Skip to content

chore(deps): update github actions major (major)#151

Merged
tobybellwood merged 1 commit intomainfrom
renovate/major-github-actions-major
Sep 18, 2025
Merged

chore(deps): update github actions major (major)#151
tobybellwood merged 1 commit intomainfrom
renovate/major-github-actions-major

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 29, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Type Update Change
actions/attest-build-provenance action major v2.4.0 -> v3.0.0
actions/github-script action major v7.0.1 -> v8.0.0
actions/setup-python action major v5.6.0 -> v6.0.0
tj-actions/changed-files action major v46.0.5 -> v47.0.0

Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v3.0.0

Compare Source

What's Changed
⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/attest-build-provenance@v2.4.0...v3.0.0

actions/github-script (actions/github-script)

v8.0.0

Compare Source

v7.1.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/github-script@v7...v7.1.0

actions/setup-python (actions/setup-python)

v6.0.0

Compare Source

What's Changed

Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Enhancements:
Bug fixes:
Dependency updates:

New Contributors

Full Changelog: actions/setup-python@v5...v6.0.0

tj-actions/changed-files (tj-actions/changed-files)

v47.0.0

Compare Source

What's Changed

New Contributors

Full Changelog: tj-actions/changed-files@v46...v47.0.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Aug 29, 2025
@github-actions
Copy link

github-actions bot commented Aug 29, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/attest-build-provenance 977bb373ede98d70efdf65b84cb5f73e068dcc2a UnknownUnknown
actions/actions/github-script ed597411d8f924073f98dfc5c65a23a2325f34cd 🟢 6.5
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Maintained⚠️ 01 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
Branch-Protection⚠️ -1internal error: error during GetBranch(releases/v2): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST🟢 10SAST tool is run on all commits
Vulnerabilities🟢 46 existing vulnerabilities detected
actions/tj-actions/changed-files 24d32ffd492484c1d75e0c0b894501ddb9d30d62 🟢 6.3
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/1 approved changesets -- score normalized to 0
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 10all dependencies are pinned
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits
Vulnerabilities🟢 82 existing vulnerabilities detected
actions/actions/setup-python e797f83bcb11b83ae66e0230d6156d7c80228e7c 🟢 5.8
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1014 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Fuzzing⚠️ 0project is not fuzzed
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy🟢 9security policy file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST🟢 10SAST tool is run on all commits
Vulnerabilities⚠️ 28 existing vulnerabilities detected

Scanned Files

  • .github/workflows/athenapdf-service-image.yaml
  • .github/workflows/database-tools-image.yaml
  • .github/workflows/docker-host-image.yaml
  • .github/workflows/drush-alias-image.yaml
  • .github/workflows/insights-scanner-image.yaml
  • .github/workflows/insights-trivy-image.yaml
  • .github/workflows/logs-concentrator-image.yaml
  • .github/workflows/logs-dispatcher-image.yaml
  • .github/workflows/pr-labeller.yaml
  • .github/workflows/release-tracker.yaml

@renovate renovate bot force-pushed the renovate/major-github-actions-major branch from e0d4420 to 9292914 Compare September 4, 2025 05:47
@renovate renovate bot changed the title chore(deps): update actions/attest-build-provenance action to v3 chore(deps): update github actions major (major) Sep 4, 2025
@renovate renovate bot force-pushed the renovate/major-github-actions-major branch from 9292914 to cd85db7 Compare September 4, 2025 17:20
@renovate renovate bot force-pushed the renovate/major-github-actions-major branch from cd85db7 to fedd3da Compare September 13, 2025 23:09
@renovate renovate bot force-pushed the renovate/major-github-actions-major branch from fedd3da to 76b8939 Compare September 18, 2025 05:59
@tobybellwood tobybellwood merged commit 8d15462 into main Sep 18, 2025
14 checks passed
@renovate renovate bot deleted the renovate/major-github-actions-major branch September 18, 2025 06:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant