/dockerhub-description@dc67fad...e98e4d1) Updates `fsfe/reuse-action` from 2 to 3 - [Release notes](https://github.com/fsfe/reuse-action/releases) - [Commits](fsfe/reuse-action@v2...v3) Updates `github/codeql-action` from 2.22.5 to 3.25.10 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@74483a3...23acc5c) Updates `ossf/scorecard-action` from 2.3.1 to 2.3.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@0864cf1...dc50aa9) Updates `actions/upload-artifact` from 3.1.2 to 4.3.3 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v3.1.2...6546280) Updates `crate-ci/typos` from 1.16.21 to 1.22.9 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@47dd297...c16dc8f) Updates `codecov/codecov-action` from 3 to 4 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@v3...v4) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: EmbarkStudios/cargo-deny-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: peter-evans/dockerhub-description dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: fsfe/reuse-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: crate-ci/typos dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 11c731a commit 7b3a8b5

File tree

9 files changed

+40
-40
lines changed

9 files changed

+40
-40
lines changed

.github/workflows/audit.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
checks: write
2525
steps:
2626
- name: Harden Runner
27-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
27+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
2828
with:
2929
egress-policy: block
3030
allowed-endpoints: >
@@ -36,7 +36,7 @@ jobs:
3636
static.rust-lang.org:443
3737
index.crates.io:443
3838
39-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
39+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
4040
- uses: Swatinem/rust-cache@81d053bdb0871dcd3f10763c8cc60d0adc41762b
4141
- uses: actions-rs/audit-check@35b7b53b1e25b55642157ac01b4adceb5b9ebef3
4242
with:
@@ -54,7 +54,7 @@ jobs:
5454

5555
steps:
5656
- name: Harden Runner
57-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
57+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
5858
with:
5959
egress-policy: block
6060
allowed-endpoints: >
@@ -67,7 +67,7 @@ jobs:
6767
static.rust-lang.org:443
6868
index.crates.io:443
6969
70-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
71-
- uses: EmbarkStudios/cargo-deny-action@1e59595bed8fc55c969333d08d7817b36888f0c5
70+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
71+
- uses: EmbarkStudios/cargo-deny-action@3f4a782664881cf5725d0ffd23969fcce89fd868
7272
with:
7373
command: check ${{ matrix.checks }}

.github/workflows/benchmark pullrequest.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,11 +36,11 @@ jobs:
3636
- 5432:5432
3737
steps:
3838
- name: Harden Runner
39-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
39+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
4040
with:
4141
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4242

43-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
43+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
4444
with:
4545
set-safe-directory: true
4646
- run: rustup default nightly

.github/workflows/benchmark.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,11 +36,11 @@ jobs:
3636
- 5432:5432
3737
steps:
3838
- name: Harden Runner
39-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
39+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
4040
with:
4141
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
4242

43-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
43+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
4444
with:
4545
set-safe-directory: true
4646
- run: rustup default nightly

.github/workflows/docker-image.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919

2020
steps:
2121
- name: Harden Runner
22-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
22+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
2323
with:
2424
egress-policy: block
2525
allowed-endpoints: >
@@ -39,26 +39,26 @@ jobs:
3939
static.rust-lang.org:443
4040
index.crates.io:443
4141
42-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
42+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
4343
- name: Log in to Docker Hub
44-
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d
44+
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446
4545
with:
4646
username: ${{ secrets.DOCKERHUB_USERNAME }}
4747
password: ${{ secrets.DOCKERHUB_PASSWORD }}
4848
- name: Extract metadata (tags, labels) for Docker
4949
id: meta
50-
uses: docker/metadata-action@96383f45573cb7f253c731d3b3ab81c87ef81934
50+
uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81
5151
with:
5252
images: mtrnord/erooster
5353
- name: Build and push
54-
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09
54+
uses: docker/build-push-action@31159d49c0d4756269a0940a750801a1ea5d7003
5555
with:
5656
context: .
5757
push: true
5858
tags: ${{ steps.meta.outputs.tags }}
5959
labels: ${{ steps.meta.outputs.labels }}
6060
- name: Update repo description
61-
uses: peter-evans/dockerhub-description@dc67fad7001ef9e8e3c124cb7a64e16d0a63d864
61+
uses: peter-evans/dockerhub-description@e98e4d1628a5f3be2be7c231e50981aee98723ae
6262
with:
6363
username: ${{ secrets.DOCKERHUB_USERNAME }}
6464
password: ${{ secrets.DOCKERHUB_PASSWORD }}

.github/workflows/reuse.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,6 @@ jobs:
1010
test:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v4
13+
- uses: actions/checkout@v4.1.7
1414
- name: REUSE Compliance Check
15-
uses: fsfe/reuse-action@v2
15+
uses: fsfe/reuse-action@v3

.github/workflows/rust-clippy.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
security-events: write
2525
steps:
2626
- name: Harden Runner
27-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
27+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
2828
with:
2929
egress-policy: block
3030
allowed-endpoints: >
@@ -39,7 +39,7 @@ jobs:
3939
index.crates.io:443
4040
4141
- name: Checkout code
42-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
42+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
4343

4444
- name: Install Rust toolchain
4545
uses: actions-rs/toolchain@16499b5e05bf2e26879000db0c1d13f7e13fa3af #@v1
@@ -61,7 +61,7 @@ jobs:
6161
continue-on-error: true
6262

6363
- name: Upload analysis results to GitHub
64-
uses: github/codeql-action/upload-sarif@74483a38d39275f33fcff5f35b679b5ca4a26a99
64+
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251
6565
with:
6666
sarif_file: rust-clippy-results.sarif
6767
wait-for-processing: true

.github/workflows/scorecards.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929

3030
steps:
3131
- name: Harden Runner
32-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
32+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
3333
with:
3434
egress-policy: block
3535
allowed-endpoints: >
@@ -50,12 +50,12 @@ jobs:
5050
index.crates.io:443
5151
5252
- name: "Checkout code"
53-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # tag=v3.0.0
53+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # tag=v3.0.0
5454
with:
5555
persist-credentials: false
5656

5757
- name: "Run analysis"
58-
uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # tag=v2.3.1
58+
uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # tag=v2.3.3
5959
with:
6060
results_file: results.sarif
6161
results_format: sarif
@@ -74,14 +74,14 @@ jobs:
7474
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
7575
# format to the repository Actions tab.
7676
- name: "Upload artifact"
77-
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # tag=v3.1.3
77+
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # tag=v4.3.3
7878
with:
7979
name: SARIF file
8080
path: results.sarif
8181
retention-days: 5
8282

8383
# Upload the results to GitHub's code scanning dashboard.
8484
- name: "Upload to code-scanning"
85-
uses: github/codeql-action/upload-sarif@74483a38d39275f33fcff5f35b679b5ca4a26a99 # tag=v1.0.26
85+
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # tag=v1.0.26
8686
with:
8787
sarif_file: results.sarif

.github/workflows/spell-check.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-latest
2121
steps:
2222
- name: Harden Runner
23-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
23+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
2424
with:
2525
egress-policy: block
2626
allowed-endpoints: >
@@ -29,9 +29,9 @@ jobs:
2929
env:
3030
USER: runner
3131
- name: Checkout Actions Repository
32-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v2
32+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v2
3333

3434
- name: Check spelling
35-
uses: crate-ci/typos@47dd2976043bd5c76a33aa9300b328a176a1d6f7 # master
35+
uses: crate-ci/typos@c16dc8f5b4a7ad6211464ecf136c69c851e8e83c # master
3636
with:
3737
config: ${{github.workspace}}/_typos.toml

.github/workflows/tests.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
runs-on: ubuntu-latest
1616
steps:
1717
- name: Harden Runner
18-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
18+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
1919
with:
2020
egress-policy: block
2121
allowed-endpoints: >
@@ -29,7 +29,7 @@ jobs:
2929
static.crates.io:443
3030
static.rust-lang.org:443
3131
32-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
32+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
3333
- uses: actions-rs/toolchain@16499b5e05bf2e26879000db0c1d13f7e13fa3af
3434
with:
3535
profile: minimal
@@ -68,11 +68,11 @@ jobs:
6868
- 5432:5432
6969
steps:
7070
- name: Harden Runner
71-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
71+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
7272
with:
7373
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
7474

75-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
75+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
7676
- name: Install Rust
7777
run: rustup toolchain install nightly --component llvm-tools-preview
7878
- uses: Swatinem/rust-cache@81d053bdb0871dcd3f10763c8cc60d0adc41762b
@@ -110,7 +110,7 @@ jobs:
110110
cargo +nightly llvm-cov report --html
111111
env:
112112
RUST_BACKTRACE: "1"
113-
- uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce
113+
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808
114114
with:
115115
name: coverage-report
116116
path: target/llvm-cov/html/
@@ -120,7 +120,7 @@ jobs:
120120
cargo +nightly llvm-cov --no-report --features "jaeger" --workspace
121121
cargo +nightly llvm-cov report --lcov --output-path lcov.info
122122
- name: Upload coverage to Codecov
123-
uses: codecov/codecov-action@v3
123+
uses: codecov/codecov-action@v4
124124
with:
125125
token: ${{ secrets.CODECOV_TOKEN }}
126126
files: lcov.info
@@ -134,11 +134,11 @@ jobs:
134134
options: --user root
135135
steps:
136136
- name: Harden Runner
137-
uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09
137+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
138138
with:
139139
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
140140

141-
- uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9
141+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
142142
- name: Install Rust
143143
run: rustup toolchain install nightly --component llvm-tools-preview
144144
- uses: Swatinem/rust-cache@81d053bdb0871dcd3f10763c8cc60d0adc41762b
@@ -176,7 +176,7 @@ jobs:
176176
cargo +nightly llvm-cov report --html
177177
env:
178178
RUST_BACKTRACE: "1"
179-
- uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32
179+
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808
180180
with:
181181
name: coverage-report
182182
path: target/llvm-cov/html/
@@ -186,7 +186,7 @@ jobs:
186186
cargo +nightly llvm-cov --no-report --features "jaeger" --workspace --features sqlite --no-default-features
187187
cargo +nightly llvm-cov report --lcov --output-path lcov.info
188188
- name: Upload coverage to Codecov
189-
uses: codecov/codecov-action@v3
189+
uses: codecov/codecov-action@v4
190190
with:
191191
token: ${{ secrets.CODECOV_TOKEN }}
192192
files: lcov.info
@@ -197,7 +197,7 @@ jobs:
197197
runs-on: ubuntu-latest
198198
steps:
199199
- name: Harden Runner
200-
uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423
200+
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6
201201
with:
202202
egress-policy: block
203203
allowed-endpoints: >
@@ -211,7 +211,7 @@ jobs:
211211
index.crates.io:443
212212
static.crates.io:443
213213
214-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
214+
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
215215
- uses: actions-rs/toolchain@16499b5e05bf2e26879000db0c1d13f7e13fa3af
216216
with:
217217
profile: minimal

0 commit comments

Comments
 (0)