github-early-access / generate-build-provenance

Publish a signed build provenance from your GitHub Actions workflow
MIT License
63 stars 30 forks source link

Bump the minor-patch group with 3 updates #188

Closed dependabot[bot] closed 5 months ago

dependabot[bot] commented 5 months ago

Bumps the minor-patch group with 3 updates: actions/upload-artifact, github/codeql-action and super-linter/super-linter.

Updates actions/upload-artifact from 4.3.2 to 4.3.3

Release notes

Sourced from actions/upload-artifact's releases.

v4.3.3

What's Changed

Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.2...v4.3.3

Commits
  • 6546280 updating package version
  • c004fb4 Merge branch 'main' into eggyhead/use-artifact-v2.1.6
  • 90aba49 updating toolkit artifact dependency to 2.1.6
  • b06cde3 Merge pull request #563 from actions/eggyhead/release-4.3.2
  • See full diff in compare view


Updates github/codeql-action from 3.25.1 to 3.25.2

Commits
  • 8f596b4 Merge pull request #2254 from github/update-v3.25.2-4909c1ffb
  • de8916e Update changelog for v3.25.2
  • 4909c1f Bump the npm group with 3 updates (#2253)
  • f45390c Merge pull request #2252 from github/henrymercer/failed-external-repo-config-...
  • 1be8c48 Add configuration error for failing to clone external Git repo
  • 82edfe2 Merge pull request #2246 from github/koesie10/remove-incorrect-log
  • 8786e1f Merge pull request #2249 from github/mergeback/v3.25.1-to-main-c7f91257
  • 3c7ac61 Update checked-in dependencies
  • b5bd9be Update changelog and version after v3.25.1
  • 5d73b1b Remove incorrect log message
  • See full diff in compare view


Updates super-linter/super-linter from 6.4.0 to 6.4.1

Release notes

Sourced from super-linter/super-linter's releases.

v6.4.1

6.4.1 (2024-04-22)

🐛 Bugfixes

⬆️ Dependency updates

  • dev-docker: bump node in /dev-dependencies (#5512) (155f3a6)
  • dev-npm: bump @​commitlint/cli in /dev-dependencies (#5522) (ed458ca)
  • docker: bump alpine/terragrunt from 1.7.5 to 1.8.0 (#5507) (9f4f94e)
  • docker: bump dotnet/sdk (#5508) (c09c7a3)
  • docker: bump hashicorp/terraform from 1.7.5 to 1.8.0 (#5510) (c65f44c)
  • docker: bump python from 3.12.2-alpine3.19 to 3.12.3-alpine3.19 (#5511) (a7d84ea)
  • docker: bump yoheimuta/protolint from 0.49.4 to 0.49.6 (#5509) (0b280e4)
  • npm: bump @​typescript-eslint/eslint-plugin in /dependencies (#5515) (afe0821)
  • npm: bump eslint-plugin-jsonc in /dependencies (#5514) (2c2ce27)
  • npm: bump eslint-plugin-vue from 9.24.1 to 9.25.0 in /dependencies (#5516) (77f9363)
  • npm: bump next from 14.1.4 to 14.2.1 in /dependencies (#5513) (041abfb)
  • npm: bump react-redux from 9.1.0 to 9.1.1 in /dependencies (#5520) (632b571)
  • npm: bump renovate from 37.280.0 to 37.296.0 in /dependencies (#5518) (338a2bc)
  • npm: bump typescript from 5.4.4 to 5.4.5 in /dependencies (#5519) (9d10c26)
  • python: bump ansible-lint in /dependencies/python (#5529) (5cc9442)
  • python: bump black from 24.3.0 to 24.4.0 in /dependencies/python (#5525) (48c98aa)
  • python: bump checkov from 3.2.55 to 3.2.65 in /dependencies/python (#5527) (3d5d68f)
  • python: bump ruff from 0.3.4 to 0.3.7 in /dependencies/python (#5528) (afaeb3a)
  • python: bump snakefmt in /dependencies/python (#5526) (8b76d91)
  • python: bump snakemake in /dependencies/python (#5523) (fdd0427)
  • python: bump sqlfluff from 3.0.3 to 3.0.4 in /dependencies/python (#5530) (a0e8621)
  • python: bump yq from 3.2.3 to 3.3.0 in /dependencies/python (#5524) (1c603c7)

🧰 Maintenance

Changelog

Sourced from super-linter/super-linter's changelog.

Changelog

6.4.1 (2024-04-22)

🐛 Bugfixes

⬆️ Dependency updates

  • dev-docker: bump node in /dev-dependencies (#5512) (155f3a6)
  • dev-npm: bump @​commitlint/cli in /dev-dependencies (#5522) (ed458ca)
  • docker: bump alpine/terragrunt from 1.7.5 to 1.8.0 (#5507) (9f4f94e)
  • docker: bump dotnet/sdk (#5508) (c09c7a3)
  • docker: bump hashicorp/terraform from 1.7.5 to 1.8.0 (#5510) (c65f44c)
  • docker: bump python from 3.12.2-alpine3.19 to 3.12.3-alpine3.19 (#5511) (a7d84ea)
  • docker: bump yoheimuta/protolint from 0.49.4 to 0.49.6 (#5509) (0b280e4)
  • npm: bump @​typescript-eslint/eslint-plugin in /dependencies (#5515) (afe0821)
  • npm: bump eslint-plugin-jsonc in /dependencies (#5514) (2c2ce27)
  • npm: bump eslint-plugin-vue from 9.24.1 to 9.25.0 in /dependencies (#5516) (77f9363)
  • npm: bump next from 14.1.4 to 14.2.1 in /dependencies (#5513) (041abfb)
  • npm: bump react-redux from 9.1.0 to 9.1.1 in /dependencies (#5520) (632b571)
  • npm: bump renovate from 37.280.0 to 37.296.0 in /dependencies (#5518) (338a2bc)
  • npm: bump typescript from 5.4.4 to 5.4.5 in /dependencies (#5519) (9d10c26)
  • python: bump ansible-lint in /dependencies/python (#5529) (5cc9442)
  • python: bump black from 24.3.0 to 24.4.0 in /dependencies/python (#5525) (48c98aa)
  • python: bump checkov from 3.2.55 to 3.2.65 in /dependencies/python (#5527) (3d5d68f)
  • python: bump ruff from 0.3.4 to 0.3.7 in /dependencies/python (#5528) (afaeb3a)
  • python: bump snakefmt in /dependencies/python (#5526) (8b76d91)
  • python: bump snakemake in /dependencies/python (#5523) (fdd0427)
  • python: bump sqlfluff from 3.0.3 to 3.0.4 in /dependencies/python (#5530) (a0e8621)
  • python: bump yq from 3.2.3 to 3.3.0 in /dependencies/python (#5524) (1c603c7)

🧰 Maintenance

6.4.0 (2024-04-16)

🚀 Features

... (truncated)

Commits


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
dependabot[bot] commented 5 months ago

Looks like these dependencies are updatable in another way, so this is no longer needed.