Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 15, 2025

This PR contains the following updates:

Package Type Update Change
Swatinem/rust-cache action minor v2.7.7 -> v2.8.2
actions/create-github-app-token action minor v2.1.1 -> v2.2.1
actions/create-github-app-token action minor v2.1.4 -> v2.2.1
actions/setup-node action minor v6.0.0 -> v6.1.0
anchore/scan-action action minor v7.0.0 -> v7.2.2
codecov/codecov-action action minor v5.4.3 -> v5.5.2
docker/setup-buildx-action action minor v3.10.0 -> v3.12.0
docker/setup-qemu-action action minor v3.6.0 -> v3.7.0
dorny/test-reporter action minor v2.1.0 -> v2.3.0
grafana/run-k6-action action minor v1.2.0 -> v1.3.1
launchdarkly/find-code-references action minor v2.13.0 -> v2.14.0
ncipollo/release-action action minor v1.16.0 -> v1.20.0
sigstore/cosign-installer action minor v3.8.2 -> v3.10.1

Release Notes

Swatinem/rust-cache (Swatinem/rust-cache)

v2.8.2

Compare Source

What's Changed
New Contributors

Full Changelog: Swatinem/rust-cache@v2.8.1...v2.8.2

v2.8.1

Compare Source

What's Changed
New Contributors

Full Changelog: Swatinem/rust-cache@v2...v2.8.1

v2.8.0

Compare Source

What's Changed
New Contributors

Full Changelog: Swatinem/rust-cache@v2.7.8...v2.8.0

v2.7.8

Compare Source

What's Changed
  • Include CPU arch in the cache key for arm64 Linux runners by @​rhysd in #​228

Full Changelog: Swatinem/rust-cache@v2.7.7...v2.7.8

actions/create-github-app-token (actions/create-github-app-token)

v2.2.1

Compare Source

Bug Fixes
  • deps: bump the production-dependencies group with 2 updates (#​311) (b212e6a)

v2.2.0

Compare Source

Bug Fixes
Features

v2.1.4

Compare Source

Bug Fixes

v2.1.3

Compare Source

Bug Fixes
  • deps: bump undici from 7.8.0 to 7.10.0 in the production-dependencies group (#​254) (f3d5ec2)

v2.1.2

Compare Source

Bug Fixes
actions/setup-node (actions/setup-node)

v6.1.0

Compare Source

What's Changed

Enhancement:
Dependency updates:
Documentation update:

Full Changelog: actions/setup-node@v6...v6.1.0

anchore/scan-action (anchore/scan-action)

v7.2.2

Compare Source

New in scan-action v7.2.2

v7.2.1

Compare Source

New in scan-action v7.2.1

v7.2.0

Compare Source

New in scan-action v7.2.0

v7.1.0

Compare Source

New in scan-action v7.1.0

v7.0.2

Compare Source

New in scan-action v7.0.2

v7.0.1

Compare Source

scan-action v7.0.1

codecov/codecov-action (codecov/codecov-action)

v5.5.2

Compare Source

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2

v5.5.1

Compare Source

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.5.0..v5.5.1

v5.5.0

Compare Source

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.4.3..v5.5.0

docker/setup-buildx-action (docker/setup-buildx-action)

v3.12.0

Compare Source

Full Changelog: docker/setup-buildx-action@v3.11.1...v3.12.0

v3.11.1

Compare Source

Full Changelog: docker/setup-buildx-action@v3.11.0...v3.11.1

v3.11.0

Compare Source

Full Changelog: docker/setup-buildx-action@v3.10.0...v3.11.0

docker/setup-qemu-action (docker/setup-qemu-action)

v3.7.0

Compare Source

Full Changelog: docker/setup-qemu-action@v3.6.0...v3.7.0

dorny/test-reporter (dorny/test-reporter)

v2.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: dorny/test-reporter@v2.2.0...v2.3.0

v2.2.0

Compare Source

v2.1.1

Compare Source

A bug fix release of the test-reporter action.

What's Changed
New Contributors

Full Changelog: dorny/test-reporter@v2.1.0...v2.1.1

grafana/run-k6-action (grafana/run-k6-action)

v1.3.1

Compare Source

What's Changed

Full Changelog: grafana/run-k6-action@v1.3.0...v1.3.1

v1.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: grafana/run-k6-action@v1...v1.3.0

launchdarkly/find-code-references (launchdarkly/find-code-references)

v2.14.0

Compare Source

Added:
  • --skipArchivedFlags option to instruct the tool to ignore any flag keys it finds from archived flags
Changed:
  • replaced the stdlib regexp with go-re2 for improved regexp compilation and pattern matching
  • now using caching to optimize file globbing and regex compilation
  • move off of legacy olekukonko/tablewriter and onto v1.x
  • updated to the latest version of the LaunchDarkly API
Fixed:
  • subdirectory option now works with projects[*].dir configuration, and produces correct "View in source" links in the LD UI
ncipollo/release-action (ncipollo/release-action)

v1.20.0

Compare Source

What's Changed

Full Changelog: ncipollo/release-action@v1...v1.20.0

v1.19.2

Compare Source

What's Changed
New Contributors

Full Changelog: ncipollo/release-action@v1...v1.19.2

v1.19.1

Compare Source

Defaults immutableCreate to false if it is omitted.

Full Changelog: ncipollo/release-action@v1.19.0...v1.19.1

v1.19.0

Compare Source

What's Changed

Full Changelog: ncipollo/release-action@v1...v1.19.0

v1.18.0

Compare Source

  • Fixes #​529 Collect asset URLs into output

Full Changelog: ncipollo/release-action@v1...v1.18.0

v1.17.0

Compare Source

What's Changed

Full Changelog: ncipollo/release-action@v1...v1.17.0

sigstore/cosign-installer (sigstore/cosign-installer)

v3.10.1

Compare Source

What's Changed?

Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.

Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.

  • Bump default Cosign to v2.6.1 (#​203)

v3.10.0

Compare Source

What's Changed

  • Bump default Cosign to v2.6.0 in #​200

Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0

v3.9.2

Compare Source

What's Changed

  • not fail fast and setup permissions in #​195
  • drop old unsupported versions <v2.0.0 in #​192
  • Update default to v2.5.3 in #​196

Full Changelog: sigstore/cosign-installer@v3.9.1...v3.9.2

v3.9.1

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.9.0...v3.9.1

v3.9.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3...v3.9.0


Configuration

📅 Schedule: Branch creation - "every 2nd week starting on the 2 week of the year before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the hold Hold this PR or item until later; DO NOT MERGE label Sep 15, 2025
@renovate renovate bot requested review from a team as code owners September 15, 2025 03:06
@renovate renovate bot requested a review from dereknance September 15, 2025 03:06
@renovate renovate bot added the hold Hold this PR or item until later; DO NOT MERGE label Sep 15, 2025
@renovate renovate bot requested a review from michalchecinski September 15, 2025 03:06
@codecov
Copy link

codecov bot commented Sep 15, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 58.58%. Comparing base (fafc61d) to head (ebe337b).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6327      +/-   ##
==========================================
+ Coverage   54.72%   58.58%   +3.85%     
==========================================
  Files        1920     1920              
  Lines       85264    85264              
  Branches     7632     7632              
==========================================
+ Hits        46664    49954    +3290     
+ Misses      36828    33464    -3364     
- Partials     1772     1846      +74     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate bot force-pushed the renovate/github-action-minor branch 3 times, most recently from 4535f0d to 37934eb Compare September 20, 2025 02:11
@renovate renovate bot force-pushed the renovate/github-action-minor branch 2 times, most recently from 48ab895 to b5bdf1b Compare September 25, 2025 11:11
@renovate renovate bot force-pushed the renovate/github-action-minor branch 4 times, most recently from f719593 to 996b958 Compare October 9, 2025 11:06
@renovate renovate bot force-pushed the renovate/github-action-minor branch 3 times, most recently from 46eb4de to 437cd9e Compare October 14, 2025 18:14
@renovate renovate bot force-pushed the renovate/github-action-minor branch 5 times, most recently from 13cd43f to 7d8531f Compare October 24, 2025 16:21
@renovate renovate bot force-pushed the renovate/github-action-minor branch 3 times, most recently from 1573f39 to ab2f084 Compare November 6, 2025 11:38
@renovate renovate bot force-pushed the renovate/github-action-minor branch 3 times, most recently from 25b1979 to ab9a2f4 Compare November 12, 2025 19:41
@renovate renovate bot force-pushed the renovate/github-action-minor branch 4 times, most recently from f55e2e6 to a9e97d9 Compare November 24, 2025 22:59
@renovate renovate bot force-pushed the renovate/github-action-minor branch 5 times, most recently from 6fec9c5 to 3735bf1 Compare December 3, 2025 11:33
@renovate renovate bot force-pushed the renovate/github-action-minor branch 3 times, most recently from 2a0dde9 to 212f2ad Compare December 13, 2025 03:55
@renovate renovate bot force-pushed the renovate/github-action-minor branch 2 times, most recently from 50da876 to 5e1a072 Compare December 15, 2025 20:49
@github-actions
Copy link
Contributor

github-actions bot commented Dec 15, 2025

Logo
Checkmarx One – Scan Summary & Details1c342b08-fba2-47fe-9315-632d2dbc1d0e

New Issues (3)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Path_Traversal /src/Api/Controllers/SelfHosted/SelfHostedOrganizationLicensesController.cs: 56
detailsMethod at line 56 of /src/Api/Controllers/SelfHosted/SelfHostedOrganizationLicensesController.cs gets dynamic data from the model element. This ...
ID: HwphbdG3YaZTdiMdREyc8GsPw%2Bw%3D
Attack Vector
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1170
detailsMethod at line 1170 of /src/Api/Vault/Controllers/CiphersController.cs gets a parameter from a user request from id. This parameter value flows ...
ID: ydwqMeYmBkmGAeG%2FbyXCmFNSIz4%3D
Attack Vector
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1060
detailsMethod at line 1060 of /src/Api/Vault/Controllers/CiphersController.cs gets a parameter from a user request from id. This parameter value flows ...
ID: NBqS3wtj%2BwcjukpYL1K2xj0Y2Fw%3D
Attack Vector
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: 208

@renovate renovate bot force-pushed the renovate/github-action-minor branch 2 times, most recently from 125d116 to e93a58a Compare December 17, 2025 05:02
@fntyler
Copy link
Contributor

fntyler commented Dec 19, 2025

Reviewing as part of BRE-1364

@fntyler
Copy link
Contributor

fntyler commented Dec 19, 2025

@michalchecinski is there any additional context around this PR?

@renovate renovate bot force-pushed the renovate/github-action-minor branch from e93a58a to 4b0a326 Compare December 19, 2025 21:10
@renovate renovate bot force-pushed the renovate/github-action-minor branch from 4b0a326 to ebe337b Compare December 23, 2025 15:44
@fntyler fntyler removed the hold Hold this PR or item until later; DO NOT MERGE label Dec 23, 2025
@fntyler fntyler enabled auto-merge (squash) December 23, 2025 21:21
@fntyler fntyler disabled auto-merge December 23, 2025 21:22
Copy link
Contributor

@dereknance dereknance left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Platform changes look good 👍🏻

@fntyler fntyler merged commit 96622d7 into main Dec 23, 2025
76 of 80 checks passed
@fntyler fntyler deleted the renovate/github-action-minor branch December 23, 2025 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants