diff --git a/.github/workflows/CodeQL-Analysis.yml b/.github/workflows/CodeQL-Analysis.yml index 93e7f2a5..65bbf396 100644 --- a/.github/workflows/CodeQL-Analysis.yml +++ b/.github/workflows/CodeQL-Analysis.yml @@ -23,7 +23,7 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Initialize CodeQL - uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3 + uses: github/codeql-action/init@755f44910c12a3d7ca0d8c6e42c048b3362f7cec # v3.30.8 with: languages: swift queries: security-and-quality @@ -33,6 +33,6 @@ jobs: run: swift build - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3 + uses: github/codeql-action/analyze@755f44910c12a3d7ca0d8c6e42c048b3362f7cec # v3.30.8 with: category: "/language:swift" diff --git a/.github/workflows/Create-Release-PR.yml b/.github/workflows/Create-Release-PR.yml index 4e9d8f04..2ae38baf 100644 --- a/.github/workflows/Create-Release-PR.yml +++ b/.github/workflows/Create-Release-PR.yml @@ -26,7 +26,7 @@ jobs: sed -i -e 's/spec.version = ".*"/spec.version = "${{ inputs.new_version }}"/' OpenTelemetry-Swift-SdkResourceExtension.podspec sed -i -e 's/spec.version = ".*"/spec.version = "${{ inputs.new_version }}"/' OpenTelemetry-Swift-PersistenceExporter.podspec - - uses: actions/create-github-app-token@a8d616148505b5069dccd32f177bb87d7f39123b # v2.1.1 + - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 id: otelbot-token with: app-id: ${{ vars.OTELBOT_APP_ID }} diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index fbaf5c8d..db302828 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -23,7 +23,7 @@ jobs: with: persist-credentials: false - - uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2 + - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 with: results_file: results.sarif results_format: sarif @@ -42,6 +42,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3 + uses: github/codeql-action/upload-sarif@755f44910c12a3d7ca0d8c6e42c048b3362f7cec # v3.30.8 with: sarif_file: results.sarif diff --git a/.github/workflows/update-core-dependencies.yml b/.github/workflows/update-core-dependencies.yml index 0866e7c3..cc224ba9 100644 --- a/.github/workflows/update-core-dependencies.yml +++ b/.github/workflows/update-core-dependencies.yml @@ -45,7 +45,7 @@ jobs: echo "has_changes=false" >> $GITHUB_OUTPUT fi - - uses: actions/create-github-app-token@a8d616148505b5069dccd32f177bb87d7f39123b # v2.1.1 + - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 id: otelbot-token with: app-id: ${{ vars.OTELBOT_APP_ID }} diff --git a/Package.swift b/Package.swift index 0ad9995c..7ece5805 100644 --- a/Package.swift +++ b/Package.swift @@ -30,11 +30,11 @@ let package = Package( ], dependencies: [ .package(url: "https://github.com/open-telemetry/opentelemetry-swift-core.git", from: "2.2.0"), - .package(url: "https://github.com/apple/swift-nio.git", from: "2.86.0"), + .package(url: "https://github.com/apple/swift-nio.git", from: "2.86.2"), .package(url: "https://github.com/grpc/grpc-swift.git", exact: "1.26.1"), .package(url: "https://github.com/apple/swift-protobuf.git", from: "1.30.0"), .package(url: "https://github.com/apple/swift-log.git", from: "1.6.4"), - .package(url: "https://github.com/apple/swift-metrics.git", from: "2.7.0") + .package(url: "https://github.com/apple/swift-metrics.git", from: "2.7.1") ], targets: [ .target(