Skip to content

Commit 8df3c30

Browse files
chore(deps): update github-actions deps (open-telemetry#40900)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://redirect.github.com/actions/cache) | action | digest | `5a3ec84` -> `0400d5f` | | [actions/create-github-app-token](https://redirect.github.com/actions/create-github-app-token) | action | minor | `v2.0.6` -> `v2.1.1` | | [docker/build-push-action](https://redirect.github.com/docker/build-push-action) | action | digest | `471d1dc` -> `2634353` | | [docker/login-action](https://redirect.github.com/docker/login-action) | action | digest | `74a5d14` -> `184bdaa` | | [docker/setup-buildx-action](https://redirect.github.com/docker/setup-buildx-action) | action | digest | `b5ca514` -> `e468171` | | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | patch | `v3.29.0` -> `v3.29.9` | | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | digest | `ce28f5b` -> `df55935` | | [lycheeverse/lychee-action](https://redirect.github.com/lycheeverse/lychee-action) | action | minor | `v2.4.1` -> `v2.5.0` | | lycheeverse/lychee-action | action | digest | `74c50ae` -> `1478291` | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. --- ### Release Notes <details> <summary>actions/create-github-app-token (actions/create-github-app-token)</summary> ### [`v2.1.1`](https://redirect.github.com/actions/create-github-app-token/compare/v2.1.0...v2.1.1) [Compare Source](https://redirect.github.com/actions/create-github-app-token/compare/v2.1.0...v2.1.1) ### [`v2.1.0`](https://redirect.github.com/actions/create-github-app-token/releases/tag/v2.1.0) [Compare Source](https://redirect.github.com/actions/create-github-app-token/compare/v2.0.6...v2.1.0) ##### Features - use `node24` as runner ([#&open-telemetry#8203;267](https://redirect.github.com/actions/create-github-app-token/issues/267)) ([a1cbe0f](https://redirect.github.com/actions/create-github-app-token/commit/a1cbe0fa3c5aa6b13e7437f226536549d68ed0dd)) </details> <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v3.29.9`](https://redirect.github.com/github/codeql-action/compare/v3.29.8...v3.29.9) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.8...v3.29.9) ### [`v3.29.8`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.8) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.7...v3.29.8) ### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. #### 3.29.8 - 08 Aug 2025 - Fix an issue where the Action would autodetect unsupported languages such as HTML. [#&open-telemetry#8203;3015](https://redirect.github.com/github/codeql-action/pull/3015) See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.8/CHANGELOG.md) for more information. ### [`v3.29.7`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.7) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.6...v3.29.7) This is a re-release of v3.29.5 to mitigate an issue that was discovered with v3.29.6. ### [`v3.29.6`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.6) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.5...v3.29.6) ### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. #### 3.29.6 - 07 Aug 2025 - The `cleanup-level` input to the `analyze` Action is now deprecated. The CodeQL Action has written a limited amount of intermediate results to the database since version 2.2.5, and now automatically manages cleanup. [#&open-telemetry#8203;2999](https://redirect.github.com/github/codeql-action/pull/2999) - Update default CodeQL bundle version to 2.22.3. [#&open-telemetry#8203;3000](https://redirect.github.com/github/codeql-action/pull/3000) See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.6/CHANGELOG.md) for more information. ### [`v3.29.5`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.5) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.4...v3.29.5) ##### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. ##### 3.29.5 - 29 Jul 2025 - Update default CodeQL bundle version to 2.22.2. [#&open-telemetry#8203;2986](https://redirect.github.com/github/codeql-action/pull/2986) See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.5/CHANGELOG.md) for more information. ### [`v3.29.4`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.4) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.3...v3.29.4) ### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. #### 3.29.4 - 23 Jul 2025 No user facing changes. See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.4/CHANGELOG.md) for more information. ### [`v3.29.3`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.3) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.2...v3.29.3) ##### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. ##### 3.29.3 - 21 Jul 2025 No user facing changes. See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.3/CHANGELOG.md) for more information. ### [`v3.29.2`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.2) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.1...v3.29.2) ##### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. ##### 3.29.2 - 30 Jun 2025 - Experimental: When the `quality-queries` input for the `init` action is provided with an argument, separate `.quality.sarif` files are produced and uploaded for each language with the results of the specified queries. Do not use this in production as it is part of an internal experiment and subject to change at any time. [#&open-telemetry#8203;2935](https://redirect.github.com/github/codeql-action/pull/2935) See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.2/CHANGELOG.md) for more information. ### [`v3.29.1`](https://redirect.github.com/github/codeql-action/releases/tag/v3.29.1) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v3.29.0...v3.29.1) ##### CodeQL Action Changelog See the [releases page](https://redirect.github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. ##### 3.29.1 - 27 Jun 2025 - Fix bug in PR analysis where user-provided `include` query filter fails to exclude non-included queries. [#&open-telemetry#8203;2938](https://redirect.github.com/github/codeql-action/pull/2938) - Update default CodeQL bundle version to 2.22.1. [#&open-telemetry#8203;2950](https://redirect.github.com/github/codeql-action/pull/2950) See the full [CHANGELOG.md](https://redirect.github.com/github/codeql-action/blob/v3.29.1/CHANGELOG.md) for more information. </details> <details> <summary>lycheeverse/lychee-action (lycheeverse/lychee-action)</summary> ### [`v2.5.0`](https://redirect.github.com/lycheeverse/lychee-action/releases/tag/v2.5.0): Version 2.5.0 [Compare Source](https://redirect.github.com/lycheeverse/lychee-action/compare/v2.4.1...v2.5.0) ##### Summary Most notably with this release the deprecated `--exclude-mail` flag was removed and the behavior of the `--accept` flag was updated. Previously, status codes such as 200 OK were always accepted. Now they are only accepted by default. This means providing the argument `--accept 201` now rejects status code 200 OK. ##### What's Changed - Update lycheeVersion to v0.19.1 by [@&open-telemetry#8203;github-actions](https://redirect.github.com/github-actions)\[bot] in[https://github.com/lycheeverse/lychee-action/pull/300](https://redirect.github.com/lycheeverse/lychee-action/pull/300)0 - See the lychee changes here: https://github.com/lycheeverse/lychee/releases/tag/lychee-v0.19.1, https://github.com/lycheeverse/lychee/releases/tag/lychee-v0.19.0 **Full Changelog**: lycheeverse/lychee-action@v2...v2.5.0 </details> --- ### Configuration 📅 **Schedule**: Branch creation - "on tuesday" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/open-telemetry/opentelemetry-collector-contrib). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC42Mi4xIiwidXBkYXRlZEluVmVyIjoiNDEuNjAuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwicmVub3ZhdGVib3QiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Yang Song <[email protected]>
1 parent 285b4d6 commit 8df3c30

12 files changed

+23
-23
lines changed

.github/workflows/auto-update-jmx-component.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ jobs:
8787
git config user.name otelbot
8888
git config user.email [email protected]
8989
90-
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
90+
- uses: actions/create-github-app-token@a8d616148505b5069dccd32f177bb87d7f39123b # v2.1.1
9191
id: otelbot-token
9292
with:
9393
app-id: ${{ vars.OTELBOT_APP_ID }}
@@ -205,7 +205,7 @@ jobs:
205205
git config user.name otelbot
206206
git config user.email [email protected]
207207
208-
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
208+
- uses: actions/create-github-app-token@a8d616148505b5069dccd32f177bb87d7f39123b # v2.1.1
209209
id: otelbot-token
210210
with:
211211
app-id: ${{ vars.OTELBOT_APP_ID }}

.github/workflows/build-and-test.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -246,7 +246,7 @@ jobs:
246246
if: steps.go-setup.outputs.cache-hit != 'true'
247247
run: make install-tools
248248
- name: Cache Test Build
249-
uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4
249+
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4
250250
with:
251251
path: ~/.cache/go-build
252252
key: go-test-build-${{ runner.os }}-${{ matrix.go-version }}-${{ matrix.runner }}-${{ hashFiles('**/go.sum') }}
@@ -575,7 +575,7 @@ jobs:
575575
docker run otel/opentelemetry-collector-contrib-dev:$GITHUB_SHA --version
576576
docker run otel/opentelemetry-collector-contrib-dev:latest --version
577577
- name: Login to Docker Hub
578-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
578+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3
579579
with:
580580
username: ${{ secrets.DOCKER_USERNAME }}
581581
password: ${{ secrets.DOCKER_PASSWORD }}

.github/workflows/changelog.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ jobs:
7878
- name: Link Checker
7979
if: ${{ !contains(github.event.pull_request.labels.*.name, 'dependencies') && !contains(github.event.pull_request.labels.*.name, 'Skip Changelog') && !contains(github.event.pull_request.title, '[chore]')}}
8080
id: lychee
81-
uses: lycheeverse/lychee-action@74c50ae9cb26a12ef66ad5769546fe0848ae9596 # f613c4a64e50d792e0b31ec34bbcbba12263c6a6
81+
uses: lycheeverse/lychee-action@147829136ad8e72b5a1e57d782626a0ebd8d1d16 # f613c4a64e50d792e0b31ec34bbcbba12263c6a6
8282
with:
8383
args: "--verbose --no-progress ./changelog_preview.md --config .github/lychee.toml"
8484
failIfEmpty: false

.github/workflows/check-links.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646

4747
- name: Link Checker
4848
id: lychee
49-
uses: lycheeverse/lychee-action@82202e5e9c2f4ef1a55a3d02563e1cb6041e5332 # v2.4.1
49+
uses: lycheeverse/lychee-action@5c4ee84814c983aa7164eaee476f014e53ff3963 # v2.5.0
5050
with:
5151
args: "--verbose --no-progress ${{needs.changedfiles.outputs.files}} --config .github/lychee.toml"
5252
failIfEmpty: false

.github/workflows/check-lychee-config.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
- name: Lychee Config Checker
2222
id: lychee
23-
uses: lycheeverse/lychee-action@82202e5e9c2f4ef1a55a3d02563e1cb6041e5332 # v2.4.1
23+
uses: lycheeverse/lychee-action@5c4ee84814c983aa7164eaee476f014e53ff3963 # v2.5.0
2424
with:
2525
args: "--verbose --config .github/lychee.toml --dump .github/lychee.toml"
2626
failIfEmpty: false

.github/workflows/codeql-analysis.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232

3333
# Initializes the CodeQL tools for scanning.
3434
- name: Initialize CodeQL
35-
uses: github/codeql-action/init@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3
35+
uses: github/codeql-action/init@df559355d593797519d70b90fc8edd5db049e7a2 # v3
3636
with:
3737
languages: go
3838

@@ -42,5 +42,5 @@ jobs:
4242
make otelcontribcol
4343
4444
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3
45+
uses: github/codeql-action/analyze@df559355d593797519d70b90fc8edd5db049e7a2 # v3
4646
timeout-minutes: 60

.github/workflows/golden.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ jobs:
3939
- name: Set up QEMU
4040
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
4141
- name: Set up Docker Buildx
42-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
42+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
4343
- name: Build binaries
4444
run: |
4545
GOOS=linux GOARCH=ppc64le make golden
@@ -48,7 +48,7 @@ jobs:
4848
GOOS=linux GOARCH=s390x make golden
4949
cp bin/golden_* cmd/golden/
5050
- name: Build golden
51-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6
51+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
5252
with:
5353
context: cmd/golden
5454
push: false
@@ -73,9 +73,9 @@ jobs:
7373
- name: Set up QEMU
7474
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
7575
- name: Set up Docker Buildx
76-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
76+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
7777
- name: Login to GitHub Container Registry
78-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
78+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3
7979
with:
8080
registry: ghcr.io
8181
username: ${{ github.repository_owner }}
@@ -88,7 +88,7 @@ jobs:
8888
GOOS=linux GOARCH=s390x make golden
8989
cp bin/golden_* cmd/golden/
9090
- name: Push golden to Github packages
91-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6
91+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
9292
with:
9393
context: cmd/golden
9494
push: true
@@ -113,12 +113,12 @@ jobs:
113113
- name: Set up QEMU
114114
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
115115
- name: Set up Docker Buildx
116-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
116+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
117117
- name: Set Release Tag
118118
id: github_tag
119119
run: ./.github/workflows/scripts/set_release_tag.sh
120120
- name: Login to GitHub Container Registry
121-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
121+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3
122122
with:
123123
registry: ghcr.io
124124
username: ${{ github.repository_owner }}
@@ -131,7 +131,7 @@ jobs:
131131
GOOS=linux GOARCH=s390x make golden
132132
cp bin/golden_* cmd/golden/
133133
- name: Push golden to Github packages
134-
uses: docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6
134+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
135135
with:
136136
context: cmd/golden
137137
push: true

.github/workflows/prepare-release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
with:
3333
go-version: oldstable
3434
cache: false
35-
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
35+
- uses: actions/create-github-app-token@a8d616148505b5069dccd32f177bb87d7f39123b # v2.1.1
3636
id: otelbot-token
3737
with:
3838
app-id: ${{ vars.OTELBOT_APP_ID }}

.github/workflows/scorecard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,6 @@ jobs:
6565

6666
# Upload the results to GitHub's code scanning dashboard.
6767
- name: "Upload to code-scanning"
68-
uses: github/codeql-action/upload-sarif@ce28f5bb42b7a9f2c824e633a3f6ee835bab6858 # v3.29.0
68+
uses: github/codeql-action/upload-sarif@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9
6969
with:
7070
sarif_file: results.sarif

.github/workflows/telemetrygen.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ jobs:
8282
- name: Set up Docker Buildx
8383
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
8484
- name: Login to GitHub Container Registry
85-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
85+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3
8686
with:
8787
registry: ghcr.io
8888
username: ${{ github.repository_owner }}
@@ -129,7 +129,7 @@ jobs:
129129
id: github_tag
130130
run: ./.github/workflows/scripts/set_release_tag.sh
131131
- name: Login to GitHub Container Registry
132-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
132+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3
133133
with:
134134
registry: ghcr.io
135135
username: ${{ github.repository_owner }}

0 commit comments

Comments
 (0)