-
Notifications
You must be signed in to change notification settings - Fork 31
chore(deps): bump the actions-deps group across 1 directory with 17 updates #401
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
son-oz
merged 1 commit into
main
from
dependabot/github_actions/actions-deps-ed62b2e922
Nov 14, 2025
Merged
chore(deps): bump the actions-deps group across 1 directory with 17 updates #401
son-oz
merged 1 commit into
main
from
dependabot/github_actions/actions-deps-ed62b2e922
Nov 14, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…pdates Bumps the actions-deps group with 17 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.13.0` | `2.13.2` | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `212f9a7760ad2b8eb511185b841f3725a62c2ae0` | `70069877f29101175ed2b055d210fe8b1d54d7d7` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.4.3` | `5.5.1` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `e77e8065d9f7ec6abdd9838668cd7b43924dd64d` | `c7c53464625b32c7a7e944ae62b3e17d2b600130` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.0.0` | `7.1.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.28.15` | `4.31.2` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `5.0.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `6.0.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `97d42c1b50f585f357413698aa1b779307aa0d52` | `5be0e66d93ac7ed76da52eca8bb058f665c3a5fe` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.7.0` | `5.9.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.6.0` | | [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description) | `a701644270a123c7b02b318a8e4fe71e15a8f3cb` | `f1b86635715271fbb2edb38dd0ed1706e6da198b` | | [googleapis/release-please-action](https://github.com/googleapis/release-please-action) | `4.2.0` | `4.4.0` | | [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `1.5.2` | `2.0.5` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.20.6` | `0.20.9` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.3` | Updates `step-security/harden-runner` from 2.13.0 to 2.13.2 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@ec9f2d5...95d9a5d) Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@11bd719...08c6903) Updates `tj-actions/changed-files` from 212f9a7760ad2b8eb511185b841f3725a62c2ae0 to 70069877f29101175ed2b055d210fe8b1d54d7d7 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@212f9a7...7006987) Updates `codecov/codecov-action` from 5.4.3 to 5.5.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@18283e0...5a10915) Updates `docker/setup-qemu-action` from e77e8065d9f7ec6abdd9838668cd7b43924dd64d to c7c53464625b32c7a7e944ae62b3e17d2b600130 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@e77e806...c7c5346) Updates `anchore/scan-action` from 7.0.0 to 7.1.0 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](anchore/scan-action@f660128...568b89d) Updates `github/codeql-action` from 3.28.15 to 4.31.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3.28.15...0499de3) Updates `actions/upload-artifact` from 4.6.2 to 5.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...330a01c) Updates `actions/download-artifact` from 4.3.0 to 6.0.0 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@d3f86a1...018cc2c) Updates `softprops/action-gh-release` from 97d42c1b50f585f357413698aa1b779307aa0d52 to 5be0e66d93ac7ed76da52eca8bb058f665c3a5fe - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@97d42c1...5be0e66) Updates `docker/metadata-action` from 5.7.0 to 5.9.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@902fa8e...318604b) Updates `docker/login-action` from 3.4.0 to 3.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...5e57cd1) Updates `peter-evans/dockerhub-description` from a701644270a123c7b02b318a8e4fe71e15a8f3cb to f1b86635715271fbb2edb38dd0ed1706e6da198b - [Release notes](https://github.com/peter-evans/dockerhub-description/releases) - [Commits](peter-evans/dockerhub-description@a701644...f1b8663) Updates `googleapis/release-please-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@a02a34c...16a9c90) Updates `iarekylew00t/verified-bot-commit` from 1.5.2 to 2.0.5 - [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases) - [Commits](IAreKyleW00t/verified-bot-commit@cd576ea...68c52be) Updates `anchore/sbom-action` from 0.20.6 to 0.20.9 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f8bdd1d...8e94d75) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@f49aabe...4eaacf0) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: tj-actions/changed-files dependency-version: 70069877f29101175ed2b055d210fe8b1d54d7d7 dependency-type: direct:production dependency-group: actions-deps - dependency-name: codecov/codecov-action dependency-version: 5.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: docker/setup-qemu-action dependency-version: c7c53464625b32c7a7e944ae62b3e17d2b600130 dependency-type: direct:production dependency-group: actions-deps - dependency-name: anchore/scan-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: github/codeql-action dependency-version: 4.31.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/upload-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/download-artifact dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: softprops/action-gh-release dependency-version: 5be0e66d93ac7ed76da52eca8bb058f665c3a5fe dependency-type: direct:production dependency-group: actions-deps - dependency-name: docker/metadata-action dependency-version: 5.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: docker/login-action dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: peter-evans/dockerhub-description dependency-version: f1b86635715271fbb2edb38dd0ed1706e6da198b dependency-type: direct:production dependency-group: actions-deps - dependency-name: googleapis/release-please-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: iarekylew00t/verified-bot-commit dependency-version: 2.0.5 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: anchore/sbom-action dependency-version: 0.20.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <[email protected]>
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
son-oz
approved these changes
Nov 14, 2025
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
cla: allowlist
cla: signed
dependencies
Pull requests that update a dependency file
github_actions
Pull requests that update GitHub Actions code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the actions-deps group with 17 updates in the / directory:
2.13.02.13.24.2.25.0.0212f9a7760ad2b8eb511185b841f3725a62c2ae070069877f29101175ed2b055d210fe8b1d54d7d75.4.35.5.1e77e8065d9f7ec6abdd9838668cd7b43924dd64dc7c53464625b32c7a7e944ae62b3e17d2b6001307.0.07.1.03.28.154.31.24.6.25.0.04.3.06.0.097d42c1b50f585f357413698aa1b779307aa0d525be0e66d93ac7ed76da52eca8bb058f665c3a5fe5.7.05.9.03.4.03.6.0a701644270a123c7b02b318a8e4fe71e15a8f3cbf1b86635715271fbb2edb38dd0ed1706e6da198b4.2.04.4.01.5.22.0.50.20.60.20.92.4.12.4.3Updates
step-security/harden-runnerfrom 2.13.0 to 2.13.2Release notes
Sourced from step-security/harden-runner's releases.
Commits
95d9a5dMerge pull request #606 from step-security/rc-2887e429dUpdate limitations.mdef891c3feat: add support for custom vm image1fa8c8aupdate agent92c522aMerge pull request #593 from step-security/ak-readme-updates4719ad5README updates4fde639Merge pull request #591 from eromosele-stepsecurity/Updf682f2fUpdate README.mdf4a75cfMerge pull request #588 from step-security/rc-2695503d0ci: remove code-review workflowUpdates
actions/checkoutfrom 4.2.2 to 5.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)08eba0bPrepare release v4.3.0 (#2237)631c7dcUpdate package dependencies (#2236)8edcb1bUpdate CODEOWNERS for actions (#2224)09d2acaUpdate README.md (#2194)85e6279Adjust positioning of user email note and permissions heading (#2044)009b9aeDocumentation update - add recommended permissions to Readme (#2043)cbb7224Update README.md (#1977)3b9b8c8docs: update README.md (#1971)Updates
tj-actions/changed-filesfrom 212f9a7760ad2b8eb511185b841f3725a62c2ae0 to 70069877f29101175ed2b055d210fe8b1d54d7d7Changelog
Sourced from tj-actions/changed-files's changelog.
... (truncated)
Commits
7006987chore(deps): bump@octokit/restfrom 22.0.0 to 22.0.1 (#2705)5df1badchore(deps-dev): bump@types/nodefrom 24.9.2 to 24.10.0 (#2707)0ff001dchore(deps-dev): bump ts-jest from 29.4.4 to 29.4.5 (#2688)52b808achore(deps-dev): bump@types/micromatchfrom 4.0.9 to 4.0.10 (#2699)d6388b7chore(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 (#2697)cf5e80achore(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#2698)cff4543chore(deps-dev): bump@types/nodefrom 24.9.1 to 24.9.2 (#2700)9dc1b5fchore(deps): bump github/codeql-action from 4.30.9 to 4.31.2 (#2702)dbf178cchore(deps): bump actions/setup-node from 5.0.0 to 6.0.0 (#2690)1900262chore(deps): bump github/codeql-action from 3.30.6 to 4.30.9 (#2693)Updates
codecov/codecov-actionfrom 5.4.3 to 5.5.1Release notes
Sourced from codecov/codecov-action's releases.
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)a4803c1build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)3139621build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)fdcc847chore(release): 5.5.0 (#1865)Updates
docker/setup-qemu-actionfrom e77e8065d9f7ec6abdd9838668cd7b43924dd64d to c7c53464625b32c7a7e944ae62b3e17d2b600130Commits
c7c5346Merge pull request #230 from docker/dependabot/npm_and_yarn/docker/actions-to...3a517a1chore: update generated contenta5b45edbuild(deps): bump@docker/actions-toolkitfrom 0.62.1 to 0.67.03a64278Merge pull request #220 from docker/dependabot/npm_and_yarn/brace-expansion-1...94906bachore: update generated content4027abfbuild(deps): bump brace-expansion from 1.1.11 to 1.1.12bee0aaaMerge pull request #221 from docker/dependabot/npm_and_yarn/tmp-0.2.40d7e257chore: update generated contentb869601build(deps): bump tmp from 0.2.3 to 0.2.43a043edMerge pull request #219 from docker/dependabot/npm_and_yarn/undici-5.29.0Updates
anchore/scan-actionfrom 7.0.0 to 7.1.0Release notes
Sourced from anchore/scan-action's releases.
Commits
568b89dchore(deps): update Grype to v0.102.0 (#536)f8889b1chore(deps-dev): bump lint-staged from 16.2.5 to 16.2.6 (#535)7c6e0bcchore(deps-dev): bump eslint from 9.37.0 to 9.38.0 (#533)7891b04chore(deps-dev): bump lint-staged from 16.2.4 to 16.2.5 (#534)a5605ebchore(deps): update Grype to v0.101.1 (#532)9e84288chore(deps): update Grype to v0.101.0 (#530)109c104chore(deps): bump@actions/cachefrom 4.0.3 to 4.1.0 (#522)c455b6fchore(deps-dev): bump eslint from 9.36.0 to 9.37.0 (#526)cdad80achore(deps-dev): bump jest from 30.1.3 to 30.2.0 (#525)45eec0dchore(deps-dev): bump lint-staged from 16.2.1 to 16.2.4 (#528)Updates
github/codeql-actionfrom 3.28.15 to 4.31.2Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
0499de3Merge pull request #3261 from github/henrymercer/setup-python3b96745Set up Python in mergeback workflow8a06050Merge pull request #3259 from github/update-v4.31.2-9576b5cbe752a642Update changelog for v4.31.29576b5cMerge pull request #3258 from github/mbg/enablement-errors/case-insensitivecc88437Merge pull request #3257 from github/henrymercer/ubuntu-slimf0e9bf0MakeisEnablementErrorcase-insensitive2a3599cRun lightweight workflows onubuntu-slim514ff4dMerge pull request #3256 from github/henrymercer/resolve-bad-mergeaab1c2fMerge pull request #3253 from github/mergeback/v4.31.1-to-main-5fe9434cUpdates
actions/upload-artifactfrom 4.6.2 to 5.0.0Release notes
Sourced from actions/upload-artifact's releases.