Skip to content

Commit b3a6dea

Browse files
chore(deps): bump the actions-deps group with 14 updates
Bumps the actions-deps group with 14 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.13.3` | `2.14.0` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `6.0.1` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.0` | `47.0.1` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.62.61` | `2.65.10` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `5.0.0` | `6.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.31.6` | `4.31.9` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.1` | `5.5.2` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.11.1` | `3.12.0` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.2.1` | `7.2.2` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2.2.0` | `2.2.1` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3.0.0` | `3.1.0` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.9` | `8.0.0` | | [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `2.0.7` | `2.1.1` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.20.10` | `0.21.0` | Updates `step-security/harden-runner` from 2.13.3 to 2.14.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@df199fb...20cf305) Updates `actions/checkout` from 4.2.2 to 6.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4.2.2...8e8c483) Updates `tj-actions/changed-files` from 47.0.0 to 47.0.1 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@24d32ff...e002140) Updates `taiki-e/install-action` from 2.62.61 to 2.65.10 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@92e6dd1...e0db384) Updates `actions/upload-artifact` from 5.0.0 to 6.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@330a01c...b7c566a) Updates `github/codeql-action` from 4.31.6 to 4.31.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@fe4161a...5d4e8d1) Updates `codecov/codecov-action` from 5.5.1 to 5.5.2 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@5a10915...671740a) Updates `docker/setup-buildx-action` from 3.11.1 to 3.12.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@e468171...8d2750c) Updates `anchore/scan-action` from 7.2.1 to 7.2.2 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@40a61b5...3c9a191) Updates `actions/create-github-app-token` from 2.2.0 to 2.2.1 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Commits](actions/create-github-app-token@7e473ef...29824e6) Updates `actions/attest-build-provenance` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@977bb37...00014ed) Updates `peter-evans/create-pull-request` from 7.0.9 to 8.0.0 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@84ae59a...98357b1) Updates `iarekylew00t/verified-bot-commit` from 2.0.7 to 2.1.1 - [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases) - [Commits](IAreKyleW00t/verified-bot-commit@9bc8019...d7e8eea) Updates `anchore/sbom-action` from 0.20.10 to 0.21.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@fbfd9c6...a930d0a) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: actions/checkout dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: tj-actions/changed-files dependency-version: 47.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: taiki-e/install-action dependency-version: 2.65.10 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: actions/upload-artifact dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: github/codeql-action dependency-version: 4.31.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: codecov/codecov-action dependency-version: 5.5.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: docker/setup-buildx-action dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: anchore/scan-action dependency-version: 7.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/create-github-app-token dependency-version: 2.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/attest-build-provenance dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: peter-evans/create-pull-request dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: iarekylew00t/verified-bot-commit dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: anchore/sbom-action dependency-version: 0.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent f350048 commit b3a6dea

File tree

13 files changed

+55
-55
lines changed

13 files changed

+55
-55
lines changed

.github/workflows/ci.yaml

Lines changed: 19 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -38,14 +38,14 @@ jobs:
3838
steps:
3939
# Checkout the repository
4040
- name: Harden the runner (Audit all outbound calls)
41-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
41+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
4242
with:
4343
egress-policy: audit
4444
- name: Checkout Code
4545
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
4646
- name: Get changed files
4747
id: changed-files-yaml
48-
uses: tj-actions/changed-files@24d32ffd492484c1d75e0c0b894501ddb9d30d62 # v47.0.0
48+
uses: tj-actions/changed-files@e0021407031f5be11a464abee9a0776171c79891 # v47.0.1
4949
with:
5050
files_yaml: |
5151
code:
@@ -77,7 +77,7 @@ jobs:
7777
runs-on: ubuntu-22.04-oz-8core
7878
steps:
7979
- name: Harden the runner (Audit all outbound calls)
80-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
80+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
8181
with:
8282
egress-policy: audit
8383
- name: Failed
@@ -90,7 +90,7 @@ jobs:
9090
steps:
9191
# Checkout the repository
9292
- name: Harden the runner (Audit all outbound calls)
93-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
93+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
9494
with:
9595
egress-policy: audit
9696
- name: Checkout Code
@@ -103,7 +103,7 @@ jobs:
103103
- name: Get cache-hit output
104104
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
105105
- name: Install cargo hack
106-
uses: taiki-e/install-action@92e6dd1c202153a204d471a3c509bf1e03dcfa44 # v2.62.61
106+
uses: taiki-e/install-action@dfcb1ee29051d97c8d0f2d437199570008fd5612 # v2.65.15
107107
with:
108108
tool: cargo-hack
109109

@@ -117,7 +117,7 @@ jobs:
117117
steps:
118118
# Checkout the repository
119119
- name: Harden the runner (Audit all outbound calls)
120-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
120+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
121121
with:
122122
egress-policy: audit
123123
- name: Checkout Code
@@ -140,7 +140,7 @@ jobs:
140140
steps:
141141
# Checkout the repository
142142
- name: Harden the runner (Audit all outbound calls)
143-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
143+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
144144
with:
145145
egress-policy: audit
146146
- name: Checkout Code
@@ -164,13 +164,13 @@ jobs:
164164
| sarif-fmt
165165
continue-on-error: true
166166
- name: upload sarif artifact
167-
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
167+
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
168168
with:
169169
name: clippy-results.sarif
170170
path: clippy-results.sarif
171171
retention-days: 1
172172
- name: Upload
173-
uses: github/codeql-action/upload-sarif@fe4161a26a8629af62121b670040955b330f9af2 # v3.29.5
173+
uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v3.29.5
174174
with:
175175
sarif_file: clippy-results.sarif
176176
wait-for-processing: true
@@ -186,7 +186,7 @@ jobs:
186186
runs-on: ubuntu-22.04-oz-8core
187187
steps:
188188
- name: Harden the runner (Audit all outbound calls)
189-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
189+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
190190
with:
191191
egress-policy: audit
192192
- name: Checkout Code
@@ -224,7 +224,7 @@ jobs:
224224
- name: Get cache-hit output
225225
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
226226
- name: Install cargo hack and cargo-llvm-cov
227-
uses: taiki-e/install-action@92e6dd1c202153a204d471a3c509bf1e03dcfa44 # v2.62.61
227+
uses: taiki-e/install-action@dfcb1ee29051d97c8d0f2d437199570008fd5612 # v2.65.15
228228
with:
229229
tool: cargo-hack,cargo-llvm-cov
230230
- name: Run Developer Tests (excluding AI) and Generate Coverage Report
@@ -248,15 +248,15 @@ jobs:
248248
249249
# Upload coverage reports
250250
- name: Upload AI Coverage to Codecov
251-
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
251+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
252252
with:
253253
token: ${{ secrets.CODECOV_TOKEN }}
254254
name: ai-coverage
255255
files: ai-lcov.info
256256
flags: ai
257257
fail_ci_if_error: true
258258
- name: Upload Developer Coverage to Codecov
259-
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
259+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
260260
with:
261261
token: ${{ secrets.CODECOV_TOKEN }}
262262
name: dev-coverage
@@ -273,7 +273,7 @@ jobs:
273273
runs-on: ubuntu-latest
274274
steps:
275275
- name: Harden the runner (Audit all outbound calls)
276-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
276+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
277277
with:
278278
egress-policy: audit
279279
- name: Checkout Code
@@ -300,7 +300,7 @@ jobs:
300300
- name: Get cache-hit output
301301
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
302302
- name: Install cargo hack and cargo-llvm-cov
303-
uses: taiki-e/install-action@92e6dd1c202153a204d471a3c509bf1e03dcfa44 # v2.62.61
303+
uses: taiki-e/install-action@dfcb1ee29051d97c8d0f2d437199570008fd5612 # v2.65.15
304304
with:
305305
tool: cargo-hack,cargo-llvm-cov
306306
- name: Run Properties Tests and Generate Coverage Report
@@ -311,7 +311,7 @@ jobs:
311311
CARGO_PROFILE_DEV_DEBUG: 1
312312
run: cargo hack llvm-cov --locked --ignore-filename-regex "(src/api/routes/docs/.*_docs\.rs$|src/repositories/.*/.*_redis\.rs$)" --lcov --output-path properties-lcov.info --test properties
313313
- name: Upload Properties Coverage to Codecov
314-
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
314+
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
315315
with:
316316
token: ${{ secrets.CODECOV_TOKEN }}
317317
name: properties-coverage
@@ -328,13 +328,13 @@ jobs:
328328
steps:
329329
# Checkout the repository
330330
- name: Harden the runner (Audit all outbound calls)
331-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
331+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
332332
with:
333333
egress-policy: audit
334334
- name: Checkout Code
335335
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
336336
- name: Set up Docker Buildx
337-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
337+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
338338
- name: Build local container
339339
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
340340
with:
@@ -344,7 +344,7 @@ jobs:
344344
file: Dockerfile.development
345345
platforms: linux/amd64
346346
- name: Scan image
347-
uses: anchore/scan-action@40a61b52209e9d50e87917c5b901783d546b12d0 # v7.2.1
347+
uses: anchore/scan-action@3c9a191a0fbab285ca6b8530b5de5a642cba332f # v7.2.2
348348
with:
349349
image: openzeppelin-relayer-dev:${{ github.sha }}
350350
fail-build: true

.github/workflows/cla.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- name: Harden the runner (Audit all outbound calls)
25-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
25+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
2626
with:
2727
egress-policy: audit
2828
- name: Checkout Private Repo for Allowlist

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,19 +35,19 @@ jobs:
3535
build-mode: none
3636
steps:
3737
- name: Harden the runner (Audit all outbound calls)
38-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
38+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
3939
with:
4040
egress-policy: audit
4141
- name: Checkout repository
4242
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4.5.4
4343

4444
# Initializes the CodeQL tools for scanning.
4545
- name: Initialize CodeQL
46-
uses: github/codeql-action/init@fe4161a26a8629af62121b670040955b330f9af2 # v3.29.5
46+
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v3.29.5
4747
with:
4848
languages: ${{ matrix.language }}
4949
build-mode: ${{ matrix.build-mode }}
5050
- name: Perform CodeQL Analysis
51-
uses: github/codeql-action/analyze@fe4161a26a8629af62121b670040955b330f9af2 # v3.29.5
51+
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v3.29.5
5252
with:
5353
category: /language:${{matrix.language}}

.github/workflows/integration-tests.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,11 @@ jobs:
1414
id-token: write # Required for OIDC authentication with AWS
1515
steps:
1616
- name: Harden the runner (Audit all outbound calls)
17-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
17+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
1818
with:
1919
egress-policy: audit
2020
- name: Checkout Code
21-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
21+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2222
- name: Set up AWS credentials via OIDC and role chaining
2323
uses: ./.github/actions/oidc
2424
with:

.github/workflows/pr-title.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Harden the runner (Audit all outbound calls)
17-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
17+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
1818
with:
1919
egress-policy: audit
2020
- uses: thehanimo/pr-title-checker@7fbfe05602bdd86f926d3fb3bccb6f3aed43bc70 # v1.4.3

.github/workflows/rc.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,10 +23,10 @@ jobs:
2323
runs-on: ubuntu-latest
2424
steps:
2525
- name: Harden the runner (Audit all outbound calls)
26-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
26+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
2727
with:
2828
egress-policy: audit
29-
- uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
29+
- uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
3030
id: gh-app-token
3131
with:
3232
app-id: ${{ vars.GH_APP_ID }}

.github/workflows/release-docker.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
SLACK_CHANNEL: '#oss-releases'
1919
steps:
2020
- name: Harden the runner (Audit all outbound calls)
21-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
21+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
2222
with:
2323
egress-policy: audit
2424
- name: Slack notification
@@ -58,7 +58,7 @@ jobs:
5858
username: ${{ vars.DOCKERHUB_USERNAME }}
5959
password: ${{ secrets.DOCKERHUB_PAT }}
6060
- name: Set Up Docker Buildx
61-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
61+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
6262
- name: Build Docker image
6363
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
6464
id: build
@@ -74,13 +74,13 @@ jobs:
7474
tags: ${{ steps.meta.outputs.tags }}
7575
labels: ${{ steps.meta.outputs.labels }}
7676
- name: Get github app token
77-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
77+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
7878
id: gh-app-token
7979
with:
8080
app-id: ${{ vars.GH_APP_ID }}
8181
private-key: ${{ secrets.GH_APP_PRIVATE_KEY }}
8282
- name: Attest
83-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0.0
83+
uses: actions/attest-build-provenance@00014ed6ed5efc5b1ab7f7f34a39eb55d41aa4f8 # v3.1.0
8484
id: attest
8585
with:
8686
subject-name: docker.io/${{ env.DOCKERHUB_IMAGE }}

.github/workflows/release-docs.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,11 +29,11 @@ jobs:
2929
TAG: ${{ inputs.tag || github.event.inputs.tag }}
3030
steps:
3131
- name: Harden the runner (Audit all outbound calls)
32-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
32+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
3333
with:
3434
egress-policy: audit
3535
- name: Get github app token
36-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
36+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
3737
id: gh-app-token
3838
with:
3939
app-id: ${{ vars.GH_APP_ID }}
@@ -81,7 +81,7 @@ jobs:
8181
echo "PR_TITLE=${PR_TITLE:-}" >> $GITHUB_OUTPUT
8282
- name: Create Pull Request for Docs
8383
if: ${{ steps.validate_tag.outputs.PR_TITLE != '' }}
84-
uses: peter-evans/create-pull-request@84ae59a2cdc2258d6fa0732dd66352dddae2a412 # v7.0.9
84+
uses: peter-evans/create-pull-request@98357b18bf14b5342f975ff684046ec3b2a07725 # v8.0.0
8585
with:
8686
token: ${{ steps.gh-app-token.outputs.token }}
8787
title: ${{ steps.validate_tag.outputs.PR_TITLE }}

.github/workflows/release-please.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,11 @@ jobs:
2626
SLACK_CHANNEL: '#oss-releases'
2727
steps:
2828
- name: Harden the runner (Audit all outbound calls)
29-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
29+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
3030
with:
3131
egress-policy: audit
3232
- name: Get github app token
33-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
33+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
3434
id: gh-app-token
3535
with:
3636
app-id: ${{ vars.GH_APP_ID }}
@@ -119,11 +119,11 @@ jobs:
119119
if: ${{ needs.release-please.outputs.release_created == 'false' && needs.release-please.outputs.pr_created == 'true' }}
120120
steps:
121121
- name: Harden the runner (Audit all outbound calls)
122-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
122+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
123123
with:
124124
egress-policy: audit
125125
- name: Get github app token
126-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
126+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
127127
id: gh-app-token
128128
with:
129129
app-id: ${{ vars.GH_APP_ID }}
@@ -158,7 +158,7 @@ jobs:
158158
fi
159159
- name: Commit cargo update
160160
if: steps.lock-file-commit.outputs.cargo_changed == 'true'
161-
uses: iarekylew00t/verified-bot-commit@9bc80191f098974ecf436b05a5cd854525281a49 # v2.0.7
161+
uses: iarekylew00t/verified-bot-commit@d7e8eea1f154881e1f9d70a3fd933e740148b7f4 # v2.1.1
162162
with:
163163
message: 'chore: Updating lock file'
164164
token: ${{ steps.gh-app-token.outputs.token }}
@@ -174,11 +174,11 @@ jobs:
174174
runs-on: ubuntu-latest
175175
steps:
176176
- name: Harden the runner (Audit all outbound calls)
177-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
177+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
178178
with:
179179
egress-policy: audit
180180
- name: Get github app token
181-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
181+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
182182
id: gh-app-token
183183
with:
184184
app-id: ${{ vars.GH_APP_ID }}
@@ -214,7 +214,7 @@ jobs:
214214
fi
215215
- name: Commit openapi spec file
216216
if: steps.update-openapi-spec-commit.outputs.openapi_changed == 'true'
217-
uses: iarekylew00t/verified-bot-commit@9bc80191f098974ecf436b05a5cd854525281a49 # v2.0.7
217+
uses: iarekylew00t/verified-bot-commit@d7e8eea1f154881e1f9d70a3fd933e740148b7f4 # v2.1.1
218218
with:
219219
message: 'chore: Updating openapi spec file and bumping version'
220220
token: ${{ steps.gh-app-token.outputs.token }}

.github/workflows/release-sbom.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ jobs:
1717
SLACK_CHANNEL: '#oss-releases'
1818
steps:
1919
- name: Harden the runner (Audit all outbound calls)
20-
uses: step-security/harden-runner@df199fb7be9f65074067a9eb93f12bb4c5547cf2 # v2.13.3
20+
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
2121
with:
2222
egress-policy: audit
2323
- name: Get github app token
24-
uses: actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 # v2.2.0
24+
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
2525
id: gh-app-token
2626
with:
2727
app-id: ${{ vars.GH_APP_ID }}
@@ -40,7 +40,7 @@ jobs:
4040
message: Starting generating sbom for ${{ github.repository }} with tag ${{ inputs.tag }}......
4141
if: always()
4242
- name: Run SBOM
43-
uses: anchore/sbom-action@fbfd9c6c189226748411491745178e0c2017392d # v0.20.10
43+
uses: anchore/sbom-action@a930d0ac434e3182448fe678398ba5713717112a # v0.21.0
4444
with:
4545
upload-artifact-retention: 7
4646
upload-release-assets: false
@@ -52,7 +52,7 @@ jobs:
5252
GH_TOKEN: ${{ steps.gh-app-token.outputs.token }}
5353
run: gh release upload ${{ inputs.tag }} openzeppelin-relayer-${{ inputs.tag }}-spdx.json
5454
- name: SBOM attestation
55-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # main
55+
uses: actions/attest-build-provenance@00014ed6ed5efc5b1ab7f7f34a39eb55d41aa4f8 # main
5656
with:
5757
subject-path: ./openzeppelin-relayer-${{ inputs.tag }}-spdx.json
5858
github-token: ${{ steps.gh-app-token.outputs.token }}

0 commit comments

Comments
 (0)