Skip to content

Commit 2dd9f89

Browse files
chore(deps): bump the actions-deps group with 13 updates (#722)
Bumps the actions-deps group with 13 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.15.0` | `2.16.0` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.4` | `47.0.5` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.68.15` | `2.69.1` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.4` | `4.33.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.2.0` | `6.3.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.2` | `5.5.3` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.19.2` | `7.0.0` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2.2.1` | `3.0.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.10.0` | `6.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.0.0` | | [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `2.1.6` | `2.1.8` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.23.0` | `0.23.1` | Updates `step-security/harden-runner` from 2.15.0 to 2.16.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a90bcbc...fa2e9d6) Updates `tj-actions/changed-files` from 47.0.4 to 47.0.5 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@7dee1b0...22103cc) Updates `taiki-e/install-action` from 2.68.15 to 2.69.1 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@68675c5...e24b8b7) Updates `github/codeql-action` from 4.32.4 to 4.33.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@89a39a4...b1bff81) Updates `actions/setup-node` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@6044e13...53b8394) Updates `codecov/codecov-action` from 5.5.2 to 5.5.3 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@671740a...1af5884) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...4d04d5d) Updates `docker/build-push-action` from 6.19.2 to 7.0.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@10e90e3...d08e5c3) Updates `actions/create-github-app-token` from 2.2.1 to 3.0.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Commits](actions/create-github-app-token@29824e6...f8d387b) Updates `docker/metadata-action` from 5.10.0 to 6.0.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@c299e40...030e881) Updates `docker/login-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@c94ce9f...b45d80f) Updates `iarekylew00t/verified-bot-commit` from 2.1.6 to 2.1.8 - [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases) - [Commits](IAreKyleW00t/verified-bot-commit@b001460...b12a125) Updates `anchore/sbom-action` from 0.23.0 to 0.23.1 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@17ae174...57aae52) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: tj-actions/changed-files dependency-version: 47.0.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: taiki-e/install-action dependency-version: 2.69.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: github/codeql-action dependency-version: 4.33.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: actions/setup-node dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: codecov/codecov-action dependency-version: 5.5.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: docker/build-push-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/create-github-app-token dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: docker/metadata-action dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: docker/login-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: iarekylew00t/verified-bot-commit dependency-version: 2.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: anchore/sbom-action dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent b2dfc3a commit 2dd9f89

13 files changed

Lines changed: 53 additions & 53 deletions

.github/workflows/ci.yaml

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -38,14 +38,14 @@ jobs:
3838
steps:
3939
# Checkout the repository
4040
- name: Harden the runner (Audit all outbound calls)
41-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
41+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
4242
with:
4343
egress-policy: audit
4444
- name: Checkout Code
4545
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4646
- name: Get changed files
4747
id: changed-files-yaml
48-
uses: tj-actions/changed-files@7dee1b0c1557f278e5c7dc244927139d78c0e22a # v47.0.4
48+
uses: tj-actions/changed-files@22103cc46bda19c2b464ffe86db46df6922fd323 # v47.0.5
4949
with:
5050
files_yaml: |
5151
code:
@@ -77,7 +77,7 @@ jobs:
7777
runs-on: ubuntu-22.04-oz-8core
7878
steps:
7979
- name: Harden the runner (Audit all outbound calls)
80-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
80+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
8181
with:
8282
egress-policy: audit
8383
- name: Failed
@@ -90,7 +90,7 @@ jobs:
9090
steps:
9191
# Checkout the repository
9292
- name: Harden the runner (Audit all outbound calls)
93-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
93+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
9494
with:
9595
egress-policy: audit
9696
- name: Checkout Code
@@ -103,7 +103,7 @@ jobs:
103103
- name: Get cache-hit output
104104
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
105105
- name: Install cargo hack
106-
uses: taiki-e/install-action@68675c5a5f1a6950c3975d33f3ae0ef155e5bf3d # v2.68.15
106+
uses: taiki-e/install-action@e24b8b7a939c6a537188f34a4163cb153dd85cf6 # v2.69.1
107107
with:
108108
tool: cargo-hack
109109

@@ -117,7 +117,7 @@ jobs:
117117
steps:
118118
# Checkout the repository
119119
- name: Harden the runner (Audit all outbound calls)
120-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
120+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
121121
with:
122122
egress-policy: audit
123123
- name: Checkout Code
@@ -140,7 +140,7 @@ jobs:
140140
steps:
141141
# Checkout the repository
142142
- name: Harden the runner (Audit all outbound calls)
143-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
143+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
144144
with:
145145
egress-policy: audit
146146
- name: Checkout Code
@@ -170,7 +170,7 @@ jobs:
170170
path: clippy-results.sarif
171171
retention-days: 1
172172
- name: Upload
173-
uses: github/codeql-action/upload-sarif@89a39a4e59826350b863aa6b6252a07ad50cf83e # v3.29.5
173+
uses: github/codeql-action/upload-sarif@b1bff81932f5cdfc8695c7752dcee935dcd061c8 # v3.29.5
174174
with:
175175
sarif_file: clippy-results.sarif
176176
wait-for-processing: true
@@ -186,13 +186,13 @@ jobs:
186186
runs-on: ubuntu-22.04-oz-8core
187187
steps:
188188
- name: Harden the runner (Audit all outbound calls)
189-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
189+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
190190
with:
191191
egress-policy: audit
192192
- name: Checkout Code
193193
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
194194
- name: Setup Node.js
195-
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
195+
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
196196
with:
197197
node-version: '20'
198198
- name: Install pnpm and plugin dependencies
@@ -224,7 +224,7 @@ jobs:
224224
- name: Get cache-hit output
225225
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
226226
- name: Install cargo hack and cargo-llvm-cov
227-
uses: taiki-e/install-action@68675c5a5f1a6950c3975d33f3ae0ef155e5bf3d # v2.68.15
227+
uses: taiki-e/install-action@e24b8b7a939c6a537188f34a4163cb153dd85cf6 # v2.69.1
228228
with:
229229
tool: cargo-hack,cargo-llvm-cov
230230
- name: Run Developer Tests (excluding AI) and Generate Coverage Report
@@ -248,15 +248,15 @@ jobs:
248248
249249
# Upload coverage reports
250250
- name: Upload AI Coverage to Codecov
251-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
251+
uses: codecov/codecov-action@1af58845a975a7985b0beb0cbe6fbbb71a41dbad # v5.5.3
252252
with:
253253
token: ${{ secrets.CODECOV_TOKEN }}
254254
name: ai-coverage
255255
files: ai-lcov.info
256256
flags: ai
257257
fail_ci_if_error: true
258258
- name: Upload Developer Coverage to Codecov
259-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
259+
uses: codecov/codecov-action@1af58845a975a7985b0beb0cbe6fbbb71a41dbad # v5.5.3
260260
with:
261261
token: ${{ secrets.CODECOV_TOKEN }}
262262
name: dev-coverage
@@ -273,13 +273,13 @@ jobs:
273273
runs-on: ubuntu-latest
274274
steps:
275275
- name: Harden the runner (Audit all outbound calls)
276-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
276+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
277277
with:
278278
egress-policy: audit
279279
- name: Checkout Code
280280
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
281281
- name: Setup Node.js
282-
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
282+
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
283283
with:
284284
node-version: '20'
285285
- name: Install pnpm and plugin dependencies
@@ -311,7 +311,7 @@ jobs:
311311
- name: Get cache-hit output
312312
run: 'echo "Cache hit >>>>>: ${{ steps.init.outputs.cache-hit }}"'
313313
- name: Install cargo hack and cargo-llvm-cov
314-
uses: taiki-e/install-action@68675c5a5f1a6950c3975d33f3ae0ef155e5bf3d # v2.68.15
314+
uses: taiki-e/install-action@e24b8b7a939c6a537188f34a4163cb153dd85cf6 # v2.69.1
315315
with:
316316
tool: cargo-hack,cargo-llvm-cov
317317
- name: Run Properties Tests and Generate Coverage Report
@@ -322,7 +322,7 @@ jobs:
322322
CARGO_PROFILE_DEV_DEBUG: 1
323323
run: cargo hack llvm-cov --locked --ignore-filename-regex "(src/api/routes/docs/.*_docs\.rs$|src/repositories/.*/.*_redis\.rs$)" --lcov --output-path properties-lcov.info --test properties
324324
- name: Upload Properties Coverage to Codecov
325-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
325+
uses: codecov/codecov-action@1af58845a975a7985b0beb0cbe6fbbb71a41dbad # v5.5.3
326326
with:
327327
token: ${{ secrets.CODECOV_TOKEN }}
328328
name: properties-coverage
@@ -339,15 +339,15 @@ jobs:
339339
steps:
340340
# Checkout the repository
341341
- name: Harden the runner (Audit all outbound calls)
342-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
342+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
343343
with:
344344
egress-policy: audit
345345
- name: Checkout Code
346346
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
347347
- name: Set up Docker Buildx
348-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
348+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
349349
- name: Build local container
350-
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
350+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
351351
with:
352352
tags: openzeppelin-relayer-dev:${{ github.sha }}
353353
push: false

.github/workflows/cla.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- name: Harden the runner (Audit all outbound calls)
25-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
25+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
2626
with:
2727
egress-policy: audit
2828
- name: Checkout Private Repo for Allowlist

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,19 +35,19 @@ jobs:
3535
build-mode: none
3636
steps:
3737
- name: Harden the runner (Audit all outbound calls)
38-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
38+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
3939
with:
4040
egress-policy: audit
4141
- name: Checkout repository
4242
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4.5.4
4343

4444
# Initializes the CodeQL tools for scanning.
4545
- name: Initialize CodeQL
46-
uses: github/codeql-action/init@89a39a4e59826350b863aa6b6252a07ad50cf83e # v3.29.5
46+
uses: github/codeql-action/init@b1bff81932f5cdfc8695c7752dcee935dcd061c8 # v3.29.5
4747
with:
4848
languages: ${{ matrix.language }}
4949
build-mode: ${{ matrix.build-mode }}
5050
- name: Perform CodeQL Analysis
51-
uses: github/codeql-action/analyze@89a39a4e59826350b863aa6b6252a07ad50cf83e # v3.29.5
51+
uses: github/codeql-action/analyze@b1bff81932f5cdfc8695c7752dcee935dcd061c8 # v3.29.5
5252
with:
5353
category: /language:${{matrix.language}}

.github/workflows/integration-tests.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
id-token: write # Required for OIDC authentication with AWS
1515
steps:
1616
- name: Harden the runner (Audit all outbound calls)
17-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
17+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
1818
with:
1919
egress-policy: audit
2020
- name: Checkout Code

.github/workflows/pr-title.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Harden the runner (Audit all outbound calls)
17-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
17+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
1818
with:
1919
egress-policy: audit
2020
- uses: thehanimo/pr-title-checker@7fbfe05602bdd86f926d3fb3bccb6f3aed43bc70 # v1.4.3

.github/workflows/rc.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,10 +23,10 @@ jobs:
2323
runs-on: ubuntu-latest
2424
steps:
2525
- name: Harden the runner (Audit all outbound calls)
26-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
26+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
2727
with:
2828
egress-policy: audit
29-
- uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
29+
- uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
3030
id: gh-app-token
3131
with:
3232
app-id: ${{ vars.GH_APP_ID }}

.github/workflows/release-docker.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
SLACK_CHANNEL: '#oss-releases'
1919
steps:
2020
- name: Harden the runner (Audit all outbound calls)
21-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
21+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
2222
with:
2323
egress-policy: audit
2424
- name: Slack notification
@@ -35,7 +35,7 @@ jobs:
3535
ref: ${{ inputs.tag }}
3636
- name: Docker meta
3737
id: meta
38-
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
38+
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
3939
with:
4040
# list of Docker images to use as base name for tags
4141
images: ${{ env.DOCKERHUB_IMAGE }}
@@ -53,14 +53,14 @@ jobs:
5353
env:
5454
DOCKER_METADATA_SHORT_SHA_LENGTH: 10
5555
- name: Login to Dockerhub
56-
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9
56+
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2
5757
with:
5858
username: ${{ vars.DOCKERHUB_USERNAME }}
5959
password: ${{ secrets.DOCKERHUB_PAT }}
6060
- name: Set Up Docker Buildx
61-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
61+
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
6262
- name: Build Docker image
63-
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
63+
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
6464
id: build
6565
with:
6666
context: .
@@ -74,7 +74,7 @@ jobs:
7474
tags: ${{ steps.meta.outputs.tags }}
7575
labels: ${{ steps.meta.outputs.labels }}
7676
- name: Get github app token
77-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
77+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
7878
id: gh-app-token
7979
with:
8080
app-id: ${{ vars.GH_APP_ID }}

.github/workflows/release-docs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,11 +29,11 @@ jobs:
2929
TAG: ${{ inputs.tag || github.event.inputs.tag }}
3030
steps:
3131
- name: Harden the runner (Audit all outbound calls)
32-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
32+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
3333
with:
3434
egress-policy: audit
3535
- name: Get github app token
36-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
36+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
3737
id: gh-app-token
3838
with:
3939
app-id: ${{ vars.GH_APP_ID }}

.github/workflows/release-please.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,11 @@ jobs:
2626
SLACK_CHANNEL: '#oss-releases'
2727
steps:
2828
- name: Harden the runner (Audit all outbound calls)
29-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
29+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
3030
with:
3131
egress-policy: audit
3232
- name: Get github app token
33-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
33+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
3434
id: gh-app-token
3535
with:
3636
app-id: ${{ vars.GH_APP_ID }}
@@ -119,11 +119,11 @@ jobs:
119119
if: ${{ needs.release-please.outputs.release_created == 'false' && needs.release-please.outputs.pr_created == 'true' }}
120120
steps:
121121
- name: Harden the runner (Audit all outbound calls)
122-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
122+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
123123
with:
124124
egress-policy: audit
125125
- name: Get github app token
126-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
126+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
127127
id: gh-app-token
128128
with:
129129
app-id: ${{ vars.GH_APP_ID }}
@@ -158,7 +158,7 @@ jobs:
158158
fi
159159
- name: Commit cargo update
160160
if: steps.lock-file-commit.outputs.cargo_changed == 'true'
161-
uses: iarekylew00t/verified-bot-commit@b001460501aa4890e4429832db1cdf63e364f162 # v2.1.6
161+
uses: iarekylew00t/verified-bot-commit@b12a1250f23e606d9aa77e54ecba1d788dfa06be # v2.1.8
162162
with:
163163
message: 'chore: Updating lock file'
164164
token: ${{ steps.gh-app-token.outputs.token }}
@@ -174,11 +174,11 @@ jobs:
174174
runs-on: ubuntu-latest
175175
steps:
176176
- name: Harden the runner (Audit all outbound calls)
177-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
177+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
178178
with:
179179
egress-policy: audit
180180
- name: Get github app token
181-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
181+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
182182
id: gh-app-token
183183
with:
184184
app-id: ${{ vars.GH_APP_ID }}
@@ -214,7 +214,7 @@ jobs:
214214
fi
215215
- name: Commit openapi spec file
216216
if: steps.update-openapi-spec-commit.outputs.openapi_changed == 'true'
217-
uses: iarekylew00t/verified-bot-commit@b001460501aa4890e4429832db1cdf63e364f162 # v2.1.6
217+
uses: iarekylew00t/verified-bot-commit@b12a1250f23e606d9aa77e54ecba1d788dfa06be # v2.1.8
218218
with:
219219
message: 'chore: Updating openapi spec file and bumping version'
220220
token: ${{ steps.gh-app-token.outputs.token }}

.github/workflows/release-sbom.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ jobs:
1717
SLACK_CHANNEL: '#oss-releases'
1818
steps:
1919
- name: Harden the runner (Audit all outbound calls)
20-
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
20+
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
2121
with:
2222
egress-policy: audit
2323
- name: Get github app token
24-
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
24+
uses: actions/create-github-app-token@f8d387b68d61c58ab83c6c016672934102569859 # v3.0.0
2525
id: gh-app-token
2626
with:
2727
app-id: ${{ vars.GH_APP_ID }}
@@ -40,7 +40,7 @@ jobs:
4040
message: Starting generating sbom for ${{ github.repository }} with tag ${{ inputs.tag }}......
4141
if: always()
4242
- name: Run SBOM
43-
uses: anchore/sbom-action@17ae1740179002c89186b61233e0f892c3118b11 # v0.23.0
43+
uses: anchore/sbom-action@57aae528053a48a3f6235f2d9461b05fbcb7366d # v0.23.1
4444
with:
4545
upload-artifact-retention: 7
4646
upload-release-assets: false

0 commit comments

Comments
 (0)