Skip to content

Commit 097ace4

Browse files
ci(deps): bump the github-actions group across 1 directory with 8 updates (#42)
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent d318804 commit 097ace4

File tree

5 files changed

+48
-48
lines changed

5 files changed

+48
-48
lines changed

.github/workflows/ci.yml

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -36,12 +36,12 @@ jobs:
3636
code: ${{ steps.filter.outputs.code }}
3737
steps:
3838
- name: Harden the runner (Audit all outbound calls)
39-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
39+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
4040
with:
4141
egress-policy: audit
4242

4343
- name: Checkout code
44-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
44+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4545

4646
- name: Check for code changes
4747
id: filter
@@ -65,12 +65,12 @@ jobs:
6565
contents: read
6666
steps:
6767
- name: Harden the runner (Audit all outbound calls)
68-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
68+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
6969
with:
7070
egress-policy: audit
7171

7272
- name: Checkout code
73-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
73+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
7474

7575
- name: Install Rust nightly toolchain
7676
uses: dtolnay/rust-toolchain@0b1efabc08b657293548b77fb76cc02d26091c7e # master
@@ -93,12 +93,12 @@ jobs:
9393
RUSTFLAGS: "-C codegen-units=16 -C link-arg=-fuse-ld=mold"
9494
steps:
9595
- name: Harden the runner (Audit all outbound calls)
96-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
96+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
9797
with:
9898
egress-policy: audit
9999

100100
- name: Checkout code
101-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
101+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
102102

103103
- name: Install Rust toolchain
104104
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -141,12 +141,12 @@ jobs:
141141
RUSTFLAGS: "-C codegen-units=16 -C link-arg=-fuse-ld=mold"
142142
steps:
143143
- name: Harden the runner (Audit all outbound calls)
144-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
144+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
145145
with:
146146
egress-policy: audit
147147

148148
- name: Checkout code
149-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
149+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
150150

151151
- name: Install Rust toolchain
152152
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -197,12 +197,12 @@ jobs:
197197
RUSTFLAGS: "-C codegen-units=16 -C link-arg=-fuse-ld=mold"
198198
steps:
199199
- name: Harden the runner (Audit all outbound calls)
200-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
200+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
201201
with:
202202
egress-policy: audit
203203

204204
- name: Checkout code
205-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
205+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
206206

207207
- name: Install Rust toolchain
208208
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -265,12 +265,12 @@ jobs:
265265
RUSTFLAGS: "-C codegen-units=16 -C link-arg=-fuse-ld=mold"
266266
steps:
267267
- name: Harden the runner (Audit all outbound calls)
268-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
268+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
269269
with:
270270
egress-policy: audit
271271

272272
- name: Checkout code
273-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
273+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
274274

275275
- name: Install Rust toolchain
276276
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -343,12 +343,12 @@ jobs:
343343
RUSTFLAGS: "-C codegen-units=16 -C link-arg=-fuse-ld=mold"
344344
steps:
345345
- name: Harden the runner (Audit all outbound calls)
346-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
346+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
347347
with:
348348
egress-policy: audit
349349

350350
- name: Checkout code
351-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
351+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
352352

353353
- name: Install Rust toolchain
354354
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -392,12 +392,12 @@ jobs:
392392
contents: read
393393
steps:
394394
- name: Harden the runner (Audit all outbound calls)
395-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
395+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
396396
with:
397397
egress-policy: audit
398398

399399
- name: Checkout code
400-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
400+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
401401

402402
- name: Install Rust toolchain (stable + nightly for udeps)
403403
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # v1
@@ -437,7 +437,7 @@ jobs:
437437
if: always()
438438
steps:
439439
- name: Harden the runner (Audit all outbound calls)
440-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
440+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
441441
with:
442442
egress-policy: audit
443443

.github/workflows/codeql.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,12 @@ jobs:
3030
actions: ${{ steps.filter.outputs.actions }}
3131
steps:
3232
- name: Harden the runner (Audit all outbound calls)
33-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
33+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
3434
with:
3535
egress-policy: audit
3636

3737
- name: Checkout code
38-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
38+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3939

4040
- name: Check for changes
4141
id: filter
@@ -60,20 +60,20 @@ jobs:
6060

6161
steps:
6262
- name: Harden the runner (Audit all outbound calls)
63-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
63+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
6464
with:
6565
egress-policy: audit
6666

6767
- name: Checkout code
68-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
68+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
6969

7070
- name: Initialize CodeQL
71-
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
71+
uses: github/codeql-action/init@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
7272
with:
7373
languages: rust
7474

7575
- name: Perform CodeQL Analysis
76-
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
76+
uses: github/codeql-action/analyze@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
7777
with:
7878
category: "/language:rust"
7979

@@ -88,19 +88,19 @@ jobs:
8888

8989
steps:
9090
- name: Harden the runner (Audit all outbound calls)
91-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
91+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
9292
with:
9393
egress-policy: audit
9494

9595
- name: Checkout code
96-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
96+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
9797

9898
- name: Initialize CodeQL
99-
uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
99+
uses: github/codeql-action/init@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
100100
with:
101101
languages: actions
102102

103103
- name: Perform CodeQL Analysis
104-
uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
104+
uses: github/codeql-action/analyze@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
105105
with:
106106
category: "/language:actions"

.github/workflows/container.yml

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -52,12 +52,12 @@ jobs:
5252
version: ${{ steps.meta.outputs.version }}
5353
steps:
5454
- name: Harden the runner (Audit all outbound calls)
55-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
55+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
5656
with:
5757
egress-policy: audit
5858

5959
- name: Checkout code
60-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
60+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
6161

6262
- name: Set up Docker Buildx
6363
uses: step-security/setup-buildx-action@8c8aef2d414c0b66518fee2b7084e0986f82d7ac # v3.11.1
@@ -72,7 +72,7 @@ jobs:
7272

7373
- name: Extract metadata
7474
id: meta
75-
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
75+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
7676
with:
7777
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
7878
tags: |
@@ -109,7 +109,7 @@ jobs:
109109
110110
- name: Upload digest
111111
if: github.event_name != 'pull_request'
112-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
112+
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
113113
with:
114114
name: digests-${{ matrix.suffix }}
115115
path: /tmp/digests/*
@@ -124,12 +124,12 @@ jobs:
124124
if: github.event_name != 'pull_request'
125125
steps:
126126
- name: Harden the runner (Audit all outbound calls)
127-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
127+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
128128
with:
129129
egress-policy: audit
130130

131131
- name: Download digests
132-
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
132+
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
133133
with:
134134
path: /tmp/digests
135135
pattern: digests-*
@@ -147,7 +147,7 @@ jobs:
147147

148148
- name: Extract metadata
149149
id: meta
150-
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
150+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
151151
with:
152152
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
153153
tags: |
@@ -182,7 +182,7 @@ jobs:
182182
if: github.event_name != 'pull_request'
183183
steps:
184184
- name: Harden the runner (Audit all outbound calls)
185-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
185+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
186186
with:
187187
egress-policy: audit
188188

@@ -195,21 +195,21 @@ jobs:
195195

196196
- name: Extract metadata
197197
id: meta
198-
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
198+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
199199
with:
200200
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
201201
tags: |
202202
type=sha,prefix=sha-
203203
204204
- name: Generate SBOM
205-
uses: anchore/sbom-action@e11c554f704a0b820cbf8c51673f6945e0731532 # v0.20.0
205+
uses: anchore/sbom-action@62ad5284b8ced813296287a0b63906cb364b73ee # v0.22.0
206206
with:
207207
image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }}
208208
artifact-name: sbom.spdx.json
209209
output-file: sbom.spdx.json
210210

211211
- name: Upload SBOM
212-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
212+
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
213213
with:
214214
name: sbom
215215
path: sbom.spdx.json
@@ -223,7 +223,7 @@ jobs:
223223
if: github.event_name != 'pull_request'
224224
steps:
225225
- name: Harden the runner (Audit all outbound calls)
226-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
226+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
227227
with:
228228
egress-policy: audit
229229

@@ -236,21 +236,21 @@ jobs:
236236

237237
- name: Extract metadata
238238
id: meta
239-
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
239+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
240240
with:
241241
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
242242
tags: |
243243
type=sha,prefix=sha-
244244
245245
- name: Run Trivy vulnerability scanner
246-
uses: aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31.0
246+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # 0.33.1
247247
with:
248248
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }}
249249
format: "sarif"
250250
output: "trivy-results.sarif"
251251
severity: "CRITICAL,HIGH"
252252

253253
- name: Upload Trivy scan results
254-
uses: github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
254+
uses: github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
255255
with:
256256
sarif_file: "trivy-results.sarif"

.github/workflows/labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-latest
2121
steps:
2222
- name: Harden the runner (Audit all outbound calls)
23-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
23+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
2424
with:
2525
egress-policy: audit
2626

.github/workflows/security.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,12 +26,12 @@ jobs:
2626
cargo: ${{ steps.filter.outputs.cargo }}
2727
steps:
2828
- name: Harden the runner (Audit all outbound calls)
29-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
29+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
3030
with:
3131
egress-policy: audit
3232

3333
- name: Checkout code
34-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
34+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3535

3636
- name: Check for dependency changes
3737
uses: step-security/paths-filter@6eee183b0d2fd101d3f8ee2935c127bca14c5625 # v3.0.5
@@ -55,12 +55,12 @@ jobs:
5555
pull-requests: write
5656
steps:
5757
- name: Harden the runner (Audit all outbound calls)
58-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
58+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
5959
with:
6060
egress-policy: audit
6161

6262
- name: Checkout code
63-
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
63+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
6464

6565
- name: Dependency Review
6666
uses: actions/dependency-review-action@3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 # v4.8.2
@@ -79,7 +79,7 @@ jobs:
7979
contents: read
8080
steps:
8181
- name: Harden the runner (Audit all outbound calls)
82-
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
82+
uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1
8383
with:
8484
egress-policy: audit
8585

0 commit comments

Comments
 (0)