Skip to content

Commit 615906a

Browse files
chore(deps): update github actions
Signed-off-by: oep-renovate[bot] <212772560+oep-renovate[bot]@users.noreply.github.com>
1 parent db78eb8 commit 615906a

10 files changed

Lines changed: 36 additions & 36 deletions

.github/workflows/codeql.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
- language: python
2727
steps:
2828
- name: Harden the runner (audit all outbound calls)
29-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
29+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3030
with:
3131
disable-sudo: true
3232
disable-telemetry: true
@@ -38,19 +38,19 @@ jobs:
3838
release-assets.githubusercontent.com:443
3939
4040
- name: Checkout code
41-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
41+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4242
with:
4343
persist-credentials: false
4444

4545
# Initializes the CodeQL tools for scanning.
4646
- name: Initialize CodeQL
47-
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
47+
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
4848
with:
4949
languages: ${{ matrix.language }}
5050
build-mode: none
5151
queries: security-extended
5252

5353
- name: Perform CodeQL Analysis
54-
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
54+
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
5555
with:
5656
category: "/language:${{matrix.language}}"

.github/workflows/collect-sbom-library.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,11 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Harden the runner (audit all outbound calls)
17-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
17+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1818
with:
1919
egress-policy: audit
2020

21-
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
21+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
2222
with:
2323
persist-credentials: false
2424

.github/workflows/docs.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
contents: write
1616
steps:
1717
- name: Harden the runner (audit all outbound calls)
18-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
18+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1919
with:
2020
disable-sudo: true
2121
disable-telemetry: true
@@ -28,7 +28,7 @@ jobs:
2828
releases.astral.sh:443
2929
3030
- name: Checkout code
31-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
31+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
3232
with:
3333
persist-credentials: false
3434

@@ -38,7 +38,7 @@ jobs:
3838
python-version-file: ".python-version"
3939

4040
- name: Install uv
41-
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
41+
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
4242
with:
4343
version: "0.11.13"
4444

.github/workflows/pr-labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Harden the runner (audit all outbound calls)
21-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
21+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2222
with:
2323
disable-sudo: true
2424
disable-telemetry: true

.github/workflows/pre_commit.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Harden the runner
21-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
21+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2222
with:
2323
disable-sudo: true
2424
disable-telemetry: true
@@ -34,7 +34,7 @@ jobs:
3434
3535
- &checkout
3636
name: Checkout code
37-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
37+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
3838
with:
3939
persist-credentials: false
4040

@@ -44,7 +44,7 @@ jobs:
4444
python-version-file: ".python-version"
4545

4646
- name: Install uv
47-
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
47+
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
4848
with:
4949
enable-cache: false
5050
version: "0.11.13"
@@ -75,7 +75,7 @@ jobs:
7575
runs-on: ${{ matrix.os }}
7676
steps:
7777
- name: Harden the runner
78-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
78+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
7979
with:
8080
disable-sudo: true
8181
disable-telemetry: true
@@ -94,7 +94,7 @@ jobs:
9494

9595
- &matrix-setup-uv
9696
name: Install uv
97-
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
97+
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
9898
with:
9999
enable-cache: false
100100
python-version: ${{ matrix.python-version }}
@@ -126,7 +126,7 @@ jobs:
126126
runs-on: ${{ matrix.os }}
127127
steps:
128128
- name: Harden the runner
129-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
129+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
130130
with:
131131
disable-sudo: true
132132
disable-telemetry: true
@@ -181,7 +181,7 @@ jobs:
181181
runs-on: ${{ matrix.os }}
182182
steps:
183183
- name: Harden the runner
184-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
184+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
185185
with:
186186
disable-sudo: true
187187
disable-telemetry: true

.github/workflows/publish.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,12 @@ jobs:
1414
steps:
1515
- &harden-runner
1616
name: Harden the runner (audit all outbound calls)
17-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
17+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1818
with:
1919
egress-policy: audit
2020

2121
- name: Checkout code
22-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
22+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
2323
with:
2424
persist-credentials: false
2525

@@ -29,7 +29,7 @@ jobs:
2929
python-version-file: ".python-version"
3030

3131
- name: Install uv
32-
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
32+
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
3333

3434
- name: Install pypa/build
3535
run: uv --directory model_api sync --locked

.github/workflows/renovate-config-validator.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ jobs:
3030
contents: read
3131
steps:
3232
- name: Harden the runner
33-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
33+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3434
with:
3535
disable-sudo: true
3636
disable-telemetry: true
@@ -45,14 +45,14 @@ jobs:
4545
releases.astral.sh:443
4646
4747
- name: Checkout code
48-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
48+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4949
with:
5050
persist-credentials: false
5151

5252
- name: Validate configuration
5353
run: |
5454
# renovate: datasource=docker
55-
export RENOVATE_IMAGE=ghcr.io/renovatebot/renovate:43.160.2@sha256:e977df2dbd4b978cc301a0b4d8e0162ec4ce08bd205422c02c4cf55f52b67336
55+
export RENOVATE_IMAGE=ghcr.io/renovatebot/renovate:43.212.4@sha256:7ddbf899a371dec16a37c22e233a6b981c4d3fbfe3075dcf22a4f1ba22fe55a9
5656
docker run --rm --entrypoint "renovate-config-validator" \
5757
-v "${{ github.workspace }}/.github/renovate.json5":"/renovate.json5" \
5858
${RENOVATE_IMAGE} "/renovate.json5"

.github/workflows/renovate.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ jobs:
5858

5959
steps:
6060
- name: Harden the runner (audit all outbound calls)
61-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
61+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
6262
with:
6363
disable-sudo: true
6464
disable-telemetry: true
@@ -73,13 +73,13 @@ jobs:
7373
release-assets.githubusercontent.com:443
7474
7575
- name: Checkout code
76-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
76+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
7777
with:
7878
persist-credentials: false
7979

8080
- name: Get token
8181
id: get-github-app-token
82-
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
82+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
8383
with:
8484
app-id: ${{ secrets.RENOVATE_APP_ID }}
8585
private-key: ${{ secrets.RENOVATE_APP_PEM }}
@@ -88,7 +88,7 @@ jobs:
8888
uses: renovatebot/github-action@693b9ef15eec82123529a37c782242f091365961 # v46.1.14
8989
with:
9090
# renovate: datasource=github-releases depName=renovatebot/renovate
91-
renovate-version: 43.160.7
91+
renovate-version: 43.212.4
9292
configurationFile: .github/renovate.json5
9393
token: "${{ steps.get-github-app-token.outputs.token }}"
9494
env:

.github/workflows/scorecards.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323

2424
steps:
2525
- name: Harden the runner (audit all outbound calls)
26-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
26+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2727
with:
2828
disable-sudo: true
2929
disable-telemetry: true
@@ -42,7 +42,7 @@ jobs:
4242
www.bestpractices.dev:443
4343
4444
- name: Checkout code
45-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
45+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4646
with:
4747
persist-credentials: false
4848

@@ -55,6 +55,6 @@ jobs:
5555

5656
# Upload the results to GitHub's code scanning dashboard
5757
- name: Upload to code-scanning
58-
uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
58+
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
5959
with:
6060
sarif_file: results.sarif

.github/workflows/security-scan.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
security-events: write # Needed to upload the results to code-scanning dashboard
3232
steps:
3333
- name: Harden the runner
34-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
34+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3535
with:
3636
disable-sudo: true
3737
disable-telemetry: true
@@ -46,7 +46,7 @@ jobs:
4646
4747
- &checkout
4848
name: Checkout code
49-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
49+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
5050
with:
5151
persist-credentials: false
5252

@@ -71,7 +71,7 @@ jobs:
7171
security-events: write # Needed to upload the results to code-scanning dashboard
7272
steps:
7373
- name: Harden the runner
74-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
74+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
7575
with:
7676
disable-sudo: true
7777
disable-telemetry: true
@@ -117,7 +117,7 @@ jobs:
117117
security-events: write # Needed to upload the results to code-scanning dashboard
118118
steps:
119119
- name: Harden the runner
120-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
120+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
121121
with:
122122
disable-sudo: true
123123
disable-telemetry: true
@@ -151,7 +151,7 @@ jobs:
151151
security-events: write # Needed to upload the results to code-scanning dashboard
152152
steps:
153153
- name: Harden the runner
154-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
154+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
155155
with:
156156
disable-sudo: true
157157
disable-telemetry: true
@@ -165,7 +165,7 @@ jobs:
165165
semgrep.dev:443
166166
167167
- name: Checkout code
168-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
168+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
169169
with:
170170
persist-credentials: false
171171
fetch-depth: 0 # needed to get the list of changed files for semgrep

0 commit comments

Comments
 (0)