G-Rath / osv-detector

MIT License
61 stars 8 forks source link

chore(deps): update workflows #268

Closed renovate[bot] closed 1 month ago

renovate[bot] commented 2 months ago

Mend Renovate

This PR contains the following updates:

Package Type Update Change
actions/setup-java action patch v4.2.1 -> v4.2.2
actions/upload-artifact action patch v4.3.4 -> v4.3.6
github/codeql-action action minor v3.25.11 -> v3.26.4
golangci/golangci-lint-action action minor v6.0.1 -> v6.1.0
ossf/scorecard-action action minor v2.3.3 -> v2.4.0
r-lib/actions action minor v2.9.0 -> v2.10.1
ruby/setup-ruby action minor v1.187.0 -> v1.190.0

Release Notes

actions/setup-java (actions/setup-java) ### [`v4.2.2`](https://togithub.com/actions/setup-java/releases/tag/v4.2.2) [Compare Source](https://togithub.com/actions/setup-java/compare/v4.2.1...v4.2.2) ##### What's Changed ##### 

Bug fixes: - Fix macos latest check failures by [@​HarithaVattikuti](https://togithub.com/HarithaVattikuti) in [https://github.com/actions/setup-java/pull/634](https://togithub.com/actions/setup-java/pull/634) - Fix dragonwell distribution parsing issues by [@​Accelerator1996](https://togithub.com/Accelerator1996) in [https://github.com/actions/setup-java/pull/643](https://togithub.com/actions/setup-java/pull/643) ##### Documentation changes - Update advanced documentation for java-version-file by [@​mahabaleshwars](https://togithub.com/mahabaleshwars) in [https://github.com/actions/setup-java/pull/622](https://togithub.com/actions/setup-java/pull/622) ##### Dependency updates: - Bump undici from 5.28.3 to 5.28.4 and other dependency updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/actions/setup-java/pull/616](https://togithub.com/actions/setup-java/pull/616) **Full Changelog**: https://github.com/actions/setup-java/compare/v4...v4.2.2
actions/upload-artifact (actions/upload-artifact) ### [`v4.3.6`](https://togithub.com/actions/upload-artifact/compare/v4.3.5...v4.3.6) [Compare Source](https://togithub.com/actions/upload-artifact/compare/v4.3.5...v4.3.6) ### [`v4.3.5`](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5) [Compare Source](https://togithub.com/actions/upload-artifact/compare/v4.3.4...v4.3.5)
github/codeql-action (github/codeql-action) ### [`v3.26.4`](https://togithub.com/github/codeql-action/compare/v3.26.3...v3.26.4) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.26.3...v3.26.4) ### [`v3.26.3`](https://togithub.com/github/codeql-action/compare/v3.26.2...v3.26.3) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.26.2...v3.26.3) ### [`v3.26.2`](https://togithub.com/github/codeql-action/compare/v3.26.1...v3.26.2) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.26.1...v3.26.2) ### [`v3.26.1`](https://togithub.com/github/codeql-action/compare/v3.26.0...v3.26.1) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.26.0...v3.26.1) ### [`v3.26.0`](https://togithub.com/github/codeql-action/compare/v3.25.15...v3.26.0) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.15...v3.26.0) ### [`v3.25.15`](https://togithub.com/github/codeql-action/compare/v3.25.14...v3.25.15) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.14...v3.25.15) ### [`v3.25.14`](https://togithub.com/github/codeql-action/compare/v3.25.13...v3.25.14) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.13...v3.25.14) ### [`v3.25.13`](https://togithub.com/github/codeql-action/compare/v3.25.12...v3.25.13) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.12...v3.25.13) ### [`v3.25.12`](https://togithub.com/github/codeql-action/compare/v3.25.11...v3.25.12) [Compare Source](https://togithub.com/github/codeql-action/compare/v3.25.11...v3.25.12)
golangci/golangci-lint-action (golangci/golangci-lint-action) ### [`v6.1.0`](https://togithub.com/golangci/golangci-lint-action/releases/tag/v6.1.0) [Compare Source](https://togithub.com/golangci/golangci-lint-action/compare/v6.0.1...v6.1.0) #### What's Changed ##### Changes - feat: allow to skip golangci-lint installation by [@​ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1079](https://togithub.com/golangci/golangci-lint-action/pull/1079) ##### Documentation - docs: add Go workspace examples by [@​ldez](https://togithub.com/ldez) in [https://github.com/golangci/golangci-lint-action/pull/1064](https://togithub.com/golangci/golangci-lint-action/pull/1064) ##### Dependencies - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.8 to 20.12.11 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1041](https://togithub.com/golangci/golangci-lint-action/pull/1041) - build(deps-dev): bump [@​typescript-eslint/eslint-plugin](https://togithub.com/typescript-eslint/eslint-plugin) from 7.8.0 to 7.9.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1042](https://togithub.com/golangci/golangci-lint-action/pull/1042) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.11 to 20.12.12 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1043](https://togithub.com/golangci/golangci-lint-action/pull/1043) - build(deps-dev): bump [@​typescript-eslint/parser](https://togithub.com/typescript-eslint/parser) from 7.8.0 to 7.9.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1044](https://togithub.com/golangci/golangci-lint-action/pull/1044) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1047](https://togithub.com/golangci/golangci-lint-action/pull/1047) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.12.12 to 20.14.0 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1051](https://togithub.com/golangci/golangci-lint-action/pull/1051) - build(deps-dev): bump the dev-dependencies group across 1 directory with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1053](https://togithub.com/golangci/golangci-lint-action/pull/1053) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1061](https://togithub.com/golangci/golangci-lint-action/pull/1061) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.0 to 20.14.2 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1062](https://togithub.com/golangci/golangci-lint-action/pull/1062) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1063](https://togithub.com/golangci/golangci-lint-action/pull/1063) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.2 to 20.14.8 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1066](https://togithub.com/golangci/golangci-lint-action/pull/1066) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1065](https://togithub.com/golangci/golangci-lint-action/pull/1065) - build(deps-dev): bump the dev-dependencies group with 2 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1067](https://togithub.com/golangci/golangci-lint-action/pull/1067) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.8 to 20.14.9 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1068](https://togithub.com/golangci/golangci-lint-action/pull/1068) - build(deps-dev): bump the dev-dependencies group with 4 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1071](https://togithub.com/golangci/golangci-lint-action/pull/1071) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.9 to 20.14.10 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1072](https://togithub.com/golangci/golangci-lint-action/pull/1072) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1073](https://togithub.com/golangci/golangci-lint-action/pull/1073) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1074](https://togithub.com/golangci/golangci-lint-action/pull/1074) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.10 to 20.14.11 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1075](https://togithub.com/golangci/golangci-lint-action/pull/1075) - build(deps-dev): bump the dev-dependencies group with 3 updates by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1077](https://togithub.com/golangci/golangci-lint-action/pull/1077) - build(deps): bump [@​types/node](https://togithub.com/types/node) from 20.14.11 to 22.0.0 in the dependencies group by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/golangci/golangci-lint-action/pull/1078](https://togithub.com/golangci/golangci-lint-action/pull/1078) **Full Changelog**: https://github.com/golangci/golangci-lint-action/compare/v6.0.1...v6.1.0
ossf/scorecard-action (ossf/scorecard-action) ### [`v2.4.0`](https://togithub.com/ossf/scorecard-action/releases/tag/v2.4.0) [Compare Source](https://togithub.com/ossf/scorecard-action/compare/v2.3.3...v2.4.0) #### What's Changed This update bumps the Scorecard version to the v5 release. For a complete list of changes, please refer to the [v5.0.0 release notes](https://togithub.com/ossf/scorecard/releases/tag/v5.0.0). Of special note to Scorecard Action is the Maintainer Annotation feature, which can be used to suppress some Code Scanning false positives. Alerts will not be generated for any Scorecard Check with an annotation. - :seedling: Bump github.com/ossf/scorecard/v5 from v5.0.0-rc2 to v5.0.0 by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1410](https://togithub.com/ossf/scorecard-action/pull/1410) - :bug: lower license sarif alert threshold to 9 by [@​spencerschrock](https://togithub.com/spencerschrock) in [https://github.com/ossf/scorecard-action/pull/1411](https://togithub.com/ossf/scorecard-action/pull/1411) ##### Documentation - docs: dogfooding badge by [@​jkowalleck](https://togithub.com/jkowalleck) in [https://github.com/ossf/scorecard-action/pull/1399](https://togithub.com/ossf/scorecard-action/pull/1399) #### New Contributors - [@​jkowalleck](https://togithub.com/jkowalleck) made their first contribution in [https://github.com/ossf/scorecard-action/pull/1399](https://togithub.com/ossf/scorecard-action/pull/1399) **Full Changelog**: https://github.com/ossf/scorecard-action/compare/v2.3.3...v2.4.0
r-lib/actions (r-lib/actions) ### [`v2.10.1`](https://togithub.com/r-lib/actions/compare/v2.10.0...v2.10.1) [Compare Source](https://togithub.com/r-lib/actions/compare/v2.10.0...v2.10.1) ### [`v2.10.0`](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0) [Compare Source](https://togithub.com/r-lib/actions/compare/v2.9.0...v2.10.0)
ruby/setup-ruby (ruby/setup-ruby) ### [`v1.190.0`](https://togithub.com/ruby/setup-ruby/releases/tag/v1.190.0) [Compare Source](https://togithub.com/ruby/setup-ruby/compare/v1.189.0...v1.190.0) #### What's Changed - Update CRuby releases on Windows by [@​ruby-builder-bot](https://togithub.com/ruby-builder-bot) in [https://github.com/ruby/setup-ruby/pull/628](https://togithub.com/ruby/setup-ruby/pull/628) **Full Changelog**: https://github.com/ruby/setup-ruby/compare/v1.189.0...v1.190.0 ### [`v1.189.0`](https://togithub.com/ruby/setup-ruby/releases/tag/v1.189.0) [Compare Source](https://togithub.com/ruby/setup-ruby/compare/v1.188.0...v1.189.0) #### What's Changed - docs: update ruby-version comment by [@​chenrui333](https://togithub.com/chenrui333) in [https://github.com/ruby/setup-ruby/pull/626](https://togithub.com/ruby/setup-ruby/pull/626) - Add ruby-3.2.5 by [@​ruby-builder-bot](https://togithub.com/ruby-builder-bot) in [https://github.com/ruby/setup-ruby/pull/627](https://togithub.com/ruby/setup-ruby/pull/627) #### New Contributors - [@​chenrui333](https://togithub.com/chenrui333) made their first contribution in [https://github.com/ruby/setup-ruby/pull/626](https://togithub.com/ruby/setup-ruby/pull/626) **Full Changelog**: https://github.com/ruby/setup-ruby/compare/v1.188.0...v1.189.0 ### [`v1.188.0`](https://togithub.com/ruby/setup-ruby/releases/tag/v1.188.0) [Compare Source](https://togithub.com/ruby/setup-ruby/compare/v1.187.0...v1.188.0) #### What's Changed - Add truffleruby-24.0.2,truffleruby+graalvm-24.0.2 by [@​ruby-builder-bot](https://togithub.com/ruby-builder-bot) in [https://github.com/ruby/setup-ruby/pull/625](https://togithub.com/ruby/setup-ruby/pull/625) **Full Changelog**: https://github.com/ruby/setup-ruby/compare/v1.187.0...v1.188.0

Configuration

📅 Schedule: Branch creation - "before 6am on monday" in timezone Pacific/Auckland, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.



This PR was generated by Mend Renovate. View the repository job log.