Skip to content

Commit 16eb353

Browse files
ci: bump the github-actions group across 1 directory with 6 updates
Bumps the github-actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `6` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `6` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `6` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `6` | | [actions/setup-java](https://github.com/actions/setup-java) | `4` | `5` | Updates `actions/checkout` from 4 to 6 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v6) Updates `actions/setup-python` from 5 to 6 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v6) Updates `actions/upload-artifact` from 4 to 6 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v6) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `actions/setup-node` from 4 to 6 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v6) Updates `actions/setup-java` from 4 to 5 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@v4...v5) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent ee3fe08 commit 16eb353

6 files changed

Lines changed: 29 additions & 29 deletions

File tree

.github/workflows/checkov-bicep.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,10 +18,10 @@ jobs:
1818

1919
steps:
2020
- name: Checkout repository
21-
uses: actions/checkout@v4
21+
uses: actions/checkout@v6
2222

2323
- name: Set up Python
24-
uses: actions/setup-python@v5
24+
uses: actions/setup-python@v6
2525
with:
2626
python-version: '3.x'
2727

@@ -39,13 +39,13 @@ jobs:
3939
--output-file-path reports/checkov-bicep.sarif
4040
4141
- name: Upload SARIF artifact
42-
uses: actions/upload-artifact@v4
42+
uses: actions/upload-artifact@v6
4343
with:
4444
name: checkov-bicep-sarif
4545
path: reports/checkov-bicep.sarif
4646
if-no-files-found: error
4747

4848
- name: Upload SARIF to GitHub Code Scanning
49-
uses: github/codeql-action/upload-sarif@v3
49+
uses: github/codeql-action/upload-sarif@v4
5050
with:
5151
sarif_file: reports/checkov-bicep.sarif

.github/workflows/codeql-db-upload.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,18 +8,18 @@ jobs:
88
runs-on: ubuntu-latest
99
steps:
1010
- name: Checkout juice-shop codebase
11-
uses: actions/checkout@v4
11+
uses: actions/checkout@v6
1212
with:
1313
path: juice-shop
1414

1515
- name: Initialize CodeQL
16-
uses: github/codeql-action/init@v3
16+
uses: github/codeql-action/init@v4
1717
with:
1818
languages: javascript-typescript
1919
source-root: juice-shop
2020

2121
- name: Perform CodeQL Analysis
22-
uses: github/codeql-action/analyze@v3
22+
uses: github/codeql-action/analyze@v4
2323
with:
2424
category: "/language:javascript-typescript"
2525

@@ -29,7 +29,7 @@ jobs:
2929
cp -r $RUNNER_TEMP/codeql_databases/javascript codeql-db
3030
3131
- name: Upload CodeQL database artifact
32-
uses: actions/upload-artifact@v4
32+
uses: actions/upload-artifact@v6
3333
with:
3434
name: codeql-db
3535
path: codeql-db

.github/workflows/codeql-nodegoat-only.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,15 +19,15 @@ jobs:
1919

2020
steps:
2121
- name: Checkout repository
22-
uses: actions/checkout@v4
22+
uses: actions/checkout@v6
2323

2424
- name: Initialize CodeQL with NodeGoat config
25-
uses: github/codeql-action/init@v3
25+
uses: github/codeql-action/init@v4
2626
with:
2727
config-file: ./.github/codeql/codeql-config-nodegoat.yml
2828
languages: javascript-typescript
2929

3030
- name: Perform CodeQL Analysis
31-
uses: github/codeql-action/analyze@v3
31+
uses: github/codeql-action/analyze@v4
3232
with:
3333
category: "/language:javascript-typescript"

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -33,15 +33,15 @@ jobs:
3333

3434
steps:
3535
- name: Checkout repository
36-
uses: actions/checkout@v4
36+
uses: actions/checkout@v6
3737

3838
- name: Initialize CodeQL
39-
uses: github/codeql-action/init@v3
39+
uses: github/codeql-action/init@v4
4040
with:
4141
languages: javascript-typescript
4242
queries: security-extended
4343

4444
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@v3
45+
uses: github/codeql-action/analyze@v4
4646
with:
4747
category: "/language:javascript-typescript"

.github/workflows/dependency-review.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-latest
2121
steps:
2222
- name: Checkout Repository
23-
uses: actions/checkout@v4
23+
uses: actions/checkout@v6
2424

2525
- name: Dependency Review
2626
uses: actions/dependency-review-action@v4
@@ -41,10 +41,10 @@ jobs:
4141
runs-on: ubuntu-latest
4242
steps:
4343
- name: Checkout Repository
44-
uses: actions/checkout@v4
44+
uses: actions/checkout@v6
4545

4646
- name: Setup Node.js
47-
uses: actions/setup-node@v4
47+
uses: actions/setup-node@v6
4848
with:
4949
node-version: '20'
5050

@@ -70,10 +70,10 @@ jobs:
7070
runs-on: ubuntu-latest
7171
steps:
7272
- name: Checkout Repository
73-
uses: actions/checkout@v4
73+
uses: actions/checkout@v6
7474

7575
- name: Setup Java
76-
uses: actions/setup-java@v4
76+
uses: actions/setup-java@v5
7777
with:
7878
distribution: 'temurin'
7979
java-version: '21'

.github/workflows/security-pipeline.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646
runs-on: ubuntu-latest
4747
steps:
4848
- name: Checkout Repository
49-
uses: actions/checkout@v4
49+
uses: actions/checkout@v6
5050
with:
5151
fetch-depth: 0
5252

@@ -71,10 +71,10 @@ jobs:
7171
runs-on: ubuntu-latest
7272
steps:
7373
- name: Checkout Repository
74-
uses: actions/checkout@v4
74+
uses: actions/checkout@v6
7575

7676
- name: Setup Node.js
77-
uses: actions/setup-node@v4
77+
uses: actions/setup-node@v6
7878
with:
7979
node-version: ${{ env.NODE_VERSION }}
8080

@@ -94,7 +94,7 @@ jobs:
9494
continue-on-error: true
9595

9696
- name: Upload Audit Results
97-
uses: actions/upload-artifact@v4
97+
uses: actions/upload-artifact@v6
9898
if: always()
9999
with:
100100
name: npm-audit-results
@@ -111,7 +111,7 @@ jobs:
111111
image: semgrep/semgrep
112112
steps:
113113
- name: Checkout Repository
114-
uses: actions/checkout@v4
114+
uses: actions/checkout@v6
115115

116116
- name: Run Semgrep
117117
run: |
@@ -129,7 +129,7 @@ jobs:
129129
. || true
130130
131131
- name: Upload Semgrep Results
132-
uses: github/codeql-action/upload-sarif@v3
132+
uses: github/codeql-action/upload-sarif@v4
133133
if: always()
134134
with:
135135
sarif_file: semgrep-results.sarif
@@ -143,7 +143,7 @@ jobs:
143143
runs-on: ubuntu-latest
144144
steps:
145145
- name: Checkout Repository
146-
uses: actions/checkout@v4
146+
uses: actions/checkout@v6
147147

148148
- name: Checkov Scan
149149
uses: bridgecrewio/checkov-action@v12
@@ -156,7 +156,7 @@ jobs:
156156
skip_check: CKV_AWS_79,CKV_AWS_18
157157

158158
- name: Upload Checkov Results
159-
uses: github/codeql-action/upload-sarif@v3
159+
uses: github/codeql-action/upload-sarif@v4
160160
if: always()
161161
with:
162162
sarif_file: checkov-results.sarif
@@ -171,7 +171,7 @@ jobs:
171171
if: github.event_name != 'pull_request'
172172
steps:
173173
- name: Checkout Repository
174-
uses: actions/checkout@v4
174+
uses: actions/checkout@v6
175175

176176
- name: Trivy Filesystem Scan
177177
uses: aquasecurity/trivy-action@master
@@ -184,7 +184,7 @@ jobs:
184184
ignore-unfixed: true
185185

186186
- name: Upload Trivy Results
187-
uses: github/codeql-action/upload-sarif@v3
187+
uses: github/codeql-action/upload-sarif@v4
188188
if: always()
189189
with:
190190
sarif_file: trivy-fs-results.sarif

0 commit comments

Comments
 (0)