feat: bump the github-actions group across 1 directory with 14 updates - #84
Conversation
…dates Bumps the github-actions group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.1` | `2.19.4` | | [EnricoMi/publish-unit-test-result-action](https://github.com/enricomi/publish-unit-test-result-action) | `2.23.0` | `2.24.0` | | [dataaxiom/ghcr-cleanup-action](https://github.com/dataaxiom/ghcr-cleanup-action) | `1.0.16` | `1.2.2` | | [actions/stale](https://github.com/actions/stale) | `10.2.0` | `10.3.0` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.3` | `0.5.7` | | [oxsecurity/megalinter/flavors/dotnet](https://github.com/oxsecurity/megalinter) | `9.4.0` | `9.5.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.35.4` | `4.36.2` | | [reviewdog/action-suggester](https://github.com/reviewdog/action-suggester) | `1.24.0` | `1.24.3` | | [rdlf0/comment-released-prs-action](https://github.com/rdlf0/comment-released-prs-action) | `3.1.0` | `3.2.0` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `3.1.1` | `3.2.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.0.0` | `4.1.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.2.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.0.0` | `6.1.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.1.0` | `7.2.0` | Updates `step-security/harden-runner` from 2.19.1 to 2.19.4 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a5ad31d...9af89fc) Updates `EnricoMi/publish-unit-test-result-action` from 2.23.0 to 2.24.0 - [Release notes](https://github.com/enricomi/publish-unit-test-result-action/releases) - [Commits](EnricoMi/publish-unit-test-result-action@c950f6f...d0a4676) Updates `dataaxiom/ghcr-cleanup-action` from 1.0.16 to 1.2.2 - [Release notes](https://github.com/dataaxiom/ghcr-cleanup-action/releases) - [Commits](dataaxiom/ghcr-cleanup-action@cd0cdb9...d52806a) Updates `actions/stale` from 10.2.0 to 10.3.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@b5d41d4...eb5cf3a) Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.5.7 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@b1d7e1f...192e21d) Updates `oxsecurity/megalinter/flavors/dotnet` from 9.4.0 to 9.5.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@8fbdead...0e3ce9b) Updates `github/codeql-action/upload-sarif` from 4.35.4 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...8aad20d) Updates `reviewdog/action-suggester` from 1.24.0 to 1.24.3 - [Release notes](https://github.com/reviewdog/action-suggester/releases) - [Commits](reviewdog/action-suggester@aa38384...2558ba1) Updates `rdlf0/comment-released-prs-action` from 3.1.0 to 3.2.0 - [Release notes](https://github.com/rdlf0/comment-released-prs-action/releases) - [Commits](rdlf0/comment-released-prs-action@a81897e...249f57b) Updates `actions/create-github-app-token` from 3.1.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](actions/create-github-app-token@1b10c78...bcd2ba4) Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@4d04d5d...d7f5e7f) Updates `docker/login-action` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@4907a6d...650006c) Updates `docker/metadata-action` from 6.0.0 to 6.1.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@030e881...80c7e94) Updates `docker/build-push-action` from 7.1.0 to 7.2.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@bcafcac...f9f3042) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: EnricoMi/publish-unit-test-result-action dependency-version: 2.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dataaxiom/ghcr-cleanup-action dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/stale dependency-version: 10.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.5.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: oxsecurity/megalinter/flavors/dotnet dependency-version: 9.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: reviewdog/action-suggester dependency-version: 1.24.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: rdlf0/comment-released-prs-action dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 24 | 0 | 0 | 0.7s | |
| ✅ ACTION | zizmor | 24 | 0 | 0 | 0 | 3.95s |
| ✅ DOCKERFILE | hadolint | 3 | 0 | 0 | 0.46s | |
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.66s | |
| ✅ JSON | prettier | 22 | 3 | 0 | 0 | 0.73s |
| ✅ JSON | v8r | 22 | 0 | 0 | 12.57s | |
| ✅ MARKDOWN | markdownlint | 12 | 0 | 0 | 0 | 1.29s |
| ✅ MARKDOWN | markdown-table-formatter | 12 | 1 | 0 | 0 | 0.32s |
| ✅ REPOSITORY | checkov | yes | no | no | 28.27s | |
| ✅ REPOSITORY | gitleaks | yes | no | no | 2.42s | |
| ✅ REPOSITORY | git_diff | yes | no | no | 0.02s | |
| ✅ REPOSITORY | grype | yes | no | no | 66.87s | |
| ✅ REPOSITORY | osv-scanner | yes | no | no | 0.68s | |
| ✅ REPOSITORY | secretlint | yes | no | no | 2.03s | |
| ✅ REPOSITORY | syft | yes | no | no | 3.02s | |
| ✅ REPOSITORY | trivy | yes | no | no | 13.29s | |
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.72s | |
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.61s | |
| lychee | 86 | 3 | 0 | 11.21s | ||
| ✅ YAML | prettier | 32 | 0 | 0 | 0 | 1.26s |
| ✅ YAML | v8r | 32 | 0 | 0 | 13.48s | |
| ✅ YAML | yamllint | 32 | 0 | 0 | 1.13s |
Detailed Issues
⚠️ SPELL / lychee - 3 errors
📝 Summary
---------------------
🔍 Total..........133
🔗 Unique.........112
✅ Successful.....125
⏳ Timeouts.........0
🔀 Redirected......13
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........3
⛔ Unsupported......3
Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 30:7) | Rejected status code: 403 Forbidden
Errors in README.md
[ERROR] https://docs.sigstore.dev/cosign/signing/overview/ (at 135:76) | Network error: Connection reset by peer (os error 104)
[ERROR] https://docs.sigstore.dev/cosign/verifying/verify/ (at 137:22) | Network error: Connection reset by peer (os error 104)
Hint: Followed 13 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
Notices
📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/salesforce@v9.5.0 (59 linters)
- oxsecurity/megalinter/flavors/javascript@v9.5.0 (62 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@9.5.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
Test Results 12 files 12 suites 17m 2s ⏱️ For more details on these failures, see this check. Results for commit 4cae0a6. |
…sion Dockerfile installs Qt 6.10.2 with win64_msvc2022_64 (#70) but the integration test still asserted the old 6.4.2/msvc2019_64 path, failing on every base image variant regardless of unrelated changes.
zizmor (bumped via this PR) newly flags two container refs as unpinned images: update-dependencies.yml's intentional :latest tracking container, and wc-integration-test.yml's already digest-pinned output — both suppressed with documented ignores. Also move DOCKERHUB_USERNAME into env to close a template-injection finding in the same file. osv-scanner flags brace-expansion (npm, fixed by bumping to 5.0.8) and bare-metal (rust, deprecated with no fixed version available) — added a scoped osv-scanner.toml ignore for the latter in the two cortex-m/cortex-mf test fixtures that pull it in transitively.
Pull Request Report (#84)Static measures
Time related measures
Status check related measures
|
|
🎉 Hooray! The changes in this pull request went live with the release of v7.3.0 🎉 |
Bumps the github-actions group with 14 updates in the / directory:
2.19.12.19.42.23.02.24.01.0.161.2.210.2.010.3.00.5.30.5.79.4.09.5.04.35.44.36.21.24.01.24.33.1.03.2.03.1.13.2.04.0.04.1.04.1.04.2.06.0.06.1.07.1.07.2.0Updates
step-security/harden-runnerfrom 2.19.1 to 2.19.4Release notes
Sourced from step-security/harden-runner's releases.
Commits
9af89fcMerge pull request #667 from step-security/update-agent-v1.8.6485dce8Update agent to v1.8.6ab7a940Merge pull request #665 from step-security/fix/use-policy-store-default-auditec41b78Default to audit mode when api-key missing with use-policy-store9ca718dMerge pull request #664 from step-security/update-agent-v1.8.51dee3dfUpdate agent to v1.8.5Updates
EnricoMi/publish-unit-test-result-actionfrom 2.23.0 to 2.24.0Release notes
Sourced from EnricoMi/publish-unit-test-result-action's releases.
Commits
d0a4676Releasing v2.24.0473c3f2Upgrade GitHub Actions in action.yml files (#776)49f3291Add Ubuntu 26.04, add arm versions (#775)4ed2544Bump emibcn/badge-action from 2.0.3 to 2.0.4 (#758)f2856f6Bump docker/metadata-action from 5.10.0 to 6.1.0 (#760)5ec6b13Bump docker/setup-qemu-action from 3.7.0 to 4.1.0 (#759)a199e4eUse env var indirection for Docker action inputs (#737)60b1d8cBump github/codeql-action from 4.32.4 to 4.36.0 (#757)b1d9536Bump docker/build-push-action from 6.19.2 to 7.2.0 (#756)17f8820Revert "Create and add workflow to enhance dependabot GHA upgrade PRs (#761)"Updates
dataaxiom/ghcr-cleanup-actionfrom 1.0.16 to 1.2.2Release notes
Sourced from dataaxiom/ghcr-cleanup-action's releases.
Commits
d52806aMerge pull request #129 from rohanmars/main7f28f9dfeat: add skip-regex-checks input to opt out of regex safety guardsf092b48Merge pull request #122 from rohanmars/mainfa3daf5ci: hoist fork-PR approval gate to a single job (was per matrix entry)c1ba289fix: synchronously claim digests before delete to prevent concurrent duplicat...f5e37e7fix: tolerate all 404s on package version delete; always flush per-tree log b...374e202Merge pull request #120 from rohanmars/code-reviewe1e6176perf: cap per-listing log volume at 1000 lines (truncate at INFO)6516895fix: drop the post-reload untag-ops invariant assertion (3.1.5 retraction)5a020affeat: buffer deleteImage logs per top-level tree, flush atomicallyUpdates
actions/stalefrom 10.2.0 to 10.3.0Release notes
Sourced from actions/stale's releases.
Commits
eb5cf3achore: upgrade dependencies and bump version to 10.3.0 (#1335)db5d06aEnhancement: ignore stale labeling events (#1311)Updates
zizmorcore/zizmor-actionfrom 0.5.3 to 0.5.7Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
192e21dSync zizmor versions (#127)2720f26Update README.md with new actions/checkout version (#126)40b41b8chore(deps): bump the github-actions group with 2 updates (#123)a687b25chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 in the github-ac...64a6900add note to explain that the default value foronline-checksis different t...14050abchore(deps): bump the github-actions group with 2 updates (#118)ee9b419chore(deps): bump github/codeql-action in the github-actions group (#116)fddf2b4Bump pins in README (#115)5f14fd0Sync zizmor versions (#114)a16621bBump pins in README (#112)Updates
oxsecurity/megalinter/flavors/dotnetfrom 9.4.0 to 9.5.0Release notes
Sourced from oxsecurity/megalinter/flavors/dotnet's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter/flavors/dotnet's changelog.
... (truncated)
Commits
0e3ce9bFix release workflows.3e132b1Release MegaLinter v9.5.0cbb7fe9Doc + prepare 9.5.0 release (#7836)29bcf10[automation] Auto-update linters version, help and documentation (#7832)ed753c5chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)e04f202feat: implement user notifications system and replace migration warnings (#7833)54bfad8chore(deps): update dependency@stoplight/spectral-clito v6.16.0 (#7830)f809408Eslint legacy detection & warning (#7831)6725b65chore(deps): update dependency langsmith to v0.8.5 (#7828)cbcc02fchore(deps): update dependency rumdl to v0.1.93 (#7825)Updates
github/codeql-action/upload-sariffrom 4.35.4 to 4.36.2Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
8aad20dMerge pull request #3949 from github/update-v4.36.2-dcb947ce1f521b08Add additional changelog notes8aeff0fUpdate changelog for v4.36.2dcb947cMerge pull request #3948 from github/update-bundle/codeql-bundle-v2.25.6c251bceAdd changelog note62953c1Update default bundle to codeql-bundle-v2.25.6423b570Merge pull request #3946 from github/dependabot/npm_and_yarn/npm-minor-5d507a...c35d1b1Merge pull request #3947 from github/dependabot/github_actions/dot-github/wor...cb1a588Merge pull request #3937 from github/robertbrignull/waitForProcessing_backoffba47406Merge pull request #3943 from github/henrymercer/cache-cli-version-infoUpdates
reviewdog/action-suggesterfrom 1.24.0 to 1.24.3Release notes
Sourced from reviewdog/action-suggester's releases.
Commits
2558ba1Merge pull request #112 from reviewdog/renovate/go-1.x344d690Merge pull request #109 from reviewdog/renovate/actions-setup-go-6.xeaae686Merge pull request #108 from reviewdog/renovate/reviewdog-action-setup-1.x0a13364Merge pull request #106 from reviewdog/renovate/reviewdog-action-misspell-1.x604cbc1Merge pull request #105 from reviewdog/renovate/reviewdog-action-actionlint-1.x50c0a5echore(deps): update reviewdog/action-misspell action to v1.27.0d5e0f41chore(deps): update reviewdog/action-actionlint action to v1.72.0f32de73chore(deps): update actions/setup-go action to v6.4.02338685Merge pull request #114 from reviewdog/renovate/actions-checkout-7.x9dc1d8bchore(deps): update actions/checkout action to v7Updates
rdlf0/comment-released-prs-actionfrom 3.1.0 to 3.2.0Release notes
Sourced from rdlf0/comment-released-prs-action's releases.
Commits
249f57bDependency bumps and refactoring (#28)afdf717Bump undici from 5.28.5 to 5.29.0 (#24)14cc9efBump undici from 5.28.4 to 5.28.5 (#23)Updates
actions/create-github-app-tokenfrom 3.1.1 to 3.2.0Release notes
Sourced from actions/create-github-app-token's releases.
Changelog
Sourced from actions/create-github-app-token's changelog.
Commits
bcd2ba4chore(main): release 3.2.0 (#370)f24bbd8fix: validate private-key input (#376)363531bdocs: capitalize Git as a proper noun in README (#374)fd28011docs: update procedure to configure Git (#287)85eb8ddfeat: support full repository names inrepositoriesinput (#372)c9aabb8build(deps-dev): bump yaml from 2.8.3 to 2.8.4 in the development-dependencie...e02e816build(deps-dev): bump undici from 7.24.6 to 8.2.0 (#366)8d835bfbuild(deps-dev): bump esbuild from 0.27.4 to 0.28.0 in the development-depend...952a2a7feat: add support for enterprise-level GitHub Apps (#263)43e5c34fix(deps): bump@actions/corefrom 3.0.0 to 3.0.1 in the production-dependenc...Updates
docker/setup-buildx-actionfrom 4.0.0 to 4.1.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
d7f5e7fMerge pull request #489 from docker/dependabot/npm_and_yarn/docker/actions-to...92bc5c9chore: update generated contentda11e35build(deps): bump@docker/actions-toolkitfrom 0.79.0 to 0.90.0f021e16Merge pull request #492 from docker/dependabot/npm_and_yarn/undici-6.24.1b5af94fchore: update generated content16ad977build(deps): bump undici from 6.23.0 to 6.25.0d7a12d7Merge pull request #495 from docker/dependabot/npm_and_yarn/glob-10.5.028ff27dbuild(deps): bump glob from 10.3.12 to 13.0.6daf436bMerge pull request #496 from docker/dependabot/npm_and_yarn/fast-xml-parser-5...9725348chore: update generated contentUpdates
docker/login-actionfrom 4.1.0 to 4.2.0Release notes
Sourced from docker/login-action's releases.
Commits
650006cMerge pull request #960 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...99df1a3chore: update generate...Description has been truncated