From e6b88e7eecc84d7e2766220ed9bd755c0d78b7ff Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 2 Apr 2026 01:45:54 +0000 Subject: [PATCH] Bump the github-actions group with 12 updates Bumps the github-actions group with 12 updates: | Package | From | To | | --- | --- | --- | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.7.0` | `4.0.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.1` | `0.24.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.4.0` | `7.0.0` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.3.1` | `7.4.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6` | `7` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `6` | `8` | | [docker/setup-compose-action](https://github.com/docker/setup-compose-action) | `1.2.0` | `2.1.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.0.0` | | [actions/attest-sbom](https://github.com/actions/attest-sbom) | `3` | `4` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3` | `4` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `b78fbfd8eb982f4802e09a265fb2bc37b3040975` | `e48f9039c82786db50685e8ef7d980b209f06186` | Updates `docker/setup-qemu-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](https://github.com/docker/setup-qemu-action/compare/c7c53464625b32c7a7e944ae62b3e17d2b600130...ce360397dd3f832beb865e1373c09c0e9f86d70a) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/8d2750c68a42422c14e847fe6c8ac0403b4cbd6f...4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd) Updates `anchore/sbom-action` from 0.22.1 to 0.24.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/sbom-action/compare/deef08a0db64bfad603422135db61477b16cef56...e22c389904149dbc22b58101806040fa8d37a610) Updates `goreleaser/goreleaser-action` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](https://github.com/goreleaser/goreleaser-action/compare/e435ccd777264be153ace6237001ef4d979d3a7a...ec59f474b9834571250b370d4735c50f8e2d1e29) Updates `anchore/scan-action` from 7.3.1 to 7.4.0 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/scan-action/compare/8d2fce09422cd6037e577f4130e9b925e9a37175...e1165082ffb1fe366ebaf02d8526e7c4989ea9d2) Updates `actions/upload-artifact` from 6 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v6...v7) Updates `actions/download-artifact` from 6 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v6...v8) Updates `docker/setup-compose-action` from 1.2.0 to 2.1.0 - [Release notes](https://github.com/docker/setup-compose-action/releases) - [Commits](https://github.com/docker/setup-compose-action/compare/364cc21a5de5b1ee4a7f5f9d3fa374ce0ccde746...8cccb8c14b6500aaffebff1aa49c502c34d2e5e6) Updates `docker/login-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...b45d80f862d83dbcd57f89517bcf500b2ab88fb2) Updates `actions/attest-sbom` from 3 to 4 - [Release notes](https://github.com/actions/attest-sbom/releases) - [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-sbom/compare/v3...v4) Updates `actions/attest-build-provenance` from 3 to 4 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/v3...v4) Updates `trufflesecurity/trufflehog` from b78fbfd8eb982f4802e09a265fb2bc37b3040975 to e48f9039c82786db50685e8ef7d980b209f06186 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](https://github.com/trufflesecurity/trufflehog/compare/b78fbfd8eb982f4802e09a265fb2bc37b3040975...e48f9039c82786db50685e8ef7d980b209f06186) --- updated-dependencies: - dependency-name: docker/setup-qemu-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: goreleaser/goreleaser-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/scan-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-compose-action dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/attest-sbom dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: e48f9039c82786db50685e8ef7d980b209f06186 dependency-type: direct:production dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/make.yaml | 30 +++++++++++++++--------------- .github/workflows/release.yaml | 30 +++++++++++++++--------------- .github/workflows/secrets.yaml | 2 +- 3 files changed, 31 insertions(+), 31 deletions(-) diff --git a/.github/workflows/make.yaml b/.github/workflows/make.yaml index 1486c5d7c..fe411ec2f 100644 --- a/.github/workflows/make.yaml +++ b/.github/workflows/make.yaml @@ -32,8 +32,8 @@ jobs: cache: "npm" - run: "npm i -g npm@11.8.0" - run: "npm ci" - - uses: "docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130" # v3.7.0 - - uses: "docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f" # v3.12.0 + - uses: "docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a" # v4.0.0 + - uses: "docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd" # v4.0.0 - uses: "sigstore/cosign-installer@053f9b74638557590800a301da1ba82351507e2c" # v3.8.1 - name: Cache Trivy database uses: "actions/cache@v5" @@ -42,8 +42,8 @@ jobs: key: trivy-db-${{ runner.os }}-${{ github.run_id }} restore-keys: | trivy-db-${{ runner.os }}- - - uses: "anchore/sbom-action/download-syft@deef08a0db64bfad603422135db61477b16cef56" # v0.22.1 - - uses: "goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a" # v6.4.0 + - uses: "anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610" # v0.24.0 + - uses: "goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29" # v7.0.0 with: distribution: "goreleaser" version: "~> v2" @@ -78,12 +78,12 @@ jobs: uses: github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1 with: sarif_file: "trivy-results.sarif" - - uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1 + - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0 with: path: ./ format: cyclonedx-json output-file: sbom.json - - uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1 + - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0 with: sbom: "sbom.json" fail-build: true @@ -111,7 +111,7 @@ jobs: - run: "npm i -g npm@11.8.0" - run: "npm ci" - run: "make build" - - uses: "actions/upload-artifact@v6" + - uses: "actions/upload-artifact@v7" with: name: "build-artifacts" path: | @@ -148,7 +148,7 @@ jobs: - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - run: "npm i -g npm@11.8.0" - run: "npm ci" - - uses: "actions/download-artifact@v6" + - uses: "actions/download-artifact@v8" with: name: "build-artifacts" - run: "chmod +x bin/probod" @@ -195,7 +195,7 @@ jobs: go-version: "1.26.1" cache: true - run: "go mod download" - - uses: "actions/download-artifact@v6" + - uses: "actions/download-artifact@v8" with: name: "build-artifacts" - run: "chmod +x bin/probod" @@ -204,14 +204,14 @@ jobs: env: GOTESTSUM_JUNITFILE: "junit.xml" - name: "Upload test results" - uses: "actions/upload-artifact@v6" + uses: "actions/upload-artifact@v7" if: "always()" with: name: "junit-results" path: "junit.xml" retention-days: 30 - run: "make coverage-report" - - uses: "actions/upload-artifact@v6" + - uses: "actions/upload-artifact@v7" with: name: "coverage-reports" path: | @@ -249,9 +249,9 @@ jobs: - run: "npm i -g npm@11.8.0" - run: "sudo apt-get install -y mkcert" - run: "sudo mkcert -install 2>&1 | grep -v 'no Firefox and/or Chrome/Chromium security databases found' || true" - - uses: "docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130" # v3.7.0 - - uses: "docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f" # v3.12.0 - - uses: "docker/setup-compose-action@364cc21a5de5b1ee4a7f5f9d3fa374ce0ccde746" # v1.2.0 + - uses: "docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a" # v4.0.0 + - uses: "docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd" # v4.0.0 + - uses: "docker/setup-compose-action@8cccb8c14b6500aaffebff1aa49c502c34d2e5e6" # v2.1.0 - run: "npm ci" - run: "make stack-up" - run: "make stack-ps" @@ -276,7 +276,7 @@ jobs: env: GOTESTSUM_JUNITFILE: "junit-e2e.xml" - name: "Upload test results" - uses: "actions/upload-artifact@v6" + uses: "actions/upload-artifact@v7" if: "always()" with: name: "junit-e2e-results" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 79311a8ff..49be8a860 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -54,22 +54,22 @@ jobs: run: cosign initialize - name: Set up Docker Buildx - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 - name: Set up QEMU - uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0 + uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0 with: platforms: all - name: Log in to GitHub Container Registry - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 + uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Run GoReleaser - uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0 + uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v7.0.0 with: distribution: goreleaser version: "~> v2" @@ -96,14 +96,14 @@ jobs: sarif_file: "trivy-results.sarif" - name: Generate SBOM - uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1 + uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0 with: path: ./ format: cyclonedx-json output-file: sbom.json - name: Run vulnerability scan - uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1 + uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0 with: sbom: "sbom.json" fail-build: true @@ -122,13 +122,13 @@ jobs: echo "hashes=$(cat checksums.txt | base64 -w0)" >> "$GITHUB_OUTPUT" - name: Attest SBOM - uses: actions/attest-sbom@v3 + uses: actions/attest-sbom@v4 with: subject-path: "dist/*.tar.gz, dist/*.zip" sbom-path: "sbom.json" - name: Attest build provenance - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-path: "dist/*.tar.gz, dist/*.zip" @@ -141,14 +141,14 @@ jobs: echo "digest=$DIGEST" >> "$GITHUB_OUTPUT" - name: Attest Docker image SBOM - uses: actions/attest-sbom@v3 + uses: actions/attest-sbom@v4 with: subject-name: "ghcr.io/getprobo/probo" subject-digest: ${{ steps.image.outputs.digest }} sbom-path: "sbom.json" - name: Upload SBOM as artifact - uses: actions/upload-artifact@v6 + uses: actions/upload-artifact@v7 with: name: sbom path: | @@ -183,13 +183,13 @@ jobs: VERSION="${GITHUB_REF_NAME#v}" npm --workspace @probo/n8n-nodes-probo version "$VERSION" --no-git-tag-version - - uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1 + - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0 with: path: ./packages/n8n-node format: cyclonedx-json output-file: packages/n8n-node/sbom.json - - uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1 + - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0 with: path: ./packages/n8n-node fail-build: true @@ -207,16 +207,16 @@ jobs: - run: npm --workspace @probo/n8n-nodes-probo publish --access public --dry-run - run: npm --workspace @probo/n8n-nodes-probo publish --access public - - uses: actions/attest-sbom@v3 + - uses: actions/attest-sbom@v4 with: subject-path: "packages/n8n-node/dist/**" sbom-path: "packages/n8n-node/sbom.json" - - uses: actions/attest-build-provenance@v3 + - uses: actions/attest-build-provenance@v4 with: subject-path: "packages/n8n-node/dist/**" - - uses: actions/upload-artifact@v6 + - uses: actions/upload-artifact@v7 with: name: npm-sbom path: | diff --git a/.github/workflows/secrets.yaml b/.github/workflows/secrets.yaml index e06105027..e1635587e 100644 --- a/.github/workflows/secrets.yaml +++ b/.github/workflows/secrets.yaml @@ -17,6 +17,6 @@ jobs: with: fetch-depth: 0 submodules: recursive - - uses: "trufflesecurity/trufflehog@b78fbfd8eb982f4802e09a265fb2bc37b3040975" # main + - uses: "trufflesecurity/trufflehog@e48f9039c82786db50685e8ef7d980b209f06186" # main with: extra_args: "--results=verified,unknown --exclude-paths=.trufflehog-exclude"