[ci][skip-ci](deps): Bump the github-actions group across 1 directory with 12 updates#3
Merged
Nick2bad4u merged 1 commit intoOct 10, 2025
Conversation
… with 12 updates Bumps the github-actions group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.13.0` | `2.13.1` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [actions/first-interaction](https://github.com/actions/first-interaction) | `2.0.0` | `3.1.0` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.0.1` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `8.8.0` | `9.1.0` | | [google/osv-scanner-action](https://github.com/google/osv-scanner-action) | `2.1.0` | `2.2.3` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `5.0.0` | | [actions/cache](https://github.com/actions/cache) | `4.2.3` | `4.3.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.0` | `2.4.3` | | [actions/stale](https://github.com/actions/stale) | `9.1.0` | `10.1.0` | | [actions/ai-inference](https://github.com/actions/ai-inference) | `1.2.3` | `2.0.1` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.90.2` | `3.90.8` | Updates `step-security/harden-runner` from 2.13.0 to 2.13.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@v2.13.0...f4a75cf) Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4.2.2...08c6903) Updates `actions/first-interaction` from 2.0.0 to 3.1.0 - [Release notes](https://github.com/actions/first-interaction/releases) - [Commits](actions/first-interaction@2d4393e...1c46889) Updates `actions/labeler` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...634933e) Updates `oxsecurity/megalinter` from 8.8.0 to 9.1.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@e08c2b0...62c799d) Updates `google/osv-scanner-action` from 2.1.0 to 2.2.3 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@b00f71e...e92b5d0) Updates `actions/setup-node` from 4.4.0 to 5.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@49933ea...a0853c2) Updates `actions/cache` from 4.2.3 to 4.3.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@5a3ec84...0057852) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@62b2cac...4eaacf0) Updates `actions/stale` from 9.1.0 to 10.1.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@5bef64f...5f858e3) Updates `actions/ai-inference` from 1.2.3 to 2.0.1 - [Release notes](https://github.com/actions/ai-inference/releases) - [Commits](actions/ai-inference@9693b13...a1c1182) Updates `trufflesecurity/trufflehog` from 3.90.2 to 3.90.8 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Changelog](https://github.com/trufflesecurity/trufflehog/blob/main/.goreleaser.yml) - [Commits](trufflesecurity/trufflehog@a05cf08...466da5b) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/first-interaction dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-version: 9.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action dependency-version: 2.2.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/stale dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/ai-inference dependency-version: 2.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.90.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Contributor
Author
|
Dependabot attempted to update this pull request, but because the branch |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 12 updates in the / directory:
2.13.02.13.14.2.25.0.02.0.03.1.05.0.06.0.18.8.09.1.02.1.02.2.34.4.05.0.04.2.34.3.02.4.02.4.39.1.010.1.01.2.32.0.13.90.23.90.8Updates
step-security/harden-runnerfrom 2.13.0 to 2.13.1Release notes
Sourced from step-security/harden-runner's releases.
Commits
f4a75cfMerge pull request #588 from step-security/rc-2695503d0ci: remove code-review workflow4b250a0ci: add job to confirm dist is as expected5b0ab6aupdate dependenciesd11f2c1fix bug where status code was not being preservedb3fc98eimprove error handling for policy store sceanrio92fc5d4update error messageb61b0a4policy store improvementse3d3f2buse GitHub release instead of packages646ac01update agentUpdates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
actions/first-interactionfrom 2.0.0 to 3.1.0Release notes
Sourced from actions/first-interaction's releases.
Commits
1c46889Merge pull request #363 from actions/dependabot/npm_and_yarn/npm-development-...76a99ddDisable checks for dist2ead13cBump the npm-development group across 1 directory with 10 updates2e8e200Merge pull request #361 from actions/dependabot/npm_and_yarn/rollup/rollup-li...df55979Merge pull request #357 from actions/dependabot/npm_and_yarn/octokit/types-15...c056c18Bump@rollup/rollup-linux-x64-gnufrom 4.50.2 to 4.52.3dac371dBump@octokit/typesfrom 14.1.0 to 15.0.033689d3Merge pull request #354 from actions/ncalteen/event8e69b57Merge branch 'main' into ncalteen/event69c5373Merge pull request #351 from actions/dependabot/npm_and_yarn/github/local-act...Updates
actions/labelerfrom 5.0.0 to 6.0.1Release notes
Sourced from actions/labeler's releases.
... (truncated)
Commits
634933epublish-action upgrade to 0.4.0 from 0.2.2 (#901)f1a63e8Update Node.js version to 24 in action and dependencies (#891)b0a1180Bump@octokit/request-errorfrom 5.0.1 to 5.1.1 (#846)110d441Update README.md (#871)bee50feBump undici from 5.28.4 to 5.28.5 (#842)6463cdbBump eslint-plugin-jest from 28.9.0 to 28.11.0 (#839)c209686Bump typescript from 5.7.2 to 5.7.3 (#835)5184940Bump@vercel/nccfrom 0.38.1 to 0.38.3 (#830)3629d55Document update - permission section (#840)d24f7f3Bump ts-jest from 29.1.2 to 29.2.5 (#831)Updates
oxsecurity/megalinterfrom 8.8.0 to 9.1.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
62c799dRelease MegaLinter v9.1.06158659[automation] Auto-update linters version, help and documentation (#6299)013588achore(deps): update dependency lightning-flow-scanner to v5.6.2 (#6301)ee69172chore(deps): update dependency isort to v6.1.0 (#6300)49e1637chore(deps): update dependency eslint-plugin-jsonc to v2.21.0 (#6298)1db8d0fchore(deps): update dependency eslint to v9.37.0 (#6297)f26af91[automation] Auto-update linters version, help and documentation (#6296)9786a83chore(deps): update dependency cfn-lint to v1.40.0 (#6295)69457fcchore(deps): update dependency azure/bicep to v0.38.33 (#6294)4ae0e6fchore(deps): update dependency npm-groovy-lint to v15.2.2 (#6293)Updates
google/osv-scanner-actionfrom 2.1.0 to 2.2.3Release notes
Sourced from google/osv-scanner-action's releases.
... (truncated)
Commits
e92b5d0Merge pull request #101 from google/update-to-v2.2.3c1fee26Update unified workflow example to point to v2.2.3 reusable workflowse161549Update reusable workflows to point to v2.2.3 actionsb930bc9"Update actions to use v2.2.3 osv-scanner image"c0e8a11Merge pull request #87 from renovate-bot/renovate/major-workflowsf317cb8chore(deps): update workflows to v59e22416Merge pull request #86 from renovate-bot/renovate/workflows90b209dMerge pull request #95 from google/update-to-v2.2.24971fe8Update unified workflow example to point to v2.2.2 reusable workflows9d4732eUpdate reusable workflows to point to v2.2.2 actionsUpdates
actions/setup-nodefrom 4.4.0 to 5.0.0Release notes
Sourced from actions/setup-node's releases.
Commits
a0853c2Bump actions/checkout from 4 to 5 (#1345)b7234ccUpgrade action to use node24 (#1325)d7a1131Enhance caching in setup-node with automatic package manager detection (#1348)5e2628cBumps form-data (#1332)65becefBump undici from 5.28.5 to 5.29.0 (#1295)7e24a65Bump uuid from 9.0.1 to 11.1.0 (#1273)08f58d1Bump@octokit/request-errorand@actions/github(#1227)Updates
actions/cachefrom 4.2.3 to 4.3.0Release notes
Sourced from actions/cache's releases.
Changelog
Sourced fro...
Description has been truncated