From 8d6595f79e21e5b65694b289238c65690be5f204 Mon Sep 17 00:00:00 2001 From: Mend Renovate Date: Wed, 7 Aug 2024 07:31:41 +0200 Subject: [PATCH] chore(deps): update workflows (#1161) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/upload-artifact](https://togithub.com/actions/upload-artifact) | action | patch | `v4.3.4` -> `v4.3.5` | | [docker/setup-buildx-action](https://togithub.com/docker/setup-buildx-action) | action | digest | `aa33708` -> `988b5a0` | | [golangci/golangci-lint-action](https://togithub.com/golangci/golangci-lint-action) | action | minor | `v6.0.1` -> `v6.1.0` | | [r-lib/actions](https://togithub.com/r-lib/actions) | action | minor | `v2.9.0` -> `v2.10.0` | --- ### Release Notes
actions/upload-artifact (actions/upload-artifact) ### [`v4.3.5`](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5) [Compare Source](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5)
golangci/golangci-lint-action (golangci/golangci-lint-action) ### [`v6.1.0`](https://togithub.com/golangci/golangci-lint-action/releases/tag/v6.1.0) [Compare Source](https://togithub.com/golangci/golangci-lint-action/compare/v6.0.1...v6.1.0) #### What's Changed ##### Changes - feat: allow to skip golangci-lint installation by [@​ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1079](https://togithub.com/golangci/golangci-lint-action/pull/1079) ##### Documentation - docs: add Go workspace examples by [@​ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1064](https://togithub.com/golangci/golangci-lint-action/pull/1064) ##### Dependencies - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.8 to 20.12.11 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1041](https://togithub.com/golangci/golangci-lint-action/pull/1041) - build(deps-dev): bump [@​typescript-eslint/eslint-plugin](https://togithub.com/typescript-eslint/eslint-plugin) from 7.8.0 to 7.9.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1042](https://togithub.com/golangci/golangci-lint-action/pull/1042) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.11 to 20.12.12 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1043](https://togithub.com/golangci/golangci-lint-action/pull/1043) - build(deps-dev): bump [@​typescript-eslint/parser](https://togithub.com/typescript-eslint/parser) from 7.8.0 to 7.9.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1044](https://togithub.com/golangci/golangci-lint-action/pull/1044) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1047](https://togithub.com/golangci/golangci-lint-action/pull/1047) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.12 to 20.14.0 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1051](https://togithub.com/golangci/golangci-lint-action/pull/1051) - build(deps-dev): bump the dev-dependencies group across 1 directory with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1053](https://togithub.com/golangci/golangci-lint-action/pull/1053) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1061](https://togithub.com/golangci/golangci-lint-action/pull/1061) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.0 to 20.14.2 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1062](https://togithub.com/golangci/golangci-lint-action/pull/1062) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1063](https://togithub.com/golangci/golangci-lint-action/pull/1063) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.2 to 20.14.8 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1066](https://togithub.com/golangci/golangci-lint-action/pull/1066) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1065](https://togithub.com/golangci/golangci-lint-action/pull/1065) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1067](https://togithub.com/golangci/golangci-lint-action/pull/1067) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.8 to 20.14.9 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1068](https://togithub.com/golangci/golangci-lint-action/pull/1068) - build(deps-dev): bump the dev-dependencies group with 4 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1071](https://togithub.com/golangci/golangci-lint-action/pull/1071) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.9 to 20.14.10 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1072](https://togithub.com/golangci/golangci-lint-action/pull/1072) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1073](https://togithub.com/golangci/golangci-lint-action/pull/1073) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1074](https://togithub.com/golangci/golangci-lint-action/pull/1074) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.10 to 20.14.11 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1075](https://togithub.com/golangci/golangci-lint-action/pull/1075) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1077](https://togithub.com/golangci/golangci-lint-action/pull/1077) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.11 to 22.0.0 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1078](https://togithub.com/golangci/golangci-lint-action/pull/1078) **Full Changelog**: https://github.com/golangci/golangci-lint-action/compare/v6.0.1...v6.1.0
r-lib/actions (r-lib/actions) ### [`v2.10.0`](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0) [Compare Source](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0)
--- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on monday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://togithub.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View the [repository job log](https://developer.mend.io/github/google/osv-scanner). Co-authored-by: Xueqin Cui <72771658+cuixq@users.noreply.github.com> --- .github/workflows/checks.yml | 2 +- .github/workflows/goreleaser.yml | 2 +- .github/workflows/lint-action/action.yml | 2 +- .github/workflows/osv-scanner-reusable-pr.yml | 6 +++--- .github/workflows/osv-scanner-reusable.yml | 2 +- .github/workflows/prerelease-check.yml | 2 +- .github/workflows/scorecards.yml | 2 +- .github/workflows/semantic.yml | 14 +++++++------- 8 files changed, 16 insertions(+), 16 deletions(-) diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index ca82313a67..379b9f3c82 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -82,7 +82,7 @@ jobs: with: persist-credentials: false - run: scripts/build_test_images.sh - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: image-fixtures-${{ github.run_number }}-${{ github.run_attempt }} path: internal/image/fixtures/*.tar diff --git a/.github/workflows/goreleaser.yml b/.github/workflows/goreleaser.yml index c3467f65eb..454eab50d0 100644 --- a/.github/workflows/goreleaser.yml +++ b/.github/workflows/goreleaser.yml @@ -32,7 +32,7 @@ jobs: go-version-file: .go-version check-latest: true - uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3 - - uses: docker/setup-buildx-action@aa33708b10e362ff993539393ff100fa93ed6a27 # v3 + - uses: docker/setup-buildx-action@988b5a0280414f521da01fcc63a27aeeb4b104db # v3 - name: ghcr-login uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3 with: diff --git a/.github/workflows/lint-action/action.yml b/.github/workflows/lint-action/action.yml index dc6cfb2a1a..bc728600f4 100644 --- a/.github/workflows/lint-action/action.yml +++ b/.github/workflows/lint-action/action.yml @@ -19,7 +19,7 @@ runs: using: composite steps: - name: Run golangci-lint - uses: golangci/golangci-lint-action@a4f60bb28d35aeee14e6880718e0c85ff1882e64 # v6.0.1 + uses: golangci/golangci-lint-action@aaa42aa0628b4ae2578232a66b541047968fac86 # v6.1.0 with: # Optional: version of golangci-lint to use in form of v1.2 or v1.2.3 or `latest` to use the latest version version: v1.59.1 diff --git a/.github/workflows/osv-scanner-reusable-pr.yml b/.github/workflows/osv-scanner-reusable-pr.yml index 3adf941cd8..f79c853215 100644 --- a/.github/workflows/osv-scanner-reusable-pr.yml +++ b/.github/workflows/osv-scanner-reusable-pr.yml @@ -86,21 +86,21 @@ jobs: # format to the repository Actions tab. - name: "Upload artifact" if: "!cancelled()" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: SARIF file path: ${{ inputs.results-file-name }} retention-days: 5 - name: "Upload old scan json results" if: "!cancelled()" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: old-json-results path: old-results.json retention-days: 5 - name: "Upload new scan json results" if: "!cancelled()" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: new-json-results path: new-results.json diff --git a/.github/workflows/osv-scanner-reusable.yml b/.github/workflows/osv-scanner-reusable.yml index 92b7a0806b..e40f5886ef 100644 --- a/.github/workflows/osv-scanner-reusable.yml +++ b/.github/workflows/osv-scanner-reusable.yml @@ -83,7 +83,7 @@ jobs: # format to the repository Actions tab. - name: "Upload artifact" if: "!cancelled()" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: SARIF file path: ${{ inputs.results-file-name }} diff --git a/.github/workflows/prerelease-check.yml b/.github/workflows/prerelease-check.yml index 489d43d612..26d87bb596 100644 --- a/.github/workflows/prerelease-check.yml +++ b/.github/workflows/prerelease-check.yml @@ -70,7 +70,7 @@ jobs: with: persist-credentials: false - run: scripts/build_test_images.sh - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: image-fixtures-${{ github.run_number }}-${{ github.run_attempt }} path: internal/image/fixtures/*.tar diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index f51ab8d285..c6f97c3515 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -60,7 +60,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: SARIF file path: results.sarif diff --git a/.github/workflows/semantic.yml b/.github/workflows/semantic.yml index 6800131a7b..03b269c7d3 100644 --- a/.github/workflows/semantic.yml +++ b/.github/workflows/semantic.yml @@ -49,7 +49,7 @@ jobs: - run: python3 scripts/generators/generate-debian-versions.py - run: git status - run: stat debian-db.zip - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-debian-versions path: internal/semantic/fixtures/debian-versions-generated.txt @@ -73,7 +73,7 @@ jobs: extensions: zip - run: php scripts/generators/generate-packagist-versions.php - run: git status - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-packagist-versions path: internal/semantic/fixtures/packagist-versions-generated.txt @@ -93,7 +93,7 @@ jobs: run: pip install packaging==21.3 - run: python3 scripts/generators/generate-pypi-versions.py - run: git status - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-pypi-versions path: internal/semantic/fixtures/pypi-versions-generated.txt @@ -113,7 +113,7 @@ jobs: run: gem install rubyzip - run: ruby scripts/generators/generate-rubygems-versions.rb - run: git status - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-rubygems-versions path: internal/semantic/fixtures/rubygems-versions-generated.txt @@ -139,7 +139,7 @@ jobs: -o scripts/generators/lib/maven-artifact-3.8.5.jar - run: java -cp 'scripts/generators/lib/*' scripts/generators/GenerateMavenVersions.java - run: git status - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-maven-versions path: internal/semantic/fixtures/maven-versions-generated.txt @@ -152,12 +152,12 @@ jobs: - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 with: persist-credentials: false - - uses: r-lib/actions/setup-r@929c772977a3a13c8733b363bf5a2f685c25dd91 # v2.9.0 + - uses: r-lib/actions/setup-r@d1a6cbabea8dd2f137598ba2a70ae37ac82d7941 # v2.10.0 with: r-version: "3.5.3" - run: Rscript scripts/generators/generate-cran-versions.R - run: git status - - uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4 + - uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5 with: name: generated-cran-versions path: internal/semantic/fixtures/cran-versions-generated.txt