Skip to content

Commit 3e759d7

Browse files
ci(deps): bump the github-actions group with 3 updates (#16)
Bumps the github-actions group with 3 updates: [graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm), [actions/download-artifact](https://github.com/actions/download-artifact) and [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer). Updates `graalvm/setup-graalvm` from 1.4.5 to 1.5.0 - [Release notes](https://github.com/graalvm/setup-graalvm/releases) - [Commits](graalvm/setup-graalvm@54b4f5a...f744c72) Updates `actions/download-artifact` from 8.0.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@70fc10c...3e5f45b) Updates `sigstore/cosign-installer` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@faadad0...ba7bc0a) --- updated-dependencies: - dependency-name: graalvm/setup-graalvm dependency-version: 1.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: sigstore/cosign-installer dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Mikaël Barbero <mikael.barbero@eclipse-foundation.org>
1 parent 9345001 commit 3e759d7

3 files changed

Lines changed: 9 additions & 9 deletions

File tree

.github/workflows/release.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -170,43 +170,43 @@ jobs:
170170
# validates the native-image version even though no native compilation
171171
# happens in this job.
172172
- name: Set up GraalVM
173-
uses: graalvm/setup-graalvm@54b4f5a65c1a84b2fdfdc2078fe43df32819e4b1 # v1.4.5
173+
uses: graalvm/setup-graalvm@f744c72a42b1995d7b0cbc314bde4bace7ac1fe1 # v1.5.0
174174
with:
175175
java-version: '21'
176176
distribution: 'graalvm-community'
177177

178178
- name: Download native binary (linux-x86_64)
179-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
179+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
180180
with:
181181
name: csi-codesign-linux-x86_64
182182
path: out/linux-x86_64
183183

184184
- name: Download native binary (linux-aarch_64)
185-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
185+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
186186
with:
187187
name: csi-codesign-linux-aarch_64
188188
path: out/linux-aarch_64
189189

190190
- name: Download native binary (osx-aarch_64)
191-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
191+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
192192
with:
193193
name: csi-codesign-osx-aarch_64
194194
path: out/osx-aarch_64
195195

196196
- name: Download native binary (osx-x86_64)
197-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
197+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
198198
with:
199199
name: csi-codesign-osx-x86_64
200200
path: out/osx-x86_64
201201

202202
- name: Download native binary (windows-x86_64)
203-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
203+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
204204
with:
205205
name: csi-codesign-windows-x86_64
206206
path: out/windows-x86_64
207207

208208
- name: Download CLI fat JAR
209-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
209+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
210210
with:
211211
name: cli-fatjar
212212
path: out/cli-fatjar

.github/workflows/reusable-native-build.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ jobs:
6060
persist-credentials: false
6161

6262
- name: Set up GraalVM
63-
uses: graalvm/setup-graalvm@54b4f5a65c1a84b2fdfdc2078fe43df32819e4b1 # v1.4.5
63+
uses: graalvm/setup-graalvm@f744c72a42b1995d7b0cbc314bde4bace7ac1fe1 # v1.5.0
6464
with:
6565
java-version: '21'
6666
distribution: 'graalvm-community'

.github/workflows/sast.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ jobs:
9090
echo "opengrep=${opengrep}" >> "$GITHUB_OUTPUT"
9191
9292
- name: Install Cosign
93-
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
93+
uses: sigstore/cosign-installer@ba7bc0a3fef59531c69a25acd34668d6d3fe6f22 # v4.1.0
9494

9595
- name: Download Opengrep
9696
env:

0 commit comments

Comments
 (0)