- Notifications
You must be signed in to change notification settings - Fork913
Commitf6dd50a
authored
ci: bump the github-actions group with 4 updates (#18289)
Bumps the github-actions group with 4 updates:[crate-ci/typos](https://github.com/crate-ci/typos),[chromaui/action](https://github.com/chromaui/action),[github/codeql-action](https://github.com/github/codeql-action) and[aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).Updates `crate-ci/typos` from 1.32.0 to 1.33.1<details><summary>Release notes</summary><p><em>Sourced from <ahref="https://github.com/crate-ci/typos/releases">crate-ci/typos'sreleases</a>.</em></p><blockquote><h2>v1.33.1</h2><h2>[1.33.1] - 2025-06-02</h2><h3>Fixes</h3><ul><li><em>(dict)</em> Don't correct <code>wasn't</code> to<code>wasm't</code></li></ul><h2>v1.33.0</h2><h2>[1.33.0] - 2025-06-02</h2><h3>Features</h3><ul><li>Updated the dictionary with the <ahref="https://redirect.github.com/crate-ci/typos/issues/1290">May2025</a> changes</li></ul></blockquote></details><details><summary>Changelog</summary><p><em>Sourced from <ahref="https://github.com/crate-ci/typos/blob/master/CHANGELOG.md">crate-ci/typos'schangelog</a>.</em></p><blockquote><h1>Change Log</h1><p>All notable changes to this project will be documented in thisfile.</p><p>The format is based on <a href="http://keepachangelog.com/">Keep aChangelog</a>and this project adheres to <a href="http://semver.org/">SemanticVersioning</a>.</p><!-- raw HTML omitted --><h2>[Unreleased] - ReleaseDate</h2><h2>[1.33.1] - 2025-06-02</h2><h3>Fixes</h3><ul><li><em>(dict)</em> Don't correct <code>wasn't</code> to<code>wasm't</code></li></ul><h2>[1.33.0] - 2025-06-02</h2><h3>Features</h3><ul><li>Updated the dictionary with the <ahref="https://redirect.github.com/crate-ci/typos/issues/1290">May2025</a> changes</li></ul><h2>[1.32.0] - 2025-05-02</h2><h3>Features</h3><ul><li>Updated the dictionary with the <ahref="https://redirect.github.com/crate-ci/typos/issues/1264">April2025</a> changes</li></ul><h2>[1.31.2] - 2025-04-28</h2><h3>Fixes</h3><ul><li><em>(exclusion)</em> Don't confused emails as base64</li><li><em>(dict)</em> Correct <code>contamint</code> to<code>contaminant</code>, not <code>contaminat</code></li><li><em>(dict)</em> Correct <code>contamints</code> to<code>contaminants</code>, not <code>contaminats</code></li></ul><h3>Performance</h3><ul><li>Improve tokenization performance</li></ul><h2>[1.31.1] - 2025-03-31</h2><h3>Fixes</h3><ul><li><em>(dict)</em> Also correct <code>typ</code> to<code>type</code></li></ul><h2>[1.31.0] - 2025-03-28</h2><h3>Features</h3><ul><li>Updated the dictionary with the <ahref="https://redirect.github.com/crate-ci/typos/issues/1248">March2025</a> changes</li></ul><!-- raw HTML omitted --></blockquote><p>... (truncated)</p></details><details><summary>Commits</summary><ul><li><ahref="https://github.com/crate-ci/typos/commit/b1ae8d918b6e85bd611117d3d9a3be4f903ee5e4"><code>b1ae8d9</code></a>chore: Release</li><li><ahref="https://github.com/crate-ci/typos/commit/6c5d17de8e16370e7e1d8dd41c8dc0a7f22ea981"><code>6c5d17d</code></a>docs: Update changelog</li><li><ahref="https://github.com/crate-ci/typos/commit/0a237ba81a86b72399a05f3441449ddeab9faf16"><code>0a237ba</code></a>Merge pull request <ahref="https://redirect.github.com/crate-ci/typos/issues/1311">#1311</a>from epage/wasn</li><li><ahref="https://github.com/crate-ci/typos/commit/79920cf06905dd147d4e784ae17136d98c211083"><code>79920cf</code></a>fix(dict): Don't correct <code>wasn't</code></li><li><ahref="https://github.com/crate-ci/typos/commit/e99b2b47d9910ae09f6e828594c33ab3e0936491"><code>e99b2b4</code></a>chore: Release</li><li><ahref="https://github.com/crate-ci/typos/commit/2afc152754dd1bf58997ad87bcc84f7797bb52ab"><code>2afc152</code></a>chore: Release</li><li><ahref="https://github.com/crate-ci/typos/commit/544a19b4ae1a0814151fd081008bb9305abccdfc"><code>544a19b</code></a>docs: Update changelog</li><li><ahref="https://github.com/crate-ci/typos/commit/2e0ca28a9540837425705660401059467b721ab9"><code>2e0ca28</code></a>Merge pull request <ahref="https://redirect.github.com/crate-ci/typos/issues/1310">#1310</a>from epage/may</li><li><ahref="https://github.com/crate-ci/typos/commit/94eb4e7b407daa7967ca1a23c72902898ab599f6"><code>94eb4e7</code></a>feat(dict): May 2025 updates</li><li><ahref="https://github.com/crate-ci/typos/commit/a4cce4ca70447aa8b294fc0eaada68193eeec1fa"><code>a4cce4c</code></a>Merge pull request <ahref="https://redirect.github.com/crate-ci/typos/issues/1308">#1308</a>from crate-ci/renovate/schemars-0.x</li><li>Additional commits viewable in <ahref="https://github.com/crate-ci/typos/compare/0f0ccba9ed1df83948f0c15026e4f5ccfce46109...b1ae8d918b6e85bd611117d3d9a3be4f903ee5e4">compareview</a></li></ul></details><br />Updates `chromaui/action` from 12.0.0 to 12.1.1<details><summary>Commits</summary><ul><li><ahref="https://github.com/chromaui/action/commit/8536229ee904071f8edce292596f6dbe0da96b9b"><code>8536229</code></a>v12.1.1</li><li><ahref="https://github.com/chromaui/action/commit/39708fe33252ca58c08b791fef95536ed2a1b976"><code>39708fe</code></a>v12.1.0</li><li>See full diff in <ahref="https://github.com/chromaui/action/compare/d7afd50124cf4f337bcd943e7f45cfa85a5e4476...8536229ee904071f8edce292596f6dbe0da96b9b">compareview</a></li></ul></details><br />Updates `github/codeql-action` from 3.28.18 to 3.28.19<details><summary>Release notes</summary><p><em>Sourced from <ahref="https://github.com/github/codeql-action/releases">github/codeql-action'sreleases</a>.</em></p><blockquote><h2>v3.28.19</h2><h1>CodeQL Action Changelog</h1><p>See the <ahref="https://github.com/github/codeql-action/releases">releasespage</a> for the relevant changes to the CodeQL CLI and languagepacks.</p><h2>3.28.19 - 03 Jun 2025</h2><ul><li>The CodeQL Action no longer includes its own copy of the extractorfor the <code>actions</code> language, which is currently in publicpreview.The <code>actions</code> extractor has been included in the CodeQL CLIsince v2.20.6. If your workflow has enabled the <code>actions</code>language <em>and</em> you have pinnedyour <code>tools:</code> property to a specific version of the CodeQLCLI earlier than v2.20.6, you will need to update to at least CodeQLv2.20.6 or disable<code>actions</code> analysis.</li><li>Update default CodeQL bundle version to 2.21.4. <ahref="https://redirect.github.com/github/codeql-action/pull/2910">#2910</a></li></ul><p>See the full <ahref="https://github.com/github/codeql-action/blob/v3.28.19/CHANGELOG.md">CHANGELOG.md</a>for more information.</p></blockquote></details><details><summary>Changelog</summary><p><em>Sourced from <ahref="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action'schangelog</a>.</em></p><blockquote><h1>CodeQL Action Changelog</h1><p>See the <ahref="https://github.com/github/codeql-action/releases">releasespage</a> for the relevant changes to the CodeQL CLI and languagepacks.</p><h2>[UNRELEASED]</h2><p>No user facing changes.</p><h2>3.28.19 - 03 Jun 2025</h2><ul><li>The CodeQL Action no longer includes its own copy of the extractorfor the <code>actions</code> language, which is currently in publicpreview.The <code>actions</code> extractor has been included in the CodeQL CLIsince v2.20.6. If your workflow has enabled the <code>actions</code>language <em>and</em> you have pinnedyour <code>tools:</code> property to a specific version of the CodeQLCLI earlier than v2.20.6, you will need to update to at least CodeQLv2.20.6 or disable<code>actions</code> analysis.</li><li>Update default CodeQL bundle version to 2.21.4. <ahref="https://redirect.github.com/github/codeql-action/pull/2910">#2910</a></li></ul><h2>3.28.18 - 16 May 2025</h2><ul><li>Update default CodeQL bundle version to 2.21.3. <ahref="https://redirect.github.com/github/codeql-action/pull/2893">#2893</a></li><li>Skip validating SARIF produced by CodeQL for improved performance.<ahref="https://redirect.github.com/github/codeql-action/pull/2894">#2894</a></li><li>The number of threads and amount of RAM used by CodeQL can now beset via the <code>CODEQL_THREADS</code> and <code>CODEQL_RAM</code>runner environment variables. If set, these environment variablesoverride the <code>threads</code> and <code>ram</code> inputsrespectively. <ahref="https://redirect.github.com/github/codeql-action/pull/2891">#2891</a></li></ul><h2>3.28.17 - 02 May 2025</h2><ul><li>Update default CodeQL bundle version to 2.21.2. <ahref="https://redirect.github.com/github/codeql-action/pull/2872">#2872</a></li></ul><h2>3.28.16 - 23 Apr 2025</h2><ul><li>Update default CodeQL bundle version to 2.21.1. <ahref="https://redirect.github.com/github/codeql-action/pull/2863">#2863</a></li></ul><h2>3.28.15 - 07 Apr 2025</h2><ul><li>Fix bug where the action would fail if it tried to produce a debugartifact with more than 65535 files. <ahref="https://redirect.github.com/github/codeql-action/pull/2842">#2842</a></li></ul><h2>3.28.14 - 07 Apr 2025</h2><ul><li>Update default CodeQL bundle version to 2.21.0. <ahref="https://redirect.github.com/github/codeql-action/pull/2838">#2838</a></li></ul><h2>3.28.13 - 24 Mar 2025</h2><p>No user facing changes.</p><h2>3.28.12 - 19 Mar 2025</h2><ul><li>Dependency caching should now cache more dependencies for Java<code>build-mode: none</code> extractions. This should speed upworkflows and avoid inconsistent alerts in some cases.</li><li>Update default CodeQL bundle version to 2.20.7. <ahref="https://redirect.github.com/github/codeql-action/pull/2810">#2810</a></li></ul><h2>3.28.11 - 07 Mar 2025</h2><ul><li>Update default CodeQL bundle version to 2.20.6. <ahref="https://redirect.github.com/github/codeql-action/pull/2793">#2793</a></li></ul><!-- raw HTML omitted --></blockquote><p>... (truncated)</p></details><details><summary>Commits</summary><ul><li><ahref="https://github.com/github/codeql-action/commit/fca7ace96b7d713c7035871441bd52efbe39e27e"><code>fca7ace</code></a>Merge pull request <ahref="https://redirect.github.com/github/codeql-action/issues/2918">#2918</a>from github/update-v3.28.19-4a00331d4</li><li><ahref="https://github.com/github/codeql-action/commit/1dcd2bebbb31e92a94fd28ed1885b2e6331afdd3"><code>1dcd2be</code></a>Update changelog for v3.28.19</li><li><ahref="https://github.com/github/codeql-action/commit/4a00331d4ecf79a214751520faf8e540e60c7567"><code>4a00331</code></a>Merge pull request <ahref="https://redirect.github.com/github/codeql-action/issues/2910">#2910</a>from github/update-bundle/codeql-bundle-v2.21.4</li><li><ahref="https://github.com/github/codeql-action/commit/c0a821da119108a26c647de84b1e6a857fda1279"><code>c0a821d</code></a>Add changelog note</li><li><ahref="https://github.com/github/codeql-action/commit/d6216866b42d1cb95b8942447efe91161628ccfd"><code>d621686</code></a>Update default bundle to codeql-bundle-v2.21.4</li><li><ahref="https://github.com/github/codeql-action/commit/dc138d4f519ecc58013d8fcef428272e2436cafd"><code>dc138d4</code></a>Merge pull request <ahref="https://redirect.github.com/github/codeql-action/issues/2913">#2913</a>from github/henrymercer/win-2019-deprecated</li><li><ahref="https://github.com/github/codeql-action/commit/3201e46e2615110190ca536fbf1280ccc7f3a247"><code>3201e46</code></a>Stop running CI on <code>windows-2019</code></li><li><ahref="https://github.com/github/codeql-action/commit/7fd62151d9daff11d4b981415ffb365dcd93f75a"><code>7fd6215</code></a>Merge pull request <ahref="https://redirect.github.com/github/codeql-action/issues/2911">#2911</a>from github/update-supported-enterprise-server-versions</li><li><ahref="https://github.com/github/codeql-action/commit/31eae5e821e97c8b2903ca297cc8894bd9b609fb"><code>31eae5e</code></a>Update supported GitHub Enterprise Server versions</li><li><ahref="https://github.com/github/codeql-action/commit/bc02a25f6449997c5e9d5a368879b28f56ae19a1"><code>bc02a25</code></a>Merge pull request <ahref="https://redirect.github.com/github/codeql-action/issues/2908">#2908</a>from github/henrymercer/dependabot</li><li>Additional commits viewable in <ahref="https://github.com/github/codeql-action/compare/ff0a06e83cb2de871e5a09832bc6a81e7276941f...fca7ace96b7d713c7035871441bd52efbe39e27e">compareview</a></li></ul></details><br />Updates `aquasecurity/trivy-action` from 0.30.0 to 0.31.0<details><summary>Release notes</summary><p><em>Sourced from <ahref="https://github.com/aquasecurity/trivy-action/releases">aquasecurity/trivy-action'sreleases</a>.</em></p><blockquote><h2>v0.31.0</h2><h2>What's Changed</h2><ul><li>docs: add info that <code>unix:/</code> prefix is required for<code>docker-host</code> input by <ahref="https://github.com/DmitriyLewen"><code>@DmitriyLewen</code></a>in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/455">aquasecurity/trivy-action#455</a></li><li>Fix Trivy action inputs leaking between invocations (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/422">#422</a>)by <a href="https://github.com/rvesse"><code>@rvesse</code></a> in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/454">aquasecurity/trivy-action#454</a></li><li>Pin aquasecuriy/setup-trivy to hash instead of tag by <ahref="https://github.com/lhotari"><code>@lhotari</code></a> in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/456">aquasecurity/trivy-action#456</a></li><li>Bump Trivy version to fix GitHub actions by <ahref="https://github.com/maximmasiutin"><code>@maximmasiutin</code></a>in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/460">aquasecurity/trivy-action#460</a></li><li>refactor: use ubuntu 24.04 in example code by <ahref="https://github.com/simar7"><code>@simar7</code></a> in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/465">aquasecurity/trivy-action#465</a></li><li>ci: fix workflow to bump Trivy by <ahref="https://github.com/nikpivkin"><code>@nikpivkin</code></a> in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/466">aquasecurity/trivy-action#466</a></li><li>chore(deps): Update trivy to v0.63.0 by <ahref="https://github.com/aqua-bot"><code>@aqua-bot</code></a> in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/467">aquasecurity/trivy-action#467</a></li></ul><h2>New Contributors</h2><ul><li><a href="https://github.com/lhotari"><code>@lhotari</code></a> madetheir first contribution in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/456">aquasecurity/trivy-action#456</a></li><li><ahref="https://github.com/maximmasiutin"><code>@maximmasiutin</code></a>made their first contribution in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/460">aquasecurity/trivy-action#460</a></li><li><a href="https://github.com/aqua-bot"><code>@aqua-bot</code></a>made their first contribution in <ahref="https://redirect.github.com/aquasecurity/trivy-action/pull/467">aquasecurity/trivy-action#467</a></li></ul><p><strong>Full Changelog</strong>: <ahref="https://github.com/aquasecurity/trivy-action/compare/0.30.0...0.31.0">https://github.com/aquasecurity/trivy-action/compare/0.30.0...0.31.0</a></p></blockquote></details><details><summary>Commits</summary><ul><li><ahref="https://github.com/aquasecurity/trivy-action/commit/76071ef0d7ec797419534a183b498b4d6366cf37"><code>76071ef</code></a>chore(deps): Update trivy to v0.63.0 (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/467">#467</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/4844d823d3541b70e147062249823a5cf735b7b8"><code>4844d82</code></a>ci: fix workflow to bump Trivy (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/466">#466</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/26d71e622b84d103f86fb33a5a42c558e11f4ae0"><code>26d71e6</code></a>refactor: use ubuntu 24.04 (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/465">#465</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/b3dafe507ffa004210975439a1e6156b8ebb3f50"><code>b3dafe5</code></a>Bump Trivy version to fix GitHub actions (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/460">#460</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/99baf0d8b4e787c3cfd7b602664c8ce60a43cd38"><code>99baf0d</code></a>Pin aquasecuriy/setup-trivy to hash instead of tag (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/456">#456</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/7aca5acc9500b463826cc47a47a65ad7d404b045"><code>7aca5ac</code></a>fix: Trivy action inputs leaking between invocations (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/422">#422</a>)(<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/454">#454</a>)</li><li><ahref="https://github.com/aquasecurity/trivy-action/commit/ea27ac12e15e065601133e2e439657937385d5a8"><code>ea27ac1</code></a>docs: add info that <code>unix:/</code> prefix is required (<ahref="https://redirect.github.com/aquasecurity/trivy-action/issues/455">#455</a>)</li><li>See full diff in <ahref="https://github.com/aquasecurity/trivy-action/compare/6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5...76071ef0d7ec797419534a183b498b4d6366cf37">compareview</a></li></ul></details><br /><details><summary>Most Recent Ignore Conditions Applied to This PullRequest</summary>| Dependency Name | Ignore Conditions || --- | --- || crate-ci/typos | [>= 1.30.a, < 1.31] |</details>Dependabot will resolve any conflicts with this PR as long as you don'talter it yourself. You can also trigger a rebase manually by commenting`@dependabot rebase`.[//]: # (dependabot-automerge-start)[//]: # (dependabot-automerge-end)---<details><summary>Dependabot commands and options</summary><br />You can trigger Dependabot actions by commenting on this PR:- `@dependabot rebase` will rebase this PR- `@dependabot recreate` will recreate this PR, overwriting any editsthat have been made to it- `@dependabot merge` will merge this PR after your CI passes on it- `@dependabot squash and merge` will squash and merge this PR afteryour CI passes on it- `@dependabot cancel merge` will cancel a previously requested mergeand block automerging- `@dependabot reopen` will reopen this PR if it is closed- `@dependabot close` will close this PR and stop Dependabot recreatingit. You can achieve the same result by closing it manually- `@dependabot show <dependency name> ignore conditions` will show allof the ignore conditions of the specified dependency- `@dependabot ignore <dependency name> major version` will close thisgroup update PR and stop Dependabot creating any more for the specificdependency's major version (unless you unignore this specificdependency's major version or upgrade to it yourself)- `@dependabot ignore <dependency name> minor version` will close thisgroup update PR and stop Dependabot creating any more for the specificdependency's minor version (unless you unignore this specificdependency's minor version or upgrade to it yourself)- `@dependabot ignore <dependency name>` will close this group update PRand stop Dependabot creating any more for the specific dependency(unless you unignore this specific dependency or upgrade to it yourself)- `@dependabot unignore <dependency name>` will remove all of the ignoreconditions of the specified dependency- `@dependabot unignore <dependency name> <ignore condition>` willremove the ignore condition of the specified dependency and ignoreconditions</details>Signed-off-by: dependabot[bot] <support@github.com>Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent3378b27 commitf6dd50a
3 files changed
+8
-8
lines changedLines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
187 | 187 |
| |
188 | 188 |
| |
189 | 189 |
| |
190 |
| - | |
| 190 | + | |
191 | 191 |
| |
192 | 192 |
| |
193 | 193 |
| |
| |||
902 | 902 |
| |
903 | 903 |
| |
904 | 904 |
| |
905 |
| - | |
| 905 | + | |
906 | 906 |
| |
907 | 907 |
| |
908 | 908 |
| |
| |||
934 | 934 |
| |
935 | 935 |
| |
936 | 936 |
| |
937 |
| - | |
| 937 | + | |
938 | 938 |
| |
939 | 939 |
| |
940 | 940 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
50 |
| - | |
| 50 | + | |
51 | 51 |
| |
52 | 52 |
|
Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
41 |
| - | |
| 41 | + | |
42 | 42 |
| |
43 | 43 |
| |
44 | 44 |
| |
| |||
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
51 |
| - | |
| 51 | + | |
52 | 52 |
| |
53 | 53 |
| |
54 | 54 |
| |
| |||
142 | 142 |
| |
143 | 143 |
| |
144 | 144 |
| |
145 |
| - | |
| 145 | + | |
146 | 146 |
| |
147 | 147 |
| |
148 | 148 |
| |
149 | 149 |
| |
150 | 150 |
| |
151 | 151 |
| |
152 | 152 |
| |
153 |
| - | |
| 153 | + | |
154 | 154 |
| |
155 | 155 |
| |
156 | 156 |
| |
|
0 commit comments
Comments
(0)