Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

ci: bump the github-actions group with 7 updates#11123

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation

dependabot[bot]
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubDec 11, 2023
edited
Loading

Bumps the github-actions group with 7 updates:

PackageFromTo
crate-ci/typos1.16.231.16.24
google-github-actions/setup-gcloud12
google-github-actions/get-gke-credentials12
docker/setup-buildx-action23
docker/build-push-action45
aquasecurity/trivy-action0.14.00.16.0
actions/stale8.0.09.0.0

Updatescrate-ci/typos from 1.16.23 to 1.16.24

Release notes

Sourced fromcrate-ci/typos's releases.

v1.16.24

[1.16.24] - 2023-12-08

Fixes

  • Don't silently ignore config when there is an error in a field
Changelog

Sourced fromcrate-ci/typos's changelog.

[1.16.24] - 2023-12-08

Fixes

  • Don't silently ignore config when there is an error in a field
Commits

Updatesgoogle-github-actions/setup-gcloud from 1 to 2

Release notes

Sourced fromgoogle-github-actions/setup-gcloud's releases.

v2

⚠️ This version requires Node 20 or later!

Floating v2 alias

v2.0.0

⚠️ This version requires Node 20 or later!

What's Changed

Full Changelog:google-github-actions/setup-gcloud@v1...v2.0.0

v1.1.1

What's Changed

New Contributors

Full Changelog:google-github-actions/setup-gcloud@v1.1.0...v1.1.1

v1.1.0

What's Changed

Full Changelog:google-github-actions/setup-gcloud@v1.0.1...v1.1.0

... (truncated)

Commits

Updatesgoogle-github-actions/get-gke-credentials from 1 to 2

Release notes

Sourced fromgoogle-github-actions/get-gke-credentials's releases.

v2

Floating v2 alias

v2.0.0

⚠️ This version requires Node 20 or later!

What's Changed

Full Changelog:google-github-actions/get-gke-credentials@v1...v2.0.0

v1.0.2

What's Changed

Full Changelog:google-github-actions/get-gke-credentials@v1.0.1...v1.0.2

v1.0.1

What's Changed

Full Changelog:google-github-actions/get-gke-credentials@v1.0.0...v1.0.1

Commits

Updatesdocker/setup-buildx-action from 2 to 3

Release notes

Sourced fromdocker/setup-buildx-action's releases.

v3.0.0

Full Changelog:docker/setup-buildx-action@v2.10.0...v3.0.0

v2.10.0

What's Changed

Full Changelog:docker/setup-buildx-action@v2.9.1...v2.10.0

v2.9.1

Full Changelog:docker/setup-buildx-action@v2.9.0...v2.9.1

v2.9.0

  • Bump@​docker/actions-toolkit from 0.6.0 to 0.7.0 indocker/setup-buildx-action#246
    • Adds support to cache Buildx binary to hosted tool cache and GHA cache backend

Full Changelog:docker/setup-buildx-action@v2.8.0...v2.9.0

v2.8.0

Full Changelog:docker/setup-buildx-action@v2.7.0...v2.8.0

v2.7.0

Full Changelog:docker/setup-buildx-action@v2.6.0...v2.7.0

v2.6.0

Full Changelog:docker/setup-buildx-action@v2.5.0...v2.6.0

v2.5.0

Full Changelog:docker/setup-buildx-action@v2.4.1...v2.5.0

v2.4.1

... (truncated)

Commits
  • f95db51 Merge pull request#267 from docker/dependabot/npm_and_yarn/actions/core-1.10.1
  • 998a87c chore: update generated content
  • 28bae59 build(deps): bump@​actions/core from 1.10.0 to 1.10.1
  • c215341 Merge pull request#264 from crazy-max/update-node20
  • 02e9319 chore: node 20 as default runtime
  • 5c9160e chore: update generated content
  • 1283140 chore: fix author in package.json
  • c6afe06 vendor: bump@​docker/actions-toolkit from 0.10.0 to 0.12.0
  • f35e0d5 chore: update dev dependencies
  • baeb468 dev: remove unneeded binaries
  • Additional commits viewable incompare view

Updatesdocker/build-push-action from 4 to 5

Release notes

Sourced fromdocker/build-push-action's releases.

v5.0.0

Full Changelog:docker/build-push-action@v4.2.1...v5.0.0

v4.2.1

Note

Buildx v0.10 enables support for a minimalSLSA Provenance attestation, which requires support forOCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g.Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality usingprovenance: false.

Full Changelog:docker/build-push-action@v4.2.0...v4.2.1

v4.2.0

Note

Buildx v0.10 enables support for a minimalSLSA Provenance attestation, which requires support forOCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g.Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality usingprovenance: false.

Full Changelog:docker/build-push-action@v4.1.1...v4.2.0

v4.1.1

Note

Buildx v0.10 enables support for a minimalSLSA Provenance attestation, which requires support forOCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g.Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality usingprovenance: false.

Full Changelog:docker/build-push-action@v4.1.0...v4.1.1

v4.1.0

Note

Buildx v0.10 enables support for a minimalSLSA Provenance attestation, which requires support forOCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g.Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality usingprovenance: false.

Full Changelog:docker/build-push-action@v4.0.0...v4.1.0

Commits
  • 4a13e50 Merge pull request#1006 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 7416668 chore: update generated content
  • b4f76a5 chore(deps): Bump@​docker/actions-toolkit from 0.13.0 to 0.14.0
  • b7feb76 Merge pull request#1005 from crazy-max/ci-inspect
  • fae8018 ci: inspect sbom and provenance
  • b625868 Merge pull request#1004 from crazy-max/ci-update-buildx
  • 5193ef1 ci: update buildx to latest
  • d3afd77 Merge pull request#991 from docker/dependabot/npm_and_yarn/babel/traverse-7....
  • 7a786bb Merge pull request#992 from crazy-max/annotations
  • c66ae3a chore: update generated content
  • Additional commits viewable incompare view

Updatesaquasecurity/trivy-action from 0.14.0 to 0.16.0

Release notes

Sourced fromaquasecurity/trivy-action's releases.

v0.16.0

What's Changed

New Contributors

Full Changelog:aquasecurity/trivy-action@0.15.0...0.16.0

v0.15.0

What's Changed

Full Changelog:aquasecurity/trivy-action@0.14.0...0.15.0

Commits

Updatesactions/stale from 8.0.0 to 9.0.0

Release notes

Sourced fromactions/stale's releases.

v9.0.0

Breaking Changes

  1. Action is now stateful: If the action ends because ofoperations-per-run then the next run will start from the first unprocessed issue skipping the issues processed during the previous run(s). The state is reset when all the issues are processed. This should be considered for scheduling workflow runs.
  2. Version 9 of this action updated the runtime to Node.js 20. All scripts are now run with Node.js 20 instead of Node.js 16 and are affected by any breaking changes between Node.js 16 and 20.

What Else Changed

  1. Performance optimization that removes unnecessary API calls by@​dsame#1033 fixes#792
  2. Logs displaying current github API rate limit by@​dsame#1032 addresses#1029

For more information, please read theaction documentation and itssection about statefulness

New Contributors

Full Changelog:actions/stale@v8...v9.0.0

Commits
  • 28ca103 Upgrade Node to v20 (#1110)
  • b69b346 build(deps-dev): bump@​types/node from 18.16.18 to 20.5.1 (#1079)
  • 88a6f4f build(deps-dev): bump typescript from 5.1.3 to 5.2.2 (#1083)
  • 796531a Merge pull request#1080 from akv-platform/fix-delete-cache
  • 8986f62 Don not try to delete cache if it does not exists
  • cab99b3 fix typo proceeded/processed
  • 184e7af Merge pull request#1064 from actions/dependabot/npm_and_yarn/typescript-esli...
  • 523885c chore: update eslint-plugin, parser and eslint-plugin-jest
  • 2487a1d build(deps-dev): bump@​typescript-eslint/eslint-plugin
  • 60c722e Merge pull request#1063 from actions/dependabot/npm_and_yarn/jest-29.6.2
  • Additional commits viewable incompare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 7 updates:| Package | From | To || --- | --- | --- || [crate-ci/typos](https://github.com/crate-ci/typos) | `1.16.23` | `1.16.24` || [google-github-actions/setup-gcloud](https://github.com/google-github-actions/setup-gcloud) | `1` | `2` || [google-github-actions/get-gke-credentials](https://github.com/google-github-actions/get-gke-credentials) | `1` | `2` || [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `2` | `3` || [docker/build-push-action](https://github.com/docker/build-push-action) | `4` | `5` || [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.14.0` | `0.16.0` || [actions/stale](https://github.com/actions/stale) | `8.0.0` | `9.0.0` |Updates `crate-ci/typos` from 1.16.23 to 1.16.24- [Release notes](https://github.com/crate-ci/typos/releases)- [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md)- [Commits](crate-ci/typos@v1.16.23...v1.16.24)Updates `google-github-actions/setup-gcloud` from 1 to 2- [Release notes](https://github.com/google-github-actions/setup-gcloud/releases)- [Changelog](https://github.com/google-github-actions/setup-gcloud/blob/main/CHANGELOG.md)- [Commits](google-github-actions/setup-gcloud@v1...v2)Updates `google-github-actions/get-gke-credentials` from 1 to 2- [Release notes](https://github.com/google-github-actions/get-gke-credentials/releases)- [Changelog](https://github.com/google-github-actions/get-gke-credentials/blob/main/CHANGELOG.md)- [Commits](google-github-actions/get-gke-credentials@v1...v2)Updates `docker/setup-buildx-action` from 2 to 3- [Release notes](https://github.com/docker/setup-buildx-action/releases)- [Commits](docker/setup-buildx-action@v2...v3)Updates `docker/build-push-action` from 4 to 5- [Release notes](https://github.com/docker/build-push-action/releases)- [Commits](docker/build-push-action@v4...v5)Updates `aquasecurity/trivy-action` from 0.14.0 to 0.16.0- [Release notes](https://github.com/aquasecurity/trivy-action/releases)- [Commits](aquasecurity/trivy-action@2b6a709...91713af)Updates `actions/stale` from 8.0.0 to 9.0.0- [Release notes](https://github.com/actions/stale/releases)- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)- [Commits](actions/stale@v8.0.0...v9.0.0)---updated-dependencies:- dependency-name: crate-ci/typos  dependency-type: direct:production  update-type: version-update:semver-patch  dependency-group: github-actions- dependency-name: google-github-actions/setup-gcloud  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: github-actions- dependency-name: google-github-actions/get-gke-credentials  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: github-actions- dependency-name: docker/setup-buildx-action  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: github-actions- dependency-name: docker/build-push-action  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: github-actions- dependency-name: aquasecurity/trivy-action  dependency-type: direct:production  update-type: version-update:semver-minor  dependency-group: github-actions- dependency-name: actions/stale  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: github-actions...Signed-off-by: dependabot[bot] <support@github.com>
Copy link
Member

@deansheatherdeansheather left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

We use node 18 so this can't be merged until the project is upgraded to node 20 I think

@matifali
Copy link
Member

@deansheather This is for actions' code; an action does not depend on our node version. Many actions we have been using have already been upgraded to node 20. For example,actions/checout@v4.

deansheather reacted with thumbs up emoji

@deansheatherdeansheather merged commit6823194 intomainDec 11, 2023
@deansheatherdeansheather deleted the dependabot/github_actions/github-actions-64346f1cc2 branchDecember 11, 2023 13:21
@github-actionsgithub-actionsbot locked and limited conversation to collaboratorsDec 11, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account?Sign in.
Reviewers

@deansheatherdeansheatherdeansheather approved these changes

@github-actionsgithub-actions[bot]github-actions[bot] approved these changes

Assignees
No one assigned
Labels
None yet
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

2 participants
@matifali@deansheather

[8]ページ先頭

©2009-2025 Movatter.jp