Skip to content

Commit 8bd67a9

Browse files
ci(deps): bump the all-github-actions group across 1 directory with 21 updates (#5227)
Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 70355cb commit 8bd67a9

File tree

11 files changed

+59
-59
lines changed

11 files changed

+59
-59
lines changed

.github/workflows/build-push-image.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
id-token: write # for Cosign to be able to sign images with GHA token
3434
steps:
3535
- name: Checkout
36-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
36+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3737
with:
3838
ref: ${{ inputs.ref }}
3939
- name: Unshallow
@@ -45,7 +45,7 @@ jobs:
4545
run: |
4646
echo "LDFLAGS=$(make echo-ldflags)" >> $GITHUB_ENV
4747
echo "FLUX_VERSION=$(make echo-flux-version)" >> $GITHUB_ENV
48-
- uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
48+
- uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f # v5.8.0
4949
id: meta
5050
with:
5151
images: ${{ inputs.image }}
@@ -55,7 +55,7 @@ jobs:
5555
if: ${{ inputs.platforms != '' }}
5656
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
5757
- uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
58-
- uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
58+
- uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
5959
with:
6060
registry: ghcr.io
6161
username: ${{ github.actor }}
@@ -77,7 +77,7 @@ jobs:
7777
cache-to: type=gha,mode=max
7878
- name: Install cosign
7979
if: ${{ inputs.push }}
80-
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9.1
80+
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
8181
- name: Keyless signing of image
8282
if: ${{ inputs.push }}
8383
run: |

.github/workflows/docs.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,11 +28,11 @@ jobs:
2828
run:
2929
working-directory: website
3030
steps:
31-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
31+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3232
- name: Setup Pages
3333
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0
3434
- name: Setup Node.js
35-
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
35+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
3636
with:
3737
node-version-file: website/package.json
3838
- name: Build docs
@@ -47,7 +47,7 @@ jobs:
4747
touch build/.nojekyll
4848
4949
- name: Upload artifact
50-
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
50+
uses: actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b # v4.0.0
5151
with:
5252
name: github-pages
5353
path: website/build

.github/workflows/lint-pr.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,12 @@ jobs:
1515
name: Validate PR title
1616
runs-on: ubuntu-latest
1717
steps:
18-
- uses: amannn/action-semantic-pull-request@0723387faaf9b38adef4775cd42cfd5155ed6017 # v5.5.3
18+
- uses: amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # v6.1.1
1919
id: lint_pr_title
2020
env:
2121
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2222

23-
- uses: marocchino/sticky-pull-request-comment@d2ad0de260ae8b0235ce059e63f2949ba9e05943 # v2.9.3
23+
- uses: marocchino/sticky-pull-request-comment@773744901bac0e8cbb5a0dc842800d45e9b2b405 # v2.9.4
2424
# When the previous steps fail, the workflow would stop. By adding this
2525
# condition you can continue the execution with the populated error message.
2626
if: always() && (steps.lint_pr_title.outputs.error_message != null)
@@ -44,7 +44,7 @@ jobs:
4444
4545
# Delete a previous comment when the issue has been resolved
4646
- if: ${{ steps.lint_pr_title.outputs.error_message == null }}
47-
uses: marocchino/sticky-pull-request-comment@d2ad0de260ae8b0235ce059e63f2949ba9e05943 # v2.9.3
47+
uses: marocchino/sticky-pull-request-comment@773744901bac0e8cbb5a0dc842800d45e9b2b405 # v2.9.4
4848
with:
4949
header: pr-title-lint-error
5050
delete: true

.github/workflows/nightly.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ jobs:
3636
contents: read
3737

3838
steps:
39-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
39+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4040
- name : Set URL environment Variable
4141
run: |
4242
echo "URL=http://localhost:8000" >> $GITHUB_ENV
@@ -46,14 +46,14 @@ jobs:
4646
echo ${{ env.URL }}
4747
4848
- name: Set up Python
49-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
49+
uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0
5050
with:
5151
python-version: "3.12"
5252
cache: "pip"
5353
- run: pip install -r requirements.txt
5454

5555
- name: Setup Flux CLI
56-
uses: fluxcd/flux2/action@bda4c8187e436462be0d072e728b67afa215c593 # v2.6.3
56+
uses: fluxcd/flux2/action@f251e8e8a9b289283be055d65ae4a4ee595f7a14 # v2.7.0
5757

5858
- name: Install kubectl
5959
run: |
@@ -138,7 +138,7 @@ jobs:
138138
retention-days: 3
139139

140140
- name: Download test artifacts
141-
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
141+
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
142142
if: success() || failure()
143143
with:
144144
name: playwright-tests-report
@@ -158,7 +158,7 @@ jobs:
158158

159159
- name: Notify Slack
160160
id: slack
161-
uses: slackapi/slack-github-action@b0fa283ad8fea605de13dc3f449259339835fc52 # v2.1.0
161+
uses: slackapi/slack-github-action@91efab103c0de0a537f72a35f6b8cda0ee76bf0a # v2.1.1
162162
with:
163163
channel-id: C058RPVS5DZ
164164
payload: |

.github/workflows/ossf.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,12 +22,12 @@ jobs:
2222

2323
steps:
2424
- name: "Checkout code"
25-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
25+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2626
with:
2727
persist-credentials: false
2828

2929
- name: "Run analysis"
30-
uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
30+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
3131
with:
3232
results_file: results.sarif
3333
results_format: sarif
@@ -44,6 +44,6 @@ jobs:
4444

4545
# required for Code scanning alerts
4646
- name: "Upload SARIF results to code scanning"
47-
uses: github/codeql-action/upload-sarif@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
47+
uses: github/codeql-action/upload-sarif@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6
4848
with:
4949
sarif_file: results.sarif

.github/workflows/pr.yaml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,9 @@ jobs:
2020
name: CI Test JS
2121
runs-on: ubuntu-latest
2222
steps:
23-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
23+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2424
- name: Setup Node.js
25-
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
25+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2626
with:
2727
node-version-file: package.json
2828
cache: yarn
@@ -43,22 +43,22 @@ jobs:
4343
name: CI Test Go
4444
runs-on: ubuntu-latest
4545
steps:
46-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
46+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4747
- name: Setup Go
48-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
48+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
4949
with:
5050
go-version-file: go.mod
5151
- name: Setup Flux CLI
52-
uses: fluxcd/flux2/action@bda4c8187e436462be0d072e728b67afa215c593 # v2.6.3
52+
uses: fluxcd/flux2/action@f251e8e8a9b289283be055d65ae4a4ee595f7a14 # v2.7.0
5353
- run: make unit-tests
5454

5555
ci-static:
5656
name: CI Check Static Checks
5757
runs-on: ubuntu-latest
5858
steps:
59-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
59+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
6060
- name: Setup Go
61-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
61+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
6262
with:
6363
go-version-file: go.mod
6464
- run: make check-format
@@ -103,9 +103,9 @@ jobs:
103103
if: ${{ github.event_name != 'pull_request' && github.repository == 'weaveworks/weave-gitops' }}
104104
steps:
105105
- name: Checkout code
106-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
106+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
107107
- name: Setup Go
108-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
108+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
109109
with:
110110
go-version-file: go.mod
111111
- name: Clean
@@ -135,7 +135,7 @@ jobs:
135135
js-version: ${{ steps.package-version.outputs.js-version }}
136136
steps:
137137
- name: Checkout
138-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
138+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
139139
with:
140140
# avoid the merge commit that on.pull_request creates
141141
# fallback to github.sha if not present (e.g. on.push(main))
@@ -144,7 +144,7 @@ jobs:
144144
ref: ${{ github.event.pull_request.head.sha || github.sha }}
145145
fetch-depth: 0
146146
- name: Setup Node.js
147-
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
147+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
148148
with:
149149
node-version-file: package.json
150150
registry-url: "https://npm.pkg.github.com"

.github/workflows/prepare-release.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,16 +19,16 @@ jobs:
1919
runs-on: ubuntu-latest
2020
steps:
2121
- name: Checkout
22-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
22+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2323
- name: Unshallow
2424
run: |
2525
git fetch --prune --unshallow
2626
- name: Setup Go
27-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
27+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
2828
with:
2929
go-version-file: go.mod
3030
- name: Setup Node.js
31-
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
31+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
3232
with:
3333
node-version-file: package.json
3434
- name: Set up environment vars
@@ -83,7 +83,7 @@ jobs:
8383

8484
- name: Build Changelog
8585
id: github_release
86-
uses: mikepenz/release-changelog-builder-action@5fb6e51e44d4aea73f66549f425aa3ed5008109e # v5.3.1
86+
uses: mikepenz/release-changelog-builder-action@c9dc8369bccbc41e0ac887f8fd674f5925d315f7 # v5.4.1
8787
with:
8888
configuration: "${{ github.workspace }}/.github/changelog/changelog_configuration.json"
8989
ignorePreReleases: true

.github/workflows/release-please.yaml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
steps:
2727
- name: Release Please
2828
id: release-please
29-
uses: googleapis/release-please-action@a02a34c4d625f9be7cb89156071d8567266a2445 # v4.2.0
29+
uses: googleapis/release-please-action@c2a5a2bd6a758a0937f1ddb1e8950609867ed15c # v4.3.0
3030
with:
3131
token: ${{ secrets.WEAVE_GITOPS_BOT_ACCESS_TOKEN }}
3232

@@ -36,7 +36,7 @@ jobs:
3636
if: "${{ needs.release-please.outputs.release_created }}"
3737
steps:
3838
- name: Checkout
39-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
39+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4040

4141
- name: Validate chart version synchronization
4242
run: |
@@ -79,9 +79,9 @@ jobs:
7979
if: "${{ needs.release-please.outputs.release_created }}"
8080
steps:
8181
- name: Checkout
82-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
82+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
8383
- name: Setup Node.js
84-
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
84+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
8585
with:
8686
node-version-file: package.json
8787
registry-url: "https://npm.pkg.github.com"
@@ -120,7 +120,7 @@ jobs:
120120
if: "${{ needs.release-please.outputs.release_created }}"
121121
steps:
122122
- name: Checkout
123-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
123+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
124124

125125
- name: Validate chart before packaging
126126
run: |
@@ -141,7 +141,7 @@ jobs:
141141
ls -la helm-release/
142142
143143
- name: Log in to the Container registry
144-
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
144+
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
145145
with:
146146
registry: ghcr.io
147147
username: ${{ github.actor }}
@@ -172,7 +172,7 @@ jobs:
172172
cat helm-release/push-metadata.txt
173173
174174
- name: Install cosign
175-
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9.1
175+
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
176176

177177
- name: Keyless signing of chart
178178
run: |
@@ -193,20 +193,20 @@ jobs:
193193
if: "${{ needs.release-please.outputs.release_created }}"
194194
steps:
195195
- name: Checkout
196-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
196+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
197197
with:
198198
fetch-depth: 0
199199
- name: Setup Go
200-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
200+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
201201
with:
202202
go-version-file: go.mod
203203
- name: Include brew publishing
204204
run: cat .goreleaser.brew.yml >> .goreleaser.yml
205205
if: ${{ !contains(needs.release-please.outputs.version, '-') }}
206206
- name: Install cosign
207-
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9.1
207+
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
208208
- name: Run GoReleaser
209-
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6.3.0
209+
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
210210
with:
211211
version: latest
212212
args: release --clean

.github/workflows/scan.yaml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,9 @@ jobs:
2626
runs-on: ubuntu-latest
2727
steps:
2828
- name: Checkout
29-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
29+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
3030
- name: Setup Go
31-
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
31+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
3232
with:
3333
go-version-file: go.mod
3434
- name: Run FOSSA scan and upload build data
@@ -43,9 +43,9 @@ jobs:
4343
runs-on: ubuntu-latest
4444
steps:
4545
- name: Checkout
46-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
46+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4747
- name: Run Dependency Review
48-
uses: actions/dependency-review-action@da24556b548a50705dd671f47852072ea4c105d9 # v4.7.1
48+
uses: actions/dependency-review-action@56339e523c0409420f6c2c9a2f4292bbb3c07dd3 # v4.8.0
4949

5050
trivy:
5151
name: Trivy
@@ -54,17 +54,17 @@ jobs:
5454
security-events: write # for Trivy to write security events
5555
steps:
5656
- name: Checkout code
57-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
57+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
5858
- name: Run Trivy vulnerability scanner in repo mode
59-
uses: aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # v0.32.0
59+
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
6060
with:
6161
scan-type: fs
6262
scanners: vuln
6363
ignore-unfixed: true
6464
format: sarif
6565
output: trivy-results.sarif
6666
- name: Upload Trivy scan results to GitHub Security tab
67-
uses: github/codeql-action/upload-sarif@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
67+
uses: github/codeql-action/upload-sarif@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6
6868
with:
6969
sarif_file: trivy-results.sarif
7070

@@ -75,12 +75,12 @@ jobs:
7575
security-events: write # for codeQL to write security events
7676
steps:
7777
- name: Checkout repository
78-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
78+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
7979
- name: Initialize CodeQL
80-
uses: github/codeql-action/init@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
80+
uses: github/codeql-action/init@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6
8181
with:
8282
languages: go
8383
- name: Autobuild
84-
uses: github/codeql-action/autobuild@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
84+
uses: github/codeql-action/autobuild@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6
8585
- name: Perform CodeQL Analysis
86-
uses: github/codeql-action/analyze@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
86+
uses: github/codeql-action/analyze@64d10c13136e1c5bce3e5fbde8d4906eeaafc885 # v3.30.6

0 commit comments

Comments
 (0)