Skip to content

Commit c0dde50

Browse files
chore(deps): update github actions monthly minor/patch
1 parent 02a2806 commit c0dde50

File tree

8 files changed

+43
-43
lines changed

8 files changed

+43
-43
lines changed

.github/workflows/athenapdf-service-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ jobs:
8787
type=ref,event=branch
8888
-
8989
name: Set up QEMU
90-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
90+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9191
-
9292
name: Set up Docker Buildx
9393
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -106,7 +106,7 @@ jobs:
106106
password: ${{ secrets.GITHUB_TOKEN }}
107107
-
108108
name: Build and push
109-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
109+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
110110
id: build-and-push
111111
with:
112112
context: athenapdf-service
@@ -115,26 +115,26 @@ jobs:
115115
tags: ${{ steps.meta.outputs.tags }}
116116
labels: ${{ steps.meta.outputs.labels }}
117117
- name: Attest dockerhub image
118-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
118+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
119119
with:
120120
subject-digest: ${{steps.build-and-push.outputs.digest}}
121121
subject-name: index.docker.io/${{ github.repository_owner }}/athenapdf-service
122122
push-to-registry: true
123123
- name: Attest ghcr image
124-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
124+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
125125
with:
126126
subject-digest: ${{steps.build-and-push.outputs.digest}}
127127
subject-name: ghcr.io/${{ github.repository_owner }}/athenapdf-service
128128
push-to-registry: true
129-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
129+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
130130
if: startsWith(github.ref, 'refs/tags/')
131131
with:
132132
image: ghcr.io/${{ github.repository_owner }}/athenapdf-service@${{steps.build-and-push.outputs.digest}}
133133
output-file: sbom.spdx.json
134134
upload-artifact: false
135135
upload-release-assets: false
136136
- name: Release
137-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
137+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
138138
if: startsWith(github.ref, 'refs/tags/')
139139
with:
140140
files: |

.github/workflows/database-tools-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: database-tools
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/database-tools
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/database-tools
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/database-tools@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/docker-host-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: docker-host
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/docker-host
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/docker-host
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/docker-host@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/drush-alias-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: drush-alias
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/drush-alias
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/drush-alias
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/drush-alias@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/insights-scanner-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: insights-scanner
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/insights-scanner
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/insights-scanner
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/insights-scanner@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/logs-concentrator-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: logs-concentrator
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/logs-concentrator
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/logs-concentrator
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/logs-concentrator@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/logs-dispatcher-image.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
type=ref,event=branch
8787
-
8888
name: Set up QEMU
89-
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
89+
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9090
-
9191
name: Set up Docker Buildx
9292
uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -105,7 +105,7 @@ jobs:
105105
password: ${{ secrets.GITHUB_TOKEN }}
106106
-
107107
name: Build and push
108-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
108+
uses: docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
109109
id: build-and-push
110110
with:
111111
context: logs-dispatcher
@@ -114,26 +114,26 @@ jobs:
114114
tags: ${{ steps.meta.outputs.tags }}
115115
labels: ${{ steps.meta.outputs.labels }}
116116
- name: Attest dockerhub image
117-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
117+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
118118
with:
119119
subject-digest: ${{steps.build-and-push.outputs.digest}}
120120
subject-name: index.docker.io/${{ github.repository_owner }}/logs-dispatcher
121121
push-to-registry: true
122122
- name: Attest ghcr image
123-
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
123+
uses: actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2.0
124124
with:
125125
subject-digest: ${{steps.build-and-push.outputs.digest}}
126126
subject-name: ghcr.io/${{ github.repository_owner }}/logs-dispatcher
127127
push-to-registry: true
128-
- uses: anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
128+
- uses: anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
129129
if: startsWith(github.ref, 'refs/tags/')
130130
with:
131131
image: ghcr.io/${{ github.repository_owner }}/logs-dispatcher@${{steps.build-and-push.outputs.digest}}
132132
output-file: sbom.spdx.json
133133
upload-artifact: false
134134
upload-release-assets: false
135135
- name: Release
136-
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
136+
uses: softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
137137
if: startsWith(github.ref, 'refs/tags/')
138138
with:
139139
files: |

.github/workflows/ossf-analysis.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,6 @@ jobs:
2626
# of the value entered here.
2727
publish_results: true
2828
- name: Upload SARIF results to code scanning
29-
uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
29+
uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
3030
with:
3131
sarif_file: results.sarif

0 commit comments

Comments
 (0)