build(deps): bump the github-actions group across 1 directory with 5 updates#11818
build(deps): bump the github-actions group across 1 directory with 5 updates#11818dependabot[bot] wants to merge 4 commits intomainfrom
Conversation
…updates Bumps the github-actions group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [sylvainsf/causinator9000](https://github.com/sylvainsf/causinator9000) | `2.1.0` | `2.2.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.35.2` | `4.35.3` | | [securego/gosec](https://github.com/securego/gosec) | `2.25.0` | `2.26.1` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.1.0` | `6.1.1` | | [mheap/require-checklist-action](https://github.com/mheap/require-checklist-action) | `2.5.0` | `2.6.1` | Updates `sylvainsf/causinator9000` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/sylvainsf/causinator9000/releases) - [Commits](sylvainsf/causinator9000@ff3e97f...ba057ac) Updates `github/codeql-action` from 4.35.2 to 4.35.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@95e58e9...e46ed2c) Updates `securego/gosec` from 2.25.0 to 2.26.1 - [Release notes](https://github.com/securego/gosec/releases) - [Commits](securego/gosec@223e19b...4a3bd8a) Updates `aws-actions/configure-aws-credentials` from 6.1.0 to 6.1.1 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@ec61189...d979d5b) Updates `mheap/require-checklist-action` from 2.5.0 to 2.6.1 - [Release notes](https://github.com/mheap/require-checklist-action/releases) - [Commits](mheap/require-checklist-action@46d2ca1...9c8100a) --- updated-dependencies: - dependency-name: sylvainsf/causinator9000 dependency-version: 2.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.35.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: securego/gosec dependency-version: 2.26.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: mheap/require-checklist-action dependency-version: 2.6.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
There was a problem hiding this comment.
Pull request overview
This PR updates pinned commit SHAs for several GitHub Actions used in Radius CI workflows, keeping the repo’s security/CI tooling up to date while maintaining immutable action references (SHA pinning).
Changes:
- Bump
github/codeql-actionusages (init/autobuild/analyze/upload-sarif) from v4.35.2 to v4.35.3. - Bump
aws-actions/configure-aws-credentialsfrom v6.1.0 to v6.1.1 in AWS-related workflows. - Bump
securego/gosec,mheap/require-checklist-action, andsylvainsf/causinator9000to newer pinned SHAs.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/scorecard.yaml | Updates CodeQL SARIF upload action pin to v4.35.3. |
| .github/workflows/require-pr-checklist.yaml | Updates PR checklist enforcement action pin to v2.6.1. |
| .github/workflows/purge-aws-test-resources.yaml | Updates AWS credentials action pin to v6.1.1. |
| .github/workflows/functional-test-cloud.yaml | Updates AWS credentials action pin to v6.1.1 for cloud functional tests. |
| .github/workflows/codeql.yml | Updates CodeQL + GoSec action pins (CodeQL v4.35.3, GoSec v2.26.1). |
| .github/workflows/c9k-nightly.yml | Updates CI failure report generator action pin to v2.2.0. |
| .github/workflows/c9k-failure-report.yml | Updates CI failure report generator action pin to v2.2.0. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #11818 +/- ##
=======================================
Coverage 51.20% 51.21%
=======================================
Files 715 715
Lines 45074 45074
=======================================
+ Hits 23079 23083 +4
+ Misses 19798 19796 -2
+ Partials 2197 2195 -2 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Bumps the github-actions group with 5 updates in the / directory:
2.1.02.2.04.35.24.35.32.25.02.26.16.1.06.1.12.5.02.6.1Updates
sylvainsf/causinator9000from 2.1.0 to 2.2.0Release notes
Sourced from sylvainsf/causinator9000's releases.
Commits
ba057acfix: skip closed PRs, require concurrency group for auto-issue\n\nTwo fixes f...4330260fix: assign Copilot after issue creation, not during\n\nThe --assignee flag o...Updates
github/codeql-actionfrom 4.35.2 to 4.35.3Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
e46ed2cMerge pull request #3867 from github/update-v4.35.3-8c6e48dbeb73d1d1Add changelog entry for #385324e0bb0Reorder changelog entriesec298daUpdate changelog for v4.35.38c6e48dMerge pull request #3865 from github/update-bundle/codeql-bundle-v2.25.37190983Add changelog note2bb2095Update default bundle to codeql-bundle-v2.25.37851e55Merge pull request #3850 from github/mbg/private-registry/cloudsmith-gcp262a15fAdd generic non-printable chars test for OIDC configsa6109b1Merge pull request #3853 from github/mbg/start-proxy/improved-checksUpdates
securego/gosecfrom 2.25.0 to 2.26.1Release notes
Sourced from securego/gosec's releases.
Commits
4a3bd8aUpdate cosign to v3.0.6 (#1659)553d8a5Sync taint rule docs and add missing CWE mappings for G113/G307 (#1658)bf0ccd3Update all dependencies (#1657)4ead098Add G710 rule for open redirect via taint analysis (#1654)8ff985fFix formattinga1aad0cUpdate the default models use by autofix and phase out the older models74bdf7fFormat and clean-up the README74dc989Add HTTP file-serving function to the skins of pathtraversal analyzer (#1647)7020111Skip flaging the TLS min version for go 1.18+ (#1646)d5869fcchore(deps): bump go.opentelemetry.io/otel from 1.39.0 to 1.41.0 (#1645)Updates
aws-actions/configure-aws-credentialsfrom 6.1.0 to 6.1.1Release notes
Sourced from aws-actions/configure-aws-credentials's releases.
Changelog
Sourced from aws-actions/configure-aws-credentials's changelog.
... (truncated)
Commits
d979d5bchore: release 6.1.1 (#1757)d4a9acdchore: Update distfc44f4achore(deps): bump@aws-sdk/client-stsfrom 3.1033.0 to 3.1038.0 (#1749)0b8336fchore: Update dist8c5bf33chore(deps-dev): bump@aws-sdk/credential-provider-env(#1751)53df0c1chore: Update distc2c5582chore(deps): bump@smithy/node-http-handlerfrom 4.6.0 to 4.6.1 (#1750)bd0031dchore(deps): bump postcss from 8.5.6 to 8.5.12 (#1752)6ab499achore(deps-dev): bump@biomejs/biomefrom 2.4.12 to 2.4.13 (#1747)bc94895chore(deps-dev): bump@biomejs/biomefrom 2.4.11 to 2.4.12 (#1739)Updates
mheap/require-checklist-actionfrom 2.5.0 to 2.6.1Release notes
Sourced from mheap/require-checklist-action's releases.
Commits
9c8100aAutomatic compilation74de6f6Update convert-action to get node24 (#58)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions