Skip to content

Commit ae8d4e5

Browse files
chore(deps): update github actions
Signed-off-by: oep-renovate[bot] <212772560+oep-renovate[bot]@users.noreply.github.com>
1 parent db78eb8 commit ae8d4e5

10 files changed

Lines changed: 32 additions & 32 deletions

.github/workflows/codeql.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
- language: python
2727
steps:
2828
- name: Harden the runner (audit all outbound calls)
29-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
29+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3030
with:
3131
disable-sudo: true
3232
disable-telemetry: true
@@ -38,19 +38,19 @@ jobs:
3838
release-assets.githubusercontent.com:443
3939
4040
- name: Checkout code
41-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
41+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4242
with:
4343
persist-credentials: false
4444

4545
# Initializes the CodeQL tools for scanning.
4646
- name: Initialize CodeQL
47-
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
47+
uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
4848
with:
4949
languages: ${{ matrix.language }}
5050
build-mode: none
5151
queries: security-extended
5252

5353
- name: Perform CodeQL Analysis
54-
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
54+
uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
5555
with:
5656
category: "/language:${{matrix.language}}"

.github/workflows/collect-sbom-library.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,11 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Harden the runner (audit all outbound calls)
17-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
17+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1818
with:
1919
egress-policy: audit
2020

21-
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
21+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
2222
with:
2323
persist-credentials: false
2424

.github/workflows/docs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
contents: write
1616
steps:
1717
- name: Harden the runner (audit all outbound calls)
18-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
18+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1919
with:
2020
disable-sudo: true
2121
disable-telemetry: true
@@ -28,7 +28,7 @@ jobs:
2828
releases.astral.sh:443
2929
3030
- name: Checkout code
31-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
31+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
3232
with:
3333
persist-credentials: false
3434

.github/workflows/pr-labeler.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Harden the runner (audit all outbound calls)
21-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
21+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2222
with:
2323
disable-sudo: true
2424
disable-telemetry: true

.github/workflows/pre_commit.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Harden the runner
21-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
21+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2222
with:
2323
disable-sudo: true
2424
disable-telemetry: true
@@ -34,7 +34,7 @@ jobs:
3434
3535
- &checkout
3636
name: Checkout code
37-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
37+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
3838
with:
3939
persist-credentials: false
4040

@@ -75,7 +75,7 @@ jobs:
7575
runs-on: ${{ matrix.os }}
7676
steps:
7777
- name: Harden the runner
78-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
78+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
7979
with:
8080
disable-sudo: true
8181
disable-telemetry: true
@@ -126,7 +126,7 @@ jobs:
126126
runs-on: ${{ matrix.os }}
127127
steps:
128128
- name: Harden the runner
129-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
129+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
130130
with:
131131
disable-sudo: true
132132
disable-telemetry: true
@@ -181,7 +181,7 @@ jobs:
181181
runs-on: ${{ matrix.os }}
182182
steps:
183183
- name: Harden the runner
184-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
184+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
185185
with:
186186
disable-sudo: true
187187
disable-telemetry: true

.github/workflows/publish.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,12 @@ jobs:
1414
steps:
1515
- &harden-runner
1616
name: Harden the runner (audit all outbound calls)
17-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
17+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
1818
with:
1919
egress-policy: audit
2020

2121
- name: Checkout code
22-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
22+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
2323
with:
2424
persist-credentials: false
2525

.github/workflows/renovate-config-validator.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ jobs:
3030
contents: read
3131
steps:
3232
- name: Harden the runner
33-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
33+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3434
with:
3535
disable-sudo: true
3636
disable-telemetry: true
@@ -45,14 +45,14 @@ jobs:
4545
releases.astral.sh:443
4646
4747
- name: Checkout code
48-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
48+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4949
with:
5050
persist-credentials: false
5151

5252
- name: Validate configuration
5353
run: |
5454
# renovate: datasource=docker
55-
export RENOVATE_IMAGE=ghcr.io/renovatebot/renovate:43.160.2@sha256:e977df2dbd4b978cc301a0b4d8e0162ec4ce08bd205422c02c4cf55f52b67336
55+
export RENOVATE_IMAGE=ghcr.io/renovatebot/renovate:43.209.1@sha256:1ac704319b8aa45a412c35d287b7ca1afeabf3d25f042eb22e4c267faf86decc
5656
docker run --rm --entrypoint "renovate-config-validator" \
5757
-v "${{ github.workspace }}/.github/renovate.json5":"/renovate.json5" \
5858
${RENOVATE_IMAGE} "/renovate.json5"

.github/workflows/renovate.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ jobs:
5858

5959
steps:
6060
- name: Harden the runner (audit all outbound calls)
61-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
61+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
6262
with:
6363
disable-sudo: true
6464
disable-telemetry: true
@@ -73,13 +73,13 @@ jobs:
7373
release-assets.githubusercontent.com:443
7474
7575
- name: Checkout code
76-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
76+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
7777
with:
7878
persist-credentials: false
7979

8080
- name: Get token
8181
id: get-github-app-token
82-
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
82+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
8383
with:
8484
app-id: ${{ secrets.RENOVATE_APP_ID }}
8585
private-key: ${{ secrets.RENOVATE_APP_PEM }}
@@ -88,7 +88,7 @@ jobs:
8888
uses: renovatebot/github-action@693b9ef15eec82123529a37c782242f091365961 # v46.1.14
8989
with:
9090
# renovate: datasource=github-releases depName=renovatebot/renovate
91-
renovate-version: 43.160.7
91+
renovate-version: 43.209.1
9292
configurationFile: .github/renovate.json5
9393
token: "${{ steps.get-github-app-token.outputs.token }}"
9494
env:

.github/workflows/scorecards.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323

2424
steps:
2525
- name: Harden the runner (audit all outbound calls)
26-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
26+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
2727
with:
2828
disable-sudo: true
2929
disable-telemetry: true
@@ -42,7 +42,7 @@ jobs:
4242
www.bestpractices.dev:443
4343
4444
- name: Checkout code
45-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
45+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
4646
with:
4747
persist-credentials: false
4848

@@ -55,6 +55,6 @@ jobs:
5555

5656
# Upload the results to GitHub's code scanning dashboard
5757
- name: Upload to code-scanning
58-
uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
58+
uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1
5959
with:
6060
sarif_file: results.sarif

.github/workflows/security-scan.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
security-events: write # Needed to upload the results to code-scanning dashboard
3232
steps:
3333
- name: Harden the runner
34-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
34+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
3535
with:
3636
disable-sudo: true
3737
disable-telemetry: true
@@ -46,7 +46,7 @@ jobs:
4646
4747
- &checkout
4848
name: Checkout code
49-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
49+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
5050
with:
5151
persist-credentials: false
5252

@@ -71,7 +71,7 @@ jobs:
7171
security-events: write # Needed to upload the results to code-scanning dashboard
7272
steps:
7373
- name: Harden the runner
74-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
74+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
7575
with:
7676
disable-sudo: true
7777
disable-telemetry: true
@@ -117,7 +117,7 @@ jobs:
117117
security-events: write # Needed to upload the results to code-scanning dashboard
118118
steps:
119119
- name: Harden the runner
120-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
120+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
121121
with:
122122
disable-sudo: true
123123
disable-telemetry: true
@@ -151,7 +151,7 @@ jobs:
151151
security-events: write # Needed to upload the results to code-scanning dashboard
152152
steps:
153153
- name: Harden the runner
154-
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
154+
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
155155
with:
156156
disable-sudo: true
157157
disable-telemetry: true
@@ -165,7 +165,7 @@ jobs:
165165
semgrep.dev:443
166166
167167
- name: Checkout code
168-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
168+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
169169
with:
170170
persist-credentials: false
171171
fetch-depth: 0 # needed to get the list of changed files for semgrep

0 commit comments

Comments
 (0)