Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SEC-090: Automated trusted workflow pinning (2024-09-01) #5063

Merged
merged 1 commit into from
Sep 3, 2024

Conversation

hashicorp-tsccr[bot]
Copy link
Contributor

@hashicorp-tsccr hashicorp-tsccr bot commented Sep 1, 2024

Bumping GitHub Actions version to latest TSCCR release.

  • changes in .github/workflows/build.yml
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
  • changes in .github/workflows/enos-run.yml
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
  • changes in .github/workflows/fuzz.yml
    • bump actions/upload-artifact from v4.3.4 to v4.3.6 (release notes)
  • changes in .github/workflows/security-scan.yml
    • bump github/codeql-action/upload-sarif from codeql-bundle-v2.18.1 to codeql-bundle-v2.18.2 (release notes)

This PR was auto-generated by security-tsccr/actions/runs/10651526549

https://hashicorp.atlassian.net/browse/ICU-15006

You can alter the configuration of this automation via the hcl config in security-tsccr/automation

This PR can be regenerated by dispatching the GitHub workflow Pin Action Refs. Please reach out to #team-prodsec if you have any questions.

@hashicorp-tsccr hashicorp-tsccr bot requested a review from a team as a code owner September 1, 2024 06:03
@hashicorp-tsccr hashicorp-tsccr bot added the SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs. label Sep 1, 2024
@moduli moduli added pr/no-milestone Ignores the Milestone Check backport/0.17.x labels Sep 3, 2024
@moduli moduli merged commit 4e8e069 into main Sep 3, 2024
68 of 72 checks passed
@moduli moduli deleted the tsccr-auto-pinning/trusted/2024-09-01 branch September 3, 2024 19:19
moduli pushed a commit that referenced this pull request Sep 3, 2024
Co-authored-by: hashicorp-tsccr[bot] <hashicorp-tsccr[bot]@users.noreply.github.com>
(cherry picked from commit 4e8e069)
moduli pushed a commit that referenced this pull request Sep 3, 2024
Co-authored-by: hashicorp-tsccr[bot] <hashicorp-tsccr[bot]@users.noreply.github.com>
(cherry picked from commit 4e8e069)
moduli pushed a commit that referenced this pull request Sep 3, 2024
…5068)

Co-authored-by: hashicorp-tsccr[bot] <hashicorp-tsccr[bot]@users.noreply.github.com>
(cherry picked from commit 4e8e069)

Co-authored-by: hashicorp-tsccr[bot] <129506189+hashicorp-tsccr[bot]@users.noreply.github.com>
moduli pushed a commit that referenced this pull request Sep 3, 2024
…5067)

Co-authored-by: hashicorp-tsccr[bot] <hashicorp-tsccr[bot]@users.noreply.github.com>
(cherry picked from commit 4e8e069)

Co-authored-by: hashicorp-tsccr[bot] <129506189+hashicorp-tsccr[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport/0.16.x backport/0.17.x pr/no-milestone Ignores the Milestone Check SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant