Bump the github-actions group with 4 updates #1868
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 4 updates: actions/checkout, actions/upload-artifact, ossf/scorecard-action and github/codeql-action.
Updates
actions/checkout
from 3.1.0 to 4.1.0Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
8ade135
Prepare 4.1.0 release (#1496)c533a0a
Add support for partial checkout filters (#1396)72f2cec
Update README.md for V4 (#1452)3df4ab1
Release 4.0.0 (#1447)8b5e8b7
Support fetching without the --progress option (#1067)97a652b
Update default runtime to node20 (#1436)f43a0e5
Release 3.6.0 (#1437)7739b9b
Add option to fetch tags even if fetch-depth > 0 (#579)96f5310
Mark test scripts with Bash'isms to be run via Bash (#1377)c85c95e
Release v3.5.3 (#1376)Updates
actions/upload-artifact
from 3.1.0 to 3.1.3Release notes
Sourced from actions/upload-artifact's releases.
Commits
a8a3f3a
Merge pull request #436 from bethanyj28/main7b48769
update dependency cache6663039
update dist/index.js55e76b7
bump@actions/artifact
version65d8626
chore(github): remove trailing whitespaces (#313)0b7f8ab
ci(github): update action/download-artifact from v1 to v3 (#312)013d2b8
Create devcontainer for codespaces + update all dev dependencies (#375)055b8b3
Bump Actions NPM dependencies (#374)7a5d483
ci(github): update action/checkout from v2 to v3 (#315)e0057a5
README: Bump actions/checkout to v3 (#352)Updates
ossf/scorecard-action
from 2.1.2 to 2.2.0Release notes
Sourced from ossf/scorecard-action's releases.
Commits
08b4669
🌱 Bump docker tag to for v2.2.0 release. (#1194)3c7470f
📖 Update README badge link to use new uri param. (#1185)a164dbc
🌱 Bump github.com/ossf/scorecard/v4 from v4.10.5 to v4.11.0 (#1192)597960e
📖 Update README to accept fine-grained tokens (#1175)8808ed2
🌱 Retry external network calls when publishing results (#1191)0eed6cb
🌱 Bump golang.org/x/net from 0.10.0 to 0.11.06c6335c
🌱 Bump github/codeql-action from 2.3.6 to 2.20.07f1baf3
📖 Switch recommended badge link to the new viewer. (#1176)df98bbc
🌱 Bump actions/checkout from 3.5.2 to 3.5.375886d4
🌱 Bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 (#1172)Updates
github/codeql-action
from 2.2.4 to 2.21.9Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
ddccb87
Merge pull request #1905 from github/update-v2.21.9-27cb1e1ded8cb5a2
Update changelog for v2.21.927cb1e1
Bump the npm group with 6 updates (#1902)4818fdd
Merge pull request #1903 from github/henrymercer/sublanguage-file-coveragee548601
Merge pull request #1897 from github/update-bundle/codeql-bundle-v2.14.6cc65420
Merge branch 'main' into update-bundle/codeql-bundle-v2.14.6c95737b
Add changelog note41d2ffa
Enable sub-language file coverage behind a ff650a85e
Merge pull request #1901 from github/henrymercer/check-for-duplicated-languages0de36d4
Merge branch 'main' into henrymercer/check-for-duplicated-languagesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions