Skip to content

chore(deps): bump the ci group with 2 updates#1425

Merged
hilmarf merged 1 commit into
mainfrom
dependabot/github_actions/ci-998bdac0e4
Apr 25, 2025
Merged

chore(deps): bump the ci group with 2 updates#1425
hilmarf merged 1 commit into
mainfrom
dependabot/github_actions/ci-998bdac0e4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 25, 2025

Bumps the ci group with 2 updates: DeterminateSystems/nix-installer-action and anchore/sbom-action.

Updates DeterminateSystems/nix-installer-action from 16 to 17

Release notes

Sourced from DeterminateSystems/nix-installer-action's releases.

v17

What's Changed

New Contributors

Full Changelog: DeterminateSystems/nix-installer-action@v16...v17

Commits
  • 21a5447 Sometimes, two heads are NOT as good as one. (#170)
  • b669a07 Merge pull request #141 from JTKBowers/main
  • 520fb5e Merge remote-tracking branch 'upstream/main'
  • 47a2223 Merge pull request #139 from dpc/dpc/jj-vqymqvyntouw
  • c6e05d5 Merge remote-tracking branch 'upstream/main' into dpc/jj-vqymqvyntouw
  • c56aa51 Regenerate bundle
  • ed5212d Apply suggestions from code review
  • d614ddf Merge pull request #169 from DeterminateSystems/flakehub-login-diagnostics
  • e1cdf19 Show diagnostics for FlakeHub login issues
  • aacc165 Don't blow the limits of summaries, by not printing logs if it blows the limi...
  • Additional commits viewable in compare view

Updates anchore/sbom-action from 0.18.0 to 0.19.0

Release notes

Sourced from anchore/sbom-action's releases.

v0.19.0

Changes in v0.19.0

  • chore(deps): update Syft to v1.23.0 (#521)
  • chore(deps): bump peter-evans/create-pull-request from 7.0.6 to 7.0.8 (#519)
  • chore(deps): bump cross-spawn (#514)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the ci group with 2 updates: [DeterminateSystems/nix-installer-action](https://github.com/determinatesystems/nix-installer-action) and [anchore/sbom-action](https://github.com/anchore/sbom-action).


Updates `DeterminateSystems/nix-installer-action` from 16 to 17
- [Release notes](https://github.com/determinatesystems/nix-installer-action/releases)
- [Commits](DeterminateSystems/nix-installer-action@v16...v17)

Updates `anchore/sbom-action` from 0.18.0 to 0.19.0
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@f325610...9f73021)

---
updated-dependencies:
- dependency-name: DeterminateSystems/nix-installer-action
  dependency-version: '17'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci
- dependency-name: anchore/sbom-action
  dependency-version: 0.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added component/github-actions Changes on GitHub Actions or within `.github/` directory kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. kind/skip-release-notes Pull request will not appear in release notes labels Apr 25, 2025
@dependabot dependabot Bot requested a review from a team as a code owner April 25, 2025 08:57
@github-actions github-actions Bot added the size/xs Extra small label Apr 25, 2025
token: ${{ steps.generate_token.outputs.token }}
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v16
uses: DeterminateSystems/nix-installer-action@v17

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Flake.nix vendorHash updater' step
Uses Step
uses 'DeterminateSystems/nix-installer-action' with ref 'v17', not a pinned commit hash
@hilmarf hilmarf enabled auto-merge (squash) April 25, 2025 09:08
@hilmarf hilmarf merged commit 213298e into main Apr 25, 2025
24 checks passed
@hilmarf hilmarf deleted the dependabot/github_actions/ci-998bdac0e4 branch April 25, 2025 09:09
@ocmbot ocmbot Bot added this to the 2025-Q2 milestone Apr 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component/github-actions Changes on GitHub Actions or within `.github/` directory kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. kind/skip-release-notes Pull request will not appear in release notes size/xs Extra small

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants