From ef87fa981da4e8d1b6524ee02632f6714a43eb90 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 21:11:37 +0000 Subject: [PATCH] Bump the github-actions group with 8 updates Bumps the github-actions group with 8 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `6` | `7` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `9.2.1` | `9.3.0` | | [docker/setup-compose-action](https://github.com/docker/setup-compose-action) | `2.2.0` | `2.3.0` | | [azure/setup-helm](https://github.com/azure/setup-helm) | `5.0.0` | `5.0.1` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.0` | `4.1.1` | | [actions/attest](https://github.com/actions/attest) | `4.1.0` | `4.1.1` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.32.1` | `4.36.2` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.95.5` | `3.95.7` | Updates `actions/checkout` from 6 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v6...v7) Updates `golangci/golangci-lint-action` from 9.2.1 to 9.3.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd2ee...ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a) Updates `docker/setup-compose-action` from 2.2.0 to 2.3.0 - [Release notes](https://github.com/docker/setup-compose-action/releases) - [Commits](https://github.com/docker/setup-compose-action/compare/16feee727cbdc83b6a014e6cc26fec4a79bcf30c...4eb059ff7f16592f9c84d5ca339c53cb7c5064e2) Updates `azure/setup-helm` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/azure/setup-helm/releases) - [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md) - [Commits](https://github.com/azure/setup-helm/compare/dda3372f752e03dde6b3237bc9431cdc2f7a02a2...9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310) Updates `actions/attest-build-provenance` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32...0f67c3f4856b2e3261c31976d6725780e5e4c373) Updates `actions/attest` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest/compare/59d89421af93a897026c735860bf21b6eb4f7b26...a1948c3f048ba23858d222213b7c278aabede763) Updates `github/codeql-action/upload-sarif` from 4.32.1 to 4.36.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/6bc82e05fd0ea64601dd4b465378bbcf57de0314...8aad20d150bbac5944a9f9d289da16a4b0d87c1e) Updates `trufflesecurity/trufflehog` from 3.95.5 to 3.95.7 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](https://github.com/trufflesecurity/trufflehog/compare/d411fff7b8879a62509f3fa98c07f247ac089a51...f446421baf832d6356c42c1743d99abff52ff334) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: golangci/golangci-lint-action dependency-version: 9.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-compose-action dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: azure/setup-helm dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/attest dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.95.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/codeql.yml | 2 +- .github/workflows/make.yaml | 26 +++++++++---------- .github/workflows/release-helm.yaml | 6 ++--- .../workflows/release-npm-cookie-banner.yaml | 4 +-- .github/workflows/release-npm-n8n-node.yaml | 4 +-- .github/workflows/release-prb.yaml | 6 ++--- .github/workflows/release-probo-agent.yaml | 6 ++--- .../workflows/release-probod-bootstrap.yaml | 6 ++--- .github/workflows/release-probod.yaml | 16 ++++++------ .github/workflows/secrets.yaml | 4 +-- 10 files changed, 40 insertions(+), 40 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index a1c551123..a5744d3e5 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -48,7 +48,7 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: submodules: recursive diff --git a/.github/workflows/make.yaml b/.github/workflows/make.yaml index 3966288c9..3bef21f6c 100644 --- a/.github/workflows/make.yaml +++ b/.github/workflows/make.yaml @@ -19,7 +19,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -67,7 +67,7 @@ jobs: - { goos: openbsd, goarch: amd64 } - { goos: openbsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -126,7 +126,7 @@ jobs: - { goos: freebsd, goarch: amd64 } - { goos: freebsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -165,7 +165,7 @@ jobs: platform: "linux/arm64" runner: "4cpu-linux-arm64" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - uses: "docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5" # v4.1.0 - uses: "docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee" # v4.2.0 @@ -213,7 +213,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -236,7 +236,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -274,7 +274,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -295,14 +295,14 @@ jobs: contents: "read" pull-requests: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - uses: "./.github/actions/setup" with: node: "false" - - uses: golangci/golangci-lint-action@82606bf257cbaff209d206a39f5134f0cfbfd2ee # v9.2.1 + - uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: version: v2.12.2 install-only: true @@ -352,7 +352,7 @@ jobs: contents: "read" pull-requests: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -380,7 +380,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -421,12 +421,12 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - uses: "./.github/actions/setup" - - uses: "docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c" # v2.2.0 + - uses: "docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2" # v2.3.0 - uses: "docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee" # v4.2.0 with: registry: artifact.probo.inc diff --git a/.github/workflows/release-helm.yaml b/.github/workflows/release-helm.yaml index 1d9d1001e..eccd7bc5f 100644 --- a/.github/workflows/release-helm.yaml +++ b/.github/workflows/release-helm.yaml @@ -15,9 +15,9 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - - uses: "azure/setup-helm@dda3372f752e03dde6b3237bc9431cdc2f7a02a2" # v5.0.0 + - uses: "azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310" # v5.0.1 with: version: "3.17.3" - name: "Validate chart version" @@ -55,7 +55,7 @@ jobs: permissions: contents: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 diff --git a/.github/workflows/release-npm-cookie-banner.yaml b/.github/workflows/release-npm-cookie-banner.yaml index 7df81a6df..5b8280752 100644 --- a/.github/workflows/release-npm-cookie-banner.yaml +++ b/.github/workflows/release-npm-cookie-banner.yaml @@ -17,7 +17,7 @@ jobs: id-token: write attestations: write steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 submodules: recursive @@ -60,7 +60,7 @@ jobs: with: subject-path: "packages/cookie-banner/dist/**" sbom-path: "packages/cookie-banner/sbom.json" - - uses: "actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32" # v4 + - uses: "actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373" # v4 with: subject-path: "packages/cookie-banner/dist/**" - name: "Extract release notes" diff --git a/.github/workflows/release-npm-n8n-node.yaml b/.github/workflows/release-npm-n8n-node.yaml index 694a253d0..06a79f810 100644 --- a/.github/workflows/release-npm-n8n-node.yaml +++ b/.github/workflows/release-npm-n8n-node.yaml @@ -17,7 +17,7 @@ jobs: id-token: write attestations: write steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 submodules: recursive @@ -60,7 +60,7 @@ jobs: with: subject-path: "packages/n8n-node/dist/**" sbom-path: "packages/n8n-node/sbom.json" - - uses: "actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32" # v4 + - uses: "actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373" # v4 with: subject-path: "packages/n8n-node/dist/**" - name: "Extract release notes" diff --git a/.github/workflows/release-prb.yaml b/.github/workflows/release-prb.yaml index fe22322c7..30cd0df95 100644 --- a/.github/workflows/release-prb.yaml +++ b/.github/workflows/release-prb.yaml @@ -28,7 +28,7 @@ jobs: - { goos: openbsd, goarch: amd64 } - { goos: openbsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -90,7 +90,7 @@ jobs: id-token: "write" attestations: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -123,7 +123,7 @@ jobs: subject-path: "archives/*.tar.gz, archives/*.zip" sbom-path: "sbom.json" - name: "Attest build provenance for archives" - uses: "actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32" # v4 + uses: "actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373" # v4 with: subject-path: "archives/*.tar.gz, archives/*.zip" - name: "Extract release notes" diff --git a/.github/workflows/release-probo-agent.yaml b/.github/workflows/release-probo-agent.yaml index 5d3bbb5a7..1c7703c4b 100644 --- a/.github/workflows/release-probo-agent.yaml +++ b/.github/workflows/release-probo-agent.yaml @@ -27,7 +27,7 @@ jobs: - { goos: freebsd, goarch: amd64 } - { goos: freebsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -91,7 +91,7 @@ jobs: id-token: "write" attestations: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -124,7 +124,7 @@ jobs: subject-path: "archives/*.tar.gz, archives/*.zip" sbom-path: "sbom.json" - name: "Attest build provenance for archives" - uses: "actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32" # v4 + uses: "actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373" # v4 with: subject-path: "archives/*.tar.gz, archives/*.zip" - name: "Extract release notes" diff --git a/.github/workflows/release-probod-bootstrap.yaml b/.github/workflows/release-probod-bootstrap.yaml index a17e4061e..177e4479d 100644 --- a/.github/workflows/release-probod-bootstrap.yaml +++ b/.github/workflows/release-probod-bootstrap.yaml @@ -28,7 +28,7 @@ jobs: - { goos: openbsd, goarch: amd64 } - { goos: openbsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -90,7 +90,7 @@ jobs: id-token: "write" attestations: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -123,7 +123,7 @@ jobs: subject-path: "archives/*.tar.gz, archives/*.zip" sbom-path: "sbom.json" - name: "Attest build provenance for archives" - uses: "actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32" # v4 + uses: "actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373" # v4 with: subject-path: "archives/*.tar.gz, archives/*.zip" - name: "Extract release notes" diff --git a/.github/workflows/release-probod.yaml b/.github/workflows/release-probod.yaml index c42eca19d..c444faf5d 100644 --- a/.github/workflows/release-probod.yaml +++ b/.github/workflows/release-probod.yaml @@ -15,7 +15,7 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -61,7 +61,7 @@ jobs: - { goos: openbsd, goarch: amd64 } - { goos: openbsd, goarch: arm64 } steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 @@ -151,7 +151,7 @@ jobs: platform: "linux/arm64" runner: "4cpu-linux-arm64" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - uses: "docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5" # v4.1.0 - uses: "docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee" # v4.2.0 @@ -270,7 +270,7 @@ jobs: attestations: "write" security-events: "write" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 submodules: recursive @@ -299,16 +299,16 @@ jobs: fail-build: true severity-cutoff: critical - name: "Attest SBOM for archives" - uses: "actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26" # v4.1.0 + uses: "actions/attest@a1948c3f048ba23858d222213b7c278aabede763" # v4.1.1 with: subject-path: "archives/*.tar.gz, archives/*.zip" sbom-path: "sbom.json" - name: "Attest build provenance for archives" - uses: "actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26" # v4.1.0 + uses: "actions/attest@a1948c3f048ba23858d222213b7c278aabede763" # v4.1.1 with: subject-path: "archives/*.tar.gz, archives/*.zip" - name: "Attest Docker image SBOM" - uses: "actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26" # v4.1.0 + uses: "actions/attest@a1948c3f048ba23858d222213b7c278aabede763" # v4.1.1 with: subject-name: "artifact.probo.inc/probo/probo" subject-digest: ${{ needs.docker-manifest.outputs.digest }} @@ -324,7 +324,7 @@ jobs: vuln-type: "os,library" severity: "CRITICAL,HIGH" - name: "Upload Trivy scan results" - uses: "github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314" # v4.32.1 + uses: "github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e" # v4.36.2 if: always() with: sarif_file: "trivy-results.sarif" diff --git a/.github/workflows/secrets.yaml b/.github/workflows/secrets.yaml index 312cb2b53..535f44b1e 100644 --- a/.github/workflows/secrets.yaml +++ b/.github/workflows/secrets.yaml @@ -15,11 +15,11 @@ jobs: permissions: contents: "read" steps: - - uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6 + - uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v6 with: fetch-depth: 0 submodules: recursive - uses: "runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60" # v2 - - uses: "trufflesecurity/trufflehog@d411fff7b8879a62509f3fa98c07f247ac089a51" # main + - uses: "trufflesecurity/trufflehog@f446421baf832d6356c42c1743d99abff52ff334" # main with: extra_args: "--results=verified,unknown --exclude-paths=.trufflehog-exclude"