Bump the github-actions group across 1 directory with 10 updates#3944
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the github-actions group across 1 directory with 10 updates#3944dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dixoncharles113-ai
approved these changes
Dec 12, 2025
8286473 to
688296f
Compare
688296f to
9553dbc
Compare
9553dbc to
c64b1c6
Compare
c64b1c6 to
97b9157
Compare
97b9157 to
b469139
Compare
Bumps the github-actions group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.5.1` | `2.19.4` | | [actions/checkout](https://github.com/actions/checkout) | `2.7.0` | `6.0.3` | | [arduino/setup-protoc](https://github.com/arduino/setup-protoc) | `1.3.0` | `3.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `2.21.3` | `4.36.1` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `3.0.7` | `5.0.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `3.12.0` | `5.2.0` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `fa4ff678dd5d0a4fa3d628e57af8162873e93cd6` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `8bd1ce1c4be9d98053ffd9e6e14585276a36762c` | `fa4ff678dd5d0a4fa3d628e57af8162873e93cd6` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.3.3` | `2.4.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `7.0.1` | Updates `step-security/harden-runner` from 2.5.1 to 2.19.4 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@8ca2b8b...9af89fc) Updates `actions/checkout` from 2.7.0 to 6.0.3 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v2.7.0...df4cb1c) Updates `arduino/setup-protoc` from 1.3.0 to 3.0.0 - [Release notes](https://github.com/arduino/setup-protoc/releases) - [Commits](arduino/setup-protoc@149f6c8...c65c819) Updates `github/codeql-action` from 2.21.3 to 4.36.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v2.21.3...87557b9) Updates `actions/dependency-review-action` from 3.0.7 to 5.0.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@7d90b4f...a1d282b) Updates `actions/setup-java` from 3.12.0 to 5.2.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@cd89f46...be666c2) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 8bd1ce1c4be9d98053ffd9e6e14585276a36762c to fa4ff678dd5d0a4fa3d628e57af8162873e93cd6 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@8bd1ce1...fa4ff67) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 8bd1ce1c4be9d98053ffd9e6e14585276a36762c to fa4ff678dd5d0a4fa3d628e57af8162873e93cd6 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@8bd1ce1...fa4ff67) Updates `ossf/scorecard-action` from 2.3.3 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@dc50aa9...4eaacf0) Updates `actions/upload-artifact` from 4.3.3 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6546280...043fb46) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.8.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: arduino/setup-protoc dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.31.6 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: '08b0aaeb6b6c6659ff98c5463e60e4b70008bfff' dependency-type: direct:production dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: '08b0aaeb6b6c6659ff98c5463e60e4b70008bfff' dependency-type: direct:production dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: step-security/harden-runner dependency-version: 2.13.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
b469139 to
d333715
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 10 updates in the / directory:
2.5.12.19.42.7.06.0.31.3.03.0.02.21.34.36.13.0.75.0.03.12.05.2.08bd1ce1c4be9d98053ffd9e6e14585276a36762cfa4ff678dd5d0a4fa3d628e57af8162873e93cd68bd1ce1c4be9d98053ffd9e6e14585276a36762cfa4ff678dd5d0a4fa3d628e57af8162873e93cd62.3.32.4.34.3.37.0.1Updates
step-security/harden-runnerfrom 2.5.1 to 2.19.4Release notes
Sourced from step-security/harden-runner's releases.
... (truncated)
Commits
9af89fcMerge pull request #667 from step-security/update-agent-v1.8.6485dce8Update agent to v1.8.6ab7a940Merge pull request #665 from step-security/fix/use-policy-store-default-auditec41b78Default to audit mode when api-key missing with use-policy-store9ca718dMerge pull request #664 from step-security/update-agent-v1.8.51dee3dfUpdate agent to v1.8.5a5ad31dMerge pull request #657 from devantler/fix/ubuntu-slim-user-env6e92856build dist and trim ubuntu-slim message4e0504eMerge branch 'main' into fix/ubuntu-slim-user-env8d3c67dRelease v2.19.0 (#661)Updates
actions/checkoutfrom 2.7.0 to 6.0.3Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
df4cb1cUpdate changelog for v6.0.3 (#2446)1cce339Fix checkout init for SHA-256 repositories (#2439)900f221fix: expand merge commit SHA regex and add SHA-256 test cases (#2414)0c366fdUpdate changelog (#2357)de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)Updates
arduino/setup-protocfrom 1.3.0 to 3.0.0Release notes
Sourced from arduino/setup-protoc's releases.
Commits
c65c819Upgrade to node 20 (#95)52a53b4Merge pull request #93 from arduino/dependabot/npm_and_yarn/babel/traverse-7....cf7ab7fBump@babel/traversefrom 7.22.1 to 7.23.2e2995baCorrectconvetiontypo in README (#91)a8b67babump semver to 7.5.3 (#90)1530d62Bump semver from 7.5.1 to 7.5.2 (#87)0fbeb49Exposepathandversioninoutputs(#89)9b1ee5bv2 release note (#82)28fd3e5Support only the new protobuf versioning scheme (#78)Updates
github/codeql-actionfrom 2.21.3 to 4.36.1Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
87557b9Merge pull request #3940 from github/update-v4.36.1-2a1689ed49431011Update changelog for v4.36.12a1689eMerge pull request #3939 from github/henrymercer/skip-overlay-revert-when-exp...5245323Disable missing diff-ranges fallback when overlay enabled manuallyd1eb120Merge pull request #3933 from github/update-supported-enterprise-server-versions115001bMerge pull request #3934 from github/dependabot/npm_and_yarn/npm-minor-86fb5c...cef2e7aMerge pull request #3925 from github/dependabot/github_actions/dot-github/wor...5e6adf7Merge pull request #3936 from github/dependabot/npm_and_yarn/tmp-0.2.7ad170e6Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actio...6a37b3aRebuildUpdates
actions/dependency-review-actionfrom 3.0.7 to 5.0.0Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
a1d282bMerge pull request #1098 from actions/ahpook/v5-releaseeb6c199update examples to show@v53943c2cv5.0.0 release branch454943cMerge pull request #1094 from actions/ashelytc/security-findings6d92a12revert@typescript-eslint/parserupdatea8e5a7eMerge pull request #1076 from tspascoal/fix-version-matching-for-non-string-s...b6b7079update@typescript-eslint/parserto 8.40.0821a21dupdate more dependencies05aaaaerun npm audit fix55d3e75Merge pull request #1077 from Marukome0743/docs/checkoutUpdates
actions/setup-javafrom 3.12.0 to 5.2.0Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
be666c2Chore: Version Update and Checkout Update to v6 (#973)f7a6fefBump actions/checkout from 5 to 6 (#961)d81c4e4Upgrade@actions/cacheto v5 (#968)1b1bbe1readme update (#972)5d7b214Retry on HTTP 522 Connection timed out (#964)f2beeb2Bump actions/publish-action from 0.3.0 to 0.4.0 (#912)4e7e684feat: Add support for.sdkmanrcfile injava-version-fileparameter (#736)46c56d6Add GitHub Token Support for GraalVM and Refactor Code (#849)66b9457Update SapMachine URLs (#955)6ba5449Enhance error logging for network failures to include endpoint/IP details, ad...Updates
google/osv-scanner-action/.github/workflows/osv-scanner-reusable.ymlfrom 8bd1ce1c4be9d98053ffd9e6e14585276a36762c to fa4ff678dd5d0a4fa3d628e57af8162873e93cd6Commits
fa4ff67Merge pull request #131 from BeyondEvil/feat/add-runs-on-inpute3f946afeat: add runs-on input to reusable workflowsb8ac13fMerge pull request #127 from SVilgelm/patch-105957d4Merge pull request #130 from google/gate-outputs-with-flag-202605193a7550ffeat: gate reusable workflow outputs with a flagf6fb127Pin download-artifact action to SHA9a49870Update unified workflow example to ...Description has been truncated