Skip to content

Commit 8adf4e4

Browse files
chore(actions): bump the github-actions-updates group across 1 directory with 11 updates
Bumps the github-actions-updates group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.3.1` | `6.0.2` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.10.0` | `4.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.3.0` | `4.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `6.2.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `8` | | [actions/github-script](https://github.com/actions/github-script) | `7.1.0` | `9.0.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `8a12e8e2fb6f3c4a4294a8e63b3659af6c08cfe3` | `6c542a5ae69ddd1214cb9dcb57ec2efbaf9ee42d` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `3.0.3` | `4.0.1` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `2.2.3` | `4.1.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.0.8` | `3.0.0` | Updates `actions/checkout` from 4.3.1 to 6.0.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@34e1148...de0fac2) Updates `docker/setup-buildx-action` from 3.10.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@b5ca514...4d04d5d) Updates `docker/login-action` from 3.3.0 to 4.1.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...4907a6d) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) Updates `actions/setup-python` from 5.6.0 to 6.2.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@a26af69...a309ff8) Updates `actions/download-artifact` from 4 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) Updates `actions/github-script` from 7.1.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@f28e40c...3a2844b) Updates `trufflesecurity/trufflehog` from 8a12e8e2fb6f3c4a4294a8e63b3659af6c08cfe3 to 6c542a5ae69ddd1214cb9dcb57ec2efbaf9ee42d - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@8a12e8e...6c542a5) Updates `dorny/paths-filter` from 3.0.3 to 4.0.1 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](dorny/paths-filter@d1c1ffe...fbd0ab8) Updates `actions/attest-build-provenance` from 2.2.3 to 4.1.0 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@c074443...a2bbfa2) Updates `softprops/action-gh-release` from 2.0.8 to 3.0.0 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@c062e08...b430933) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/setup-python dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: docker/login-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: dorny/paths-filter dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: softprops/action-gh-release dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: trufflesecurity/trufflehog dependency-version: 2edd4d326abd10ea6320e03f42c3b6a7cf259b3d dependency-type: direct:production dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 4206e1a commit 8adf4e4

12 files changed

Lines changed: 36 additions & 36 deletions

.github/workflows/_build_container.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -48,12 +48,12 @@ jobs:
4848
image_tag: ${{ steps.build.outputs.image_tag }}
4949
steps:
5050
- name: Checkout repository
51-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
51+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5252
- name: Set up Docker Buildx
53-
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
53+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v3
5454
- name: Log in to GitHub Container Registry
5555
if: ${{ inputs.push }}
56-
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3
56+
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v3
5757
with:
5858
registry: ghcr.io
5959
username: ${{ github.actor }}

.github/workflows/_build_package.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
metadata: ${{ steps.build.outputs.metadata }}
4242
steps:
4343
- name: Checkout repository
44-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
44+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4545
with:
4646
fetch-depth: 0
4747
- name: "Set up build toolchain"
@@ -58,7 +58,7 @@ jobs:
5858
SHA=$(find dist/ -type f | sort | xargs sha256sum | sha256sum | awk '{print $1}')
5959
echo "metadata=${SHA}" >> "$GITHUB_OUTPUT"
6060
- name: Upload build artifact
61-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
61+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
6262
with:
6363
name: build-artifact-${{ inputs.build_type }}-${{ github.run_id }}
6464
path: dist/

.github/workflows/_docs.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -45,11 +45,11 @@ jobs:
4545
deployed_url: ${{ steps.dest.outputs.path }}
4646
steps:
4747
- name: Checkout repository
48-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
48+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4949
with:
5050
fetch-depth: 0
5151
- name: Set up Python
52-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
52+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
5353
with:
5454
python-version: "3.x"
5555
- name: Configure Git Credentials
@@ -62,21 +62,21 @@ jobs:
6262
hatch run docs:mkdocs --version
6363
- name: Download unit test coverage
6464
if: ${{ inputs.include_coverage }}
65-
uses: actions/download-artifact@v4
65+
uses: actions/download-artifact@v8
6666
with:
6767
pattern: coverage-report-unit-*
6868
path: docs/coverage/unit
6969
merge-multiple: true
7070
- name: Download integration test coverage
7171
if: ${{ inputs.include_coverage }}
72-
uses: actions/download-artifact@v4
72+
uses: actions/download-artifact@v8
7373
with:
7474
pattern: coverage-report-integration-*
7575
path: docs/coverage/integration
7676
merge-multiple: true
7777
- name: Download e2e test coverage
7878
if: ${{ inputs.include_coverage }}
79-
uses: actions/download-artifact@v4
79+
uses: actions/download-artifact@v8
8080
with:
8181
pattern: coverage-report-e2e-*
8282
path: docs/coverage/e2e

.github/workflows/_link-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ jobs:
3636
report_content: ${{ steps.read-report.outputs.content }}
3737
steps:
3838
- name: Checkout repository
39-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
39+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4040
- name: Run lychee link checker
4141
uses: lycheeverse/lychee-action@8646ba30535128ac92d33dfc9133794bfdd9b411 # v2
4242
id: lychee

.github/workflows/_pr_comment.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
- name: "Download PR Number Artifact"
3030
# Wait, how does it know the PR number? The `development.yml` needs to upload the PR number as an artifact
3131
# so this workflow can read it. Let's write the script to find the PR associated with the commit.
32-
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7
32+
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
3333
with:
3434
script: |-
3535
const workflowRun = context.payload.workflow_run;

.github/workflows/_quality.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,9 @@ jobs:
2828
python-version: ${{ fromJson(inputs.python_versions) }}
2929
steps:
3030
- name: Checkout repository
31-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
31+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3232
- name: "Set up Python ${{ matrix.python-version }}"
33-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
33+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
3434
with:
3535
python-version: ${{ matrix.python-version }}
3636
- name: "Install uv"
@@ -49,9 +49,9 @@ jobs:
4949
python-version: ${{ fromJson(inputs.python_versions) }}
5050
steps:
5151
- name: Checkout repository
52-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
52+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5353
- name: "Set up Python ${{ matrix.python-version }}"
54-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
54+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
5555
with:
5656
python-version: ${{ matrix.python-version }}
5757
- name: "Install uv"

.github/workflows/_security.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,19 +18,19 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Checkout repository
21-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
21+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2222
with:
2323
fetch-depth: 0
2424
- name: Run TruffleHog
25-
uses: trufflesecurity/trufflehog@8a12e8e2fb6f3c4a4294a8e63b3659af6c08cfe3 # main
25+
uses: trufflesecurity/trufflehog@6c542a5ae69ddd1214cb9dcb57ec2efbaf9ee42d # main
2626
with:
2727
path: ./
2828
dependency-audit:
2929
name: "Dependency Vulnerability Scan"
3030
runs-on: ubuntu-latest
3131
steps:
3232
- name: Checkout repository
33-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
33+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3434
- name: Set up toolchain
3535
run: pip install pip-audit hatch
3636
- name: Run dependency vulnerability scan
@@ -40,7 +40,7 @@ jobs:
4040
pip-audit -r requirements.txt --output json -o audit.json
4141
- name: Upload SCA results
4242
if: always()
43-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
43+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
4444
with:
4545
name: sca-results-${{ github.run_id }}
4646
path: audit.json

.github/workflows/_tests.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -68,9 +68,9 @@ jobs:
6868
coverage_location: "coverage/"
6969
steps:
7070
- name: Checkout repository
71-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
71+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
7272
- name: "Set up Python ${{ matrix.python-version }}"
73-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
73+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
7474
with:
7575
python-version: ${{ matrix.python-version }}
7676
- name: "Install uv"
@@ -105,7 +105,7 @@ jobs:
105105
fi
106106
- name: Upload test results
107107
if: ${{ inputs.publish_results }}
108-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
108+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
109109
with:
110110
name: test-results-${{ matrix.test-config.level }}-py${{ matrix.python-version }}-${{
111111
github.run_id }}
@@ -114,7 +114,7 @@ jobs:
114114
if-no-files-found: warn
115115
- name: Upload coverage report
116116
if: ${{ inputs.publish_results && (inputs.generate_coverage == true || matrix.test-config.coverage == true) }}
117-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
117+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
118118
with:
119119
name: coverage-report-${{ matrix.test-config.level }}-py${{ matrix.python-version
120120
}}-${{ github.run_id }}

.github/workflows/development.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,9 @@ jobs:
3131
docs: ${{ steps.filter.outputs.docs }}
3232
steps:
3333
- name: Checkout repository
34-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
34+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3535
- name: Check for docs changes
36-
uses: dorny/paths-filter@d1c1ffe0248fe513906c8e24db8ea791d46f8590 # v3
36+
uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
3737
id: filter
3838
with:
3939
filters: |

.github/workflows/development_cleanup.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,11 +22,11 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- name: Checkout repository
25-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
25+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2626
with:
2727
fetch-depth: 0
2828
- name: Set up Python
29-
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
29+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
3030
with:
3131
python-version: "3.x"
3232
- name: Configure Git Credentials

0 commit comments

Comments
 (0)