Skip to content

Commit 8d6595f

Browse files
renovate-botcuixq
andauthored
chore(deps): update workflows (#1161)
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/upload-artifact](https://togithub.com/actions/upload-artifact) | action | patch | `v4.3.4` -> `v4.3.5` | | [docker/setup-buildx-action](https://togithub.com/docker/setup-buildx-action) | action | digest | `aa33708` -> `988b5a0` | | [golangci/golangci-lint-action](https://togithub.com/golangci/golangci-lint-action) | action | minor | `v6.0.1` -> `v6.1.0` | | [r-lib/actions](https://togithub.com/r-lib/actions) | action | minor | `v2.9.0` -> `v2.10.0` | --- ### Release Notes <details> <summary>actions/upload-artifact (actions/upload-artifact)</summary> ### [`v4.3.5`](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5) [Compare Source](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5) </details> <details> <summary>golangci/golangci-lint-action (golangci/golangci-lint-action)</summary> ### [`v6.1.0`](https://togithub.com/golangci/golangci-lint-action/releases/tag/v6.1.0) [Compare Source](https://togithub.com/golangci/golangci-lint-action/compare/v6.0.1...v6.1.0) <!-- Release notes generated using configuration in .github/release.yml at v6.1.0 --> #### What's Changed ##### Changes - feat: allow to skip golangci-lint installation by [@&#8203;ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1079](https://togithub.com/golangci/golangci-lint-action/pull/1079) ##### Documentation - docs: add Go workspace examples by [@&#8203;ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1064](https://togithub.com/golangci/golangci-lint-action/pull/1064) ##### Dependencies - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.12.8 to 20.12.11 by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1041](https://togithub.com/golangci/golangci-lint-action/pull/1041) - build(deps-dev): bump [@&#8203;typescript-eslint/eslint-plugin](https://togithub.com/typescript-eslint/eslint-plugin) from 7.8.0 to 7.9.0 by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1042](https://togithub.com/golangci/golangci-lint-action/pull/1042) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.12.11 to 20.12.12 by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1043](https://togithub.com/golangci/golangci-lint-action/pull/1043) - build(deps-dev): bump [@&#8203;typescript-eslint/parser](https://togithub.com/typescript-eslint/parser) from 7.8.0 to 7.9.0 by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1044](https://togithub.com/golangci/golangci-lint-action/pull/1044) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1047](https://togithub.com/golangci/golangci-lint-action/pull/1047) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.12.12 to 20.14.0 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1051](https://togithub.com/golangci/golangci-lint-action/pull/1051) - build(deps-dev): bump the dev-dependencies group across 1 directory with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1053](https://togithub.com/golangci/golangci-lint-action/pull/1053) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1061](https://togithub.com/golangci/golangci-lint-action/pull/1061) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.0 to 20.14.2 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1062](https://togithub.com/golangci/golangci-lint-action/pull/1062) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1063](https://togithub.com/golangci/golangci-lint-action/pull/1063) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.2 to 20.14.8 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1066](https://togithub.com/golangci/golangci-lint-action/pull/1066) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1065](https://togithub.com/golangci/golangci-lint-action/pull/1065) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1067](https://togithub.com/golangci/golangci-lint-action/pull/1067) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.8 to 20.14.9 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1068](https://togithub.com/golangci/golangci-lint-action/pull/1068) - build(deps-dev): bump the dev-dependencies group with 4 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1071](https://togithub.com/golangci/golangci-lint-action/pull/1071) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.9 to 20.14.10 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1072](https://togithub.com/golangci/golangci-lint-action/pull/1072) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1073](https://togithub.com/golangci/golangci-lint-action/pull/1073) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1074](https://togithub.com/golangci/golangci-lint-action/pull/1074) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.10 to 20.14.11 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1075](https://togithub.com/golangci/golangci-lint-action/pull/1075) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1077](https://togithub.com/golangci/golangci-lint-action/pull/1077) - build(deps): bump [@&#8203;types/node](https://togithub.com/types/node) from 20.14.11 to 22.0.0 in the dependencies group by [@&#8203;dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1078](https://togithub.com/golangci/golangci-lint-action/pull/1078) **Full Changelog**: golangci/golangci-lint-action@v6.0.1...v6.1.0 </details> <details> <summary>r-lib/actions (r-lib/actions)</summary> ### [`v2.10.0`](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0) [Compare Source](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on monday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://togithub.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View the [repository job log](https://developer.mend.io/github/google/osv-scanner). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40NDAuNyIsInVwZGF0ZWRJblZlciI6IjM3LjQ0MC43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: Xueqin Cui <[email protected]>
1 parent 8617d67 commit 8d6595f

8 files changed

+16
-16
lines changed

.github/workflows/checks.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ jobs:
8282
with:
8383
persist-credentials: false
8484
- run: scripts/build_test_images.sh
85-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
85+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
8686
with:
8787
name: image-fixtures-${{ github.run_number }}-${{ github.run_attempt }}
8888
path: internal/image/fixtures/*.tar

.github/workflows/goreleaser.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
go-version-file: .go-version
3333
check-latest: true
3434
- uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
35-
- uses: docker/setup-buildx-action@aa33708b10e362ff993539393ff100fa93ed6a27 # v3
35+
- uses: docker/setup-buildx-action@988b5a0280414f521da01fcc63a27aeeb4b104db # v3
3636
- name: ghcr-login
3737
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3
3838
with:

.github/workflows/lint-action/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ runs:
1919
using: composite
2020
steps:
2121
- name: Run golangci-lint
22-
uses: golangci/golangci-lint-action@a4f60bb28d35aeee14e6880718e0c85ff1882e64 # v6.0.1
22+
uses: golangci/golangci-lint-action@aaa42aa0628b4ae2578232a66b541047968fac86 # v6.1.0
2323
with:
2424
# Optional: version of golangci-lint to use in form of v1.2 or v1.2.3 or `latest` to use the latest version
2525
version: v1.59.1

.github/workflows/osv-scanner-reusable-pr.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -86,21 +86,21 @@ jobs:
8686
# format to the repository Actions tab.
8787
- name: "Upload artifact"
8888
if: "!cancelled()"
89-
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
89+
uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
9090
with:
9191
name: SARIF file
9292
path: ${{ inputs.results-file-name }}
9393
retention-days: 5
9494
- name: "Upload old scan json results"
9595
if: "!cancelled()"
96-
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
96+
uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
9797
with:
9898
name: old-json-results
9999
path: old-results.json
100100
retention-days: 5
101101
- name: "Upload new scan json results"
102102
if: "!cancelled()"
103-
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
103+
uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
104104
with:
105105
name: new-json-results
106106
path: new-results.json

.github/workflows/osv-scanner-reusable.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ jobs:
8383
# format to the repository Actions tab.
8484
- name: "Upload artifact"
8585
if: "!cancelled()"
86-
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
86+
uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
8787
with:
8888
name: SARIF file
8989
path: ${{ inputs.results-file-name }}

.github/workflows/prerelease-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ jobs:
7070
with:
7171
persist-credentials: false
7272
- run: scripts/build_test_images.sh
73-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
73+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
7474
with:
7575
name: image-fixtures-${{ github.run_number }}-${{ github.run_attempt }}
7676
path: internal/image/fixtures/*.tar

.github/workflows/scorecards.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ jobs:
6060
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6161
# format to the repository Actions tab.
6262
- name: "Upload artifact"
63-
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
63+
uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
6464
with:
6565
name: SARIF file
6666
path: results.sarif

.github/workflows/semantic.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ jobs:
4949
- run: python3 scripts/generators/generate-debian-versions.py
5050
- run: git status
5151
- run: stat debian-db.zip
52-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
52+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
5353
with:
5454
name: generated-debian-versions
5555
path: internal/semantic/fixtures/debian-versions-generated.txt
@@ -73,7 +73,7 @@ jobs:
7373
extensions: zip
7474
- run: php scripts/generators/generate-packagist-versions.php
7575
- run: git status
76-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
76+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
7777
with:
7878
name: generated-packagist-versions
7979
path: internal/semantic/fixtures/packagist-versions-generated.txt
@@ -93,7 +93,7 @@ jobs:
9393
run: pip install packaging==21.3
9494
- run: python3 scripts/generators/generate-pypi-versions.py
9595
- run: git status
96-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
96+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
9797
with:
9898
name: generated-pypi-versions
9999
path: internal/semantic/fixtures/pypi-versions-generated.txt
@@ -113,7 +113,7 @@ jobs:
113113
run: gem install rubyzip
114114
- run: ruby scripts/generators/generate-rubygems-versions.rb
115115
- run: git status
116-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
116+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
117117
with:
118118
name: generated-rubygems-versions
119119
path: internal/semantic/fixtures/rubygems-versions-generated.txt
@@ -139,7 +139,7 @@ jobs:
139139
-o scripts/generators/lib/maven-artifact-3.8.5.jar
140140
- run: java -cp 'scripts/generators/lib/*' scripts/generators/GenerateMavenVersions.java
141141
- run: git status
142-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
142+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
143143
with:
144144
name: generated-maven-versions
145145
path: internal/semantic/fixtures/maven-versions-generated.txt
@@ -152,12 +152,12 @@ jobs:
152152
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
153153
with:
154154
persist-credentials: false
155-
- uses: r-lib/actions/setup-r@929c772977a3a13c8733b363bf5a2f685c25dd91 # v2.9.0
155+
- uses: r-lib/actions/setup-r@d1a6cbabea8dd2f137598ba2a70ae37ac82d7941 # v2.10.0
156156
with:
157157
r-version: "3.5.3"
158158
- run: Rscript scripts/generators/generate-cran-versions.R
159159
- run: git status
160-
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
160+
- uses: actions/upload-artifact@89ef406dd8d7e03cfd12d9e0a4a378f454709029 # v4.3.5
161161
with:
162162
name: generated-cran-versions
163163
path: internal/semantic/fixtures/cran-versions-generated.txt

0 commit comments

Comments
 (0)