Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the minor-patch group with 2 updates #129

Merged
merged 1 commit into from
Feb 16, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 16, 2024

Bumps the minor-patch group with 2 updates: github/codeql-action and super-linter/super-linter.

Updates github/codeql-action from 3.24.0 to 3.24.3

Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

Note that the only difference between v2 and v3 of the CodeQL Action is the node version they support, with v3 running on node 20 while we continue to release v2 to support running on node 16. For example 3.22.11 was the first v3 release and is functionally identical to 2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.

[UNRELEASED]

No user facing changes.

3.24.3 - 15 Feb 2024

  • Fix an issue where the CodeQL Action would fail to load a configuration specified by the config input to the init Action. #2147

3.24.2 - 15 Feb 2024

  • Enable improved multi-threaded performance on larger runners for GitHub Enterprise Server users. This feature is already available to github.com users. #2141

3.24.1 - 13 Feb 2024

  • Update default CodeQL bundle version to 2.16.2. #2124
  • The CodeQL action no longer fails if it can't write to the telemetry api endpoint. #2121

3.24.0 - 02 Feb 2024

  • CodeQL Python analysis will no longer install dependencies on GitHub Enterprise Server, as is already the case for github.com. See release notes for 3.23.0 for more details. #2106

3.23.2 - 26 Jan 2024

  • On Linux, the maximum possible value for the --threads option now respects the CPU count as specified in cgroup files to more accurately reflect the number of available cores when running in containers. #2083
  • Update default CodeQL bundle version to 2.16.1. #2096

3.23.1 - 17 Jan 2024

  • Update default CodeQL bundle version to 2.16.0. #2073
  • Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. #2079

3.23.0 - 08 Jan 2024

  • We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. #2031
  • The CodeQL Action now requires CodeQL version 2.11.6 or later. For more information, see the corresponding changelog entry for CodeQL Action version 2.22.7. #2009

3.22.12 - 22 Dec 2023

  • Update default CodeQL bundle version to 2.15.5. #2047

3.22.11 - 13 Dec 2023

  • [v3+ only] The CodeQL Action now runs on Node.js v20. #2006

... (truncated)

Commits
  • 3796146 Merge pull request #2148 from github/update-v3.24.3-3a7796d6a
  • 01d302a Update changelog for v3.24.3
  • 3a7796d Merge pull request #2147 from github/henrymercer/fix-config-outside-workspace...
  • 56b93f2 Add changelog note
  • 381e65f Allow generated user config file to be outside the workspace
  • d88d538 Add PR check for specifying configuration using the config input
  • dc983b3 Merge pull request #2143 from github/mergeback/v3.24.2-to-main-ece8414c
  • 66a4732 Update checked-in dependencies
  • e62fb8e Update changelog and version after v3.24.2
  • ece8414 Merge pull request #2142 from github/update-v3.24.2-1a41e5519
  • Additional commits viewable in compare view

Updates super-linter/super-linter from 6.0.0 to 6.1.1

Release notes

Sourced from super-linter/super-linter's releases.

v6.1.1

6.1.1 (2024-02-15)

🧰 Maintenance

v6.1.0

6.1.0 (2024-02-13)

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • dev-docker: bump node in /dev-dependencies (#5230) (0b5a56d)
  • docker: bump alpine/terragrunt from 1.7.1 to 1.7.2 (#5234) (31c3195)
  • docker: bump alpine/terragrunt from 1.7.2 to 1.7.3 (#5275) (d4f6d04)
  • docker: bump clj-kondo/clj-kondo (#5260) (02e9da5)
  • docker: bump dart from 3.2.5-sdk to 3.2.6-sdk (#5233) (ee53371)
  • docker: bump golang from 1.21.6-alpine to 1.22.0-alpine (#5274) (acc794f)
  • docker: bump golangci/golangci-lint from v1.55.2 to v1.56.1 (#5256) (edd813a)
  • docker: bump hashicorp/terraform from 1.7.1 to 1.7.2 (#5231) (27bb6ab)
  • docker: bump hashicorp/terraform from 1.7.2 to 1.7.3 (#5273) (e4bcc5d)
  • docker: bump mvdan/shfmt from v3.7.0 to v3.8.0 (#5257) (9b1e936)
  • docker: bump powershell from 7.3-alpine-3.17 to 7.4-alpine-3.17 (#5279) (3e6a272)
  • docker: bump python from 3.12.1-alpine3.19 to 3.12.2-alpine3.19 (#5259) (07e5032)
  • docker: bump terraform-linters/tflint from v0.50.2 to v0.50.3 (#5258) (5dc9a6a)
  • docker: bump zricethezav/gitleaks from v8.18.1 to v8.18.2 (#5232) (299dbf0)
  • npm: bump @​babel/eslint-parser in /dependencies (#5226) (3b12f82)
  • npm: bump @​typescript-eslint/eslint-plugin in /dependencies (#5268) (e54b770)

... (truncated)

Changelog

Sourced from super-linter/super-linter's changelog.

Changelog

6.1.1 (2024-02-15)

🧰 Maintenance

6.1.0 (2024-02-13)

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • dev-docker: bump node in /dev-dependencies (#5230) (0b5a56d)
  • docker: bump alpine/terragrunt from 1.7.1 to 1.7.2 (#5234) (31c3195)
  • docker: bump alpine/terragrunt from 1.7.2 to 1.7.3 (#5275) (d4f6d04)
  • docker: bump clj-kondo/clj-kondo (#5260) (02e9da5)
  • docker: bump dart from 3.2.5-sdk to 3.2.6-sdk (#5233) (ee53371)
  • docker: bump golang from 1.21.6-alpine to 1.22.0-alpine (#5274) (acc794f)
  • docker: bump golangci/golangci-lint from v1.55.2 to v1.56.1 (#5256) (edd813a)
  • docker: bump hashicorp/terraform from 1.7.1 to 1.7.2 (#5231) (27bb6ab)
  • docker: bump hashicorp/terraform from 1.7.2 to 1.7.3 (#5273) (e4bcc5d)
  • docker: bump mvdan/shfmt from v3.7.0 to v3.8.0 (#5257) (9b1e936)
  • docker: bump powershell from 7.3-alpine-3.17 to 7.4-alpine-3.17 (#5279) (3e6a272)
  • docker: bump python from 3.12.1-alpine3.19 to 3.12.2-alpine3.19 (#5259) (07e5032)
  • docker: bump terraform-linters/tflint from v0.50.2 to v0.50.3 (#5258) (5dc9a6a)
  • docker: bump zricethezav/gitleaks from v8.18.1 to v8.18.2 (#5232) (299dbf0)
  • npm: bump @​babel/eslint-parser in /dependencies (#5226) (3b12f82)
  • npm: bump @​typescript-eslint/eslint-plugin in /dependencies (#5268) (e54b770)

... (truncated)

Commits
  • f5150a3 chore(main): release 6.1.1 (#5285)
  • 5451412 ci: configure git user and email (#5284)
  • e85bf75 chore(main): release 6.1.0 (#5209)
  • e4bcc5d deps(docker): bump hashicorp/terraform from 1.7.2 to 1.7.3 (#5273)
  • 4361db8 deps(npm): bump renovate from 37.183.2 to 37.186.1 in /dependencies (#5276)
  • d4f6d04 deps(docker): bump alpine/terragrunt from 1.7.2 to 1.7.3 (#5275)
  • acc794f deps(docker): bump golang from 1.21.6-alpine to 1.22.0-alpine (#5274)
  • 11860a0 deps(python): bump black from 24.1.1 to 24.2.0 in /dependencies/python (#5280)
  • 3e6a272 deps(docker): bump powershell from 7.3-alpine-3.17 to 7.4-alpine-3.17 (#5279)
  • 7a6ab11 ci: take package-lock into account in devcontainer (#5278)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-patch group with 2 updates: [github/codeql-action](https://github.com/github/codeql-action) and [super-linter/super-linter](https://github.com/super-linter/super-linter).


Updates `github/codeql-action` from 3.24.0 to 3.24.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e8893c5...3796146)

Updates `super-linter/super-linter` from 6.0.0 to 6.1.1
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@ff5037c...f5150a3)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: super-linter/super-linter
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner February 16, 2024 03:10
@bdehamer bdehamer merged commit d935b99 into main Feb 16, 2024
22 checks passed
@bdehamer bdehamer deleted the dependabot/github_actions/minor-patch-15e249218d branch February 16, 2024 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant