Repository navigation
build(deps): bump the cicd group with 10 updates - #3260
Erik Osterman (Cloud Posse) (osterman) merged 12 commits into
Conversation
Bumps the cicd group with 10 updates: | Package | From | To | | --- | --- | --- | | [cloudposse/.github/.github/workflows/shared-release-branches.yml](https://github.com/cloudposse/.github) | `0.171.0` | `0.173.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [cloudposse/.github/.github/workflows/shared-go-auto-release.yml](https://github.com/cloudposse/.github) | `0.170.0` | `0.173.0` | | [cloudposse/github-action-setup-atmos](https://github.com/cloudposse/github-action-setup-atmos) | `3.5.0` | `3.6.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.0.0` | `7.1.1` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.97.4` | `3.97.5` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.4` | `6.3.0` | Updates `cloudposse/.github/.github/workflows/shared-release-branches.yml` from 0.171.0 to 0.173.0 - [Release notes](https://github.com/cloudposse/.github/releases) - [Commits](cloudposse/.github@4e05ff6...281621d) Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `github/codeql-action/init` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `cloudposse/.github/.github/workflows/shared-go-auto-release.yml` from 0.170.0 to 0.173.0 - [Release notes](https://github.com/cloudposse/.github/releases) - [Commits](cloudposse/.github@v0.170.0...281621d) Updates `cloudposse/github-action-setup-atmos` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/cloudposse/github-action-setup-atmos/releases) - [Commits](cloudposse/github-action-setup-atmos@60878d4...9e8d1e2) Updates `codecov/codecov-action` from 7.0.0 to 7.1.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@fb8b358...303a32d) Updates `trufflesecurity/trufflehog` from 3.97.4 to 3.97.5 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@363923b...f714bf4) Updates `aws-actions/configure-aws-credentials` from 6.2.4 to 6.3.0 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@cbe3b39...e125382) --- updated-dependencies: - dependency-name: cloudposse/.github/.github/workflows/shared-release-branches.yml dependency-version: 0.173.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cicd - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cicd - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cicd - dependency-name: github/codeql-action/autobuild dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cicd - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cicd - dependency-name: cloudposse/.github/.github/workflows/shared-go-auto-release.yml dependency-version: 0.173.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cicd - dependency-name: cloudposse/github-action-setup-atmos dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cicd - dependency-name: codecov/codecov-action dependency-version: 7.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cicd - dependency-name: trufflesecurity/trufflehog dependency-version: 3.97.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cicd - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cicd ... Signed-off-by: dependabot[bot] <support@github.com>
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Dependency ReviewThe following issues were found:
License Issues.github/workflows/nightlybuilds.yml
Scanned Files
|
|
Warning SHA Pin Verification Passed — with documented exceptionsAll 239 third-party action reference(s) are covered, but 2 rely on a documented allowlist entry in
See the action run for full details. |
|
Important Cloud Posse Engineering Team Review RequiredThis pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes. To expedite this process, reach out to us on Slack in the |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3260 +/- ##
==========================================
- Coverage 84.68% 84.67% -0.02%
==========================================
Files 2105 2105
Lines 206759 206759
==========================================
- Hits 175092 175067 -25
- Misses 23401 23416 +15
- Partials 8266 8276 +10
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
CI timing summaryLatest completed GitHub Actions runs for
Wall-clock time spans the earliest included workflow creation through the latest completion. Aggregate runner time adds each job's execution time, so concurrent jobs are counted separately.
Longest jobs (top 10)
Updated automatically when a PR workflow finishes. |
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Bumps the cicd group with 10 updates:
0.171.00.173.04.38.04.38.14.38.04.38.14.38.04.38.14.38.04.38.10.170.00.173.03.5.03.6.07.0.07.1.13.97.43.97.56.2.46.3.0Updates
cloudposse/.github/.github/workflows/shared-release-branches.ymlfrom 0.171.0 to 0.173.0Release notes
Sourced from cloudposse/.github/.github/workflows/shared-release-branches.yml's releases.
Commits
281621dfeat(readme): render deprecation notices above the introduction (#283)1bce210chore: right-size RunsOn volumes (#282)Updates
github/codeql-action/upload-sariffrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/initfrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/autobuildfrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/autobuild's releases.
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/analyzefrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
cloudposse/.github/.github/workflows/shared-go-auto-release.ymlfrom 0.170.0 to 0.173.0Release notes
Sourced from cloudposse/.github/.github/workflows/shared-go-auto-release.yml's releases.
... (truncated)
Commits
281621dfeat(readme): render deprecation notices above the introduction (#283)1bce210chore: right-size RunsOn volumes (#282)4e05ff6fix: re-mint GitHub App token before goreleaser to avoid mid-run expiry (#281)Updates
cloudposse/github-action-setup-atmosfrom 3.5.0 to 3.6.0Release notes
Sourced from cloudposse/github-action-setup-atmos's releases.
Commits
9e8d1e2ci: use free hosted runner for install tests (#121)Updates
codecov/codecov-actionfrom 7.0.0 to 7.1.1Release notes
Sourced from codecov/codecov-action's releases.
Commits
303a32dchore(release): 7.1.1 (#1973)0b35c9echore(release): 7.1.0 (#1971)Updates
trufflesecurity/trufflehogfrom 3.97.4 to 3.97.5Release notes
Sourced from trufflesecurity/trufflehog's releases.
Commits
f714bf4[SCAN-177] Purge secret parts from verification cache (#5318)4ecb5c6Add elasticsearch source documentation (#5284)8d77a9dAdd filesystem source documentation (#5285)b8a71eeAdd documentation for CircleCI source (#5268)b1d7daeperf(engine): lowercase prefilter chunks as ASCII in a pooled buffer (#5291)07e3ac7Introduce a new optional detector interface that will allow us to verify cred...5a6944eci: avoid Node 20 BuildPulse action (#5266)ce7b2b8fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)58bf481Postgres: drop non-connection URI params before verifying (#5296)82fd19cAdding no-ignore flag to allow reporting of "ignored" secrets (#5297)Updates
aws-actions/configure-aws-credentialsfrom 6.2.4 to 6.3.0Release notes
Sourced from aws-actions/configure-aws-credentials's releases.
Changelog
Sourced from aws-actions/configure-aws-credentials's changelog.
... (truncated)
Commits
e125382chore(main): release 6.3.0 (#1963)438100achore: add link to GH security docs (#1962)e92ebccchore: Update dist57b8365feat: add translate-env-variables option (#1961)cc49fa7chore(docs): README main branch guidance (#1960)866cb16chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (#1958)6782cb1chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (#1951)c20509achore: Update dist7a41fc6chore(deps): bump@aws-sdk/client-stsfrom 3.1121.0 to 3.1127.0 (#1954)726b713chore(deps-dev): bump@biomejs/biomefrom 2.5.11 to 2.5.12 (#1957)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions