From decb38a83220f8eabe02f0f362b87ac33e1666ab Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 21 Jul 2026 21:34:25 +0000 Subject: [PATCH] deps(deps): bump the dependencies group with 25 updates Bumps the dependencies group with 25 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `7.0.0` | | [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain) | `3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9` | `2c7215f132e9ebf062739d9130488b56d53c060c` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.4.0` | `7.0.0` | | [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.6.0` | `8.7.0` | | [actions/labeler](https://github.com/actions/labeler) | `6.1.0` | `7.0.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.0` | `4.1.1` | | [actions/cache](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2.0.6` | `3.2.0` | | [falkcorp/gha-load-config](https://github.com/falkcorp/gha-load-config) | `1.1.5.pre.rc.1` | `1.1.5` | | [falkcorp/gha-ci-generate-matrices](https://github.com/falkcorp/gha-ci-generate-matrices) | `1.1.7` | `1.1.8` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.2` | | [falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml](https://github.com/falkcorp/github-common) | `1.10.6.pre.rc.2` | `1.10.8` | | [falkcorp/gha-release-protobuf](https://github.com/falkcorp/gha-release-protobuf) | `1.0.3.pre.rc.1` | `1.0.3` | | [falkcorp/gha-ci-workflow-helpers](https://github.com/falkcorp/gha-ci-workflow-helpers) | `1.1.5` | `1.1.6` | | [vladopajic/go-test-coverage](https://github.com/vladopajic/go-test-coverage) | `2.18.8` | `2.18.9` | | [falkcorp/gha-get-frontend-config](https://github.com/falkcorp/gha-get-frontend-config) | `1.1.5.pre.rc.1` | `1.1.5` | | [actions/stale](https://github.com/actions/stale) | `10.3.0` | `10.4.0` | | [falkcorp/gha-detect-languages](https://github.com/falkcorp/gha-detect-languages) | `1.1.6` | `1.1.7` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.0` | `3.0.2` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.36.1` | `4.37.2` | | [github/codeql-action/start-proxy](https://github.com/github/codeql-action) | `4.36.1` | `4.37.2` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.36.1` | `4.37.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.36.1` | `4.37.2` | Updates `actions/checkout` from 4.2.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4.2.2...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `actions/setup-python` from 6.2.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97) Updates `dtolnay/rust-toolchain` from 3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 to 2c7215f132e9ebf062739d9130488b56d53c060c - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](https://github.com/dtolnay/rust-toolchain/compare/3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9...2c7215f132e9ebf062739d9130488b56d53c060c) Updates `actions/setup-node` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020) Updates `actions/setup-go` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...b7ad1dad31e06c5925ef5d2fc7ad053ef454303e) Updates `super-linter/super-linter` from 8.6.0 to 8.7.0 - [Release notes](https://github.com/super-linter/super-linter/releases) - [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md) - [Commits](https://github.com/super-linter/super-linter/compare/9e863354e3ff62e0727d37183162c4a88873df41...4ce20838b8ab83717e78138c5b3a1407148e0918) Updates `actions/labeler` from 6.1.0 to 7.0.0 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](https://github.com/actions/labeler/compare/f27b608878404679385c85cfa523b85ccb86e213...bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13) Updates `actions/attest-build-provenance` from 4.1.0 to 4.1.1 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32...0f67c3f4856b2e3261c31976d6725780e5e4c373) Updates `actions/cache` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fccae...55cc8345863c7cc4c66a329aec7e433d2d1c52a9) Updates `actions/create-github-app-token` from 2.0.6 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/create-github-app-token/compare/v2.0.6...bcd2ba49218906704ab6c1aa796996da409d3eb1) Updates `falkcorp/gha-load-config` from 1.1.5.pre.rc.1 to 1.1.5 - [Release notes](https://github.com/falkcorp/gha-load-config/releases) - [Changelog](https://github.com/falkcorp/gha-load-config/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/gha-load-config/compare/bb213cbf6b6e789bea8ad0787f2914760d00536b...3ec49a74178f365d9791be2d132583a5c2578d09) Updates `falkcorp/gha-ci-generate-matrices` from 1.1.7 to 1.1.8 - [Release notes](https://github.com/falkcorp/gha-ci-generate-matrices/releases) - [Changelog](https://github.com/falkcorp/gha-ci-generate-matrices/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/gha-ci-generate-matrices/compare/8c36d080ec55e96d3532e9b02417054fc6aaaeac...7d5fdd49ccf4b6fe1cff4730e3695ebaafc4fc28) Updates `dorny/paths-filter` from 4.0.1 to 4.0.2 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](https://github.com/dorny/paths-filter/compare/fbd0ab8f3e69293af611ebaee6363fc25e6d187d...7b450fff21473bca461d4b92ce414b9d0420d706) Updates `falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml` from 1.10.6.pre.rc.2 to 1.10.8 - [Release notes](https://github.com/falkcorp/github-common/releases) - [Changelog](https://github.com/falkcorp/github-common/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/github-common/compare/1e106b5c7bc2e80beb0c6019e8ac263d41f2ed5f...d0c3326b96557c8ea9117c1c196b628e5e028186) Updates `falkcorp/gha-release-protobuf` from 1.0.3.pre.rc.1 to 1.0.3 - [Release notes](https://github.com/falkcorp/gha-release-protobuf/releases) - [Commits](https://github.com/falkcorp/gha-release-protobuf/compare/1c07a62621ea5bdaf7fd46643fd4e650c69de8d9...0e3f1f18b2f2576895c359691f57de04dd9a37fb) Updates `falkcorp/gha-ci-workflow-helpers` from 1.1.5 to 1.1.6 - [Release notes](https://github.com/falkcorp/gha-ci-workflow-helpers/releases) - [Changelog](https://github.com/falkcorp/gha-ci-workflow-helpers/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/gha-ci-workflow-helpers/compare/c8b87fae92ee0a0458e47b970ed892310323aa58...4b5f4d45d42c99d98ccf731624f2f4b91d849561) Updates `vladopajic/go-test-coverage` from 2.18.8 to 2.18.9 - [Release notes](https://github.com/vladopajic/go-test-coverage/releases) - [Commits](https://github.com/vladopajic/go-test-coverage/compare/a93b868a4cbcbf18dc3781650fad241f0020e609...5f3508324fc185e82048a2861f8bdd3d83db133b) Updates `falkcorp/gha-get-frontend-config` from 1.1.5.pre.rc.1 to 1.1.5 - [Release notes](https://github.com/falkcorp/gha-get-frontend-config/releases) - [Changelog](https://github.com/falkcorp/gha-get-frontend-config/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/gha-get-frontend-config/compare/517d41adc382a541ea13dead79a12a57a7172dcf...97f9fea2ba59e35fa23a74f0733b7a07005c5809) Updates `actions/stale` from 10.3.0 to 10.4.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899...1e223db275d687790206a7acac4d1a11bd6fe629) Updates `falkcorp/gha-detect-languages` from 1.1.6 to 1.1.7 - [Release notes](https://github.com/falkcorp/gha-detect-languages/releases) - [Changelog](https://github.com/falkcorp/gha-detect-languages/blob/main/CHANGELOG.md) - [Commits](https://github.com/falkcorp/gha-detect-languages/compare/d5712363aae458b4bbb47bbb1780f02de2a03784...b2e051b4ec8467f2a82fe195fc5a3bc3c7ccf983) Updates `softprops/action-gh-release` from 3.0.0 to 3.0.2 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/b4309332981a82ec1c5618f44dd2e27cc8bfbfda...3d0d9888cb7fd7b750713d6e236d1fcb99157228) Updates `github/codeql-action/init` from 4.36.1 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/87557b9c84dde89fdd9b10e88954ac2f4248e463...e0647621c2984b5ed2f768cb892365bf2a616ad1) Updates `github/codeql-action/start-proxy` from 4.36.1 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/87557b9c84dde89fdd9b10e88954ac2f4248e463...e0647621c2984b5ed2f768cb892365bf2a616ad1) Updates `github/codeql-action/autobuild` from 4.36.1 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/87557b9c84dde89fdd9b10e88954ac2f4248e463...e0647621c2984b5ed2f768cb892365bf2a616ad1) Updates `github/codeql-action/analyze` from 4.36.1 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/87557b9c84dde89fdd9b10e88954ac2f4248e463...e0647621c2984b5ed2f768cb892365bf2a616ad1) deps(deps-dev): bump the dependencies group with 5 updates Bumps the dependencies group with 5 updates: | Package | From | To | | --- | --- | --- | | [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.5` | `3.3.6` | | [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) | `9.39.4` | `9.39.5` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.60.1` | `8.65.0` | | [eslint](https://github.com/eslint/eslint) | `9.39.4` | `9.39.5` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.60.1` | `8.65.0` | Updates `@eslint/eslintrc` from 3.3.5 to 3.3.6 - [Release notes](https://github.com/eslint/eslintrc/releases) - [Changelog](https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md) - [Commits](https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.5...eslintrc-v3.3.6) Updates `@eslint/js` from 9.39.4 to 9.39.5 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/commits/v9.39.5/packages/js) Updates `@typescript-eslint/eslint-plugin` from 8.60.1 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin) Updates `eslint` from 9.39.4 to 9.39.5 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v9.39.4...v9.39.5) Updates `typescript-eslint` from 8.60.1 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/typescript-eslint) deps(deps): bump the dependencies group across 2 directories with 3 updates Updates the requirements on [idna](https://github.com/kjd/idna), [inquirer](https://github.com/magmax/python-inquirer) and [rich](https://github.com/Textualize/rich) to permit the latest version. Updates `idna` to 3.18 - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](https://github.com/kjd/idna/compare/v3.15...v3.18) Updates `inquirer` to 3.4.1 - [Release notes](https://github.com/magmax/python-inquirer/releases) - [Commits](https://github.com/magmax/python-inquirer/compare/v3.1.0...v3.4.1) Updates `rich` to 13.9.4 - [Release notes](https://github.com/Textualize/rich/releases) - [Changelog](https://github.com/Textualize/rich/blob/main/CHANGELOG.md) - [Commits](https://github.com/Textualize/rich/compare/v13.0.0...v13.9.4) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: dtolnay/rust-toolchain dependency-version: 2c7215f132e9ebf062739d9130488b56d53c060c dependency-type: direct:production dependency-group: dependencies - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: actions/setup-go dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: super-linter/super-linter dependency-version: 8.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: actions/labeler dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: actions/attest-build-provenance dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: falkcorp/gha-load-config dependency-version: 1.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: falkcorp/gha-ci-generate-matrices dependency-version: 1.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: dorny/paths-filter dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: falkcorp/gha-release-protobuf dependency-version: 1.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: falkcorp/gha-ci-workflow-helpers dependency-version: 1.1.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: vladopajic/go-test-coverage dependency-version: 2.18.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: falkcorp/gha-get-frontend-config dependency-version: 1.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: actions/stale dependency-version: 10.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: falkcorp/gha-detect-languages dependency-version: 1.1.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: softprops/action-gh-release dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github/codeql-action/init dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github/codeql-action/start-proxy dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github/codeql-action/autobuild dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github/codeql-action/analyze dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@eslint/eslintrc" dependency-version: 3.3.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: "@eslint/js" dependency-version: 9.39.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: eslint dependency-version: 9.39.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: typescript-eslint dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: idna dependency-version: '3.18' dependency-type: direct:production dependency-group: dependencies - dependency-name: inquirer dependency-version: 3.4.1 dependency-type: direct:production dependency-group: dependencies - dependency-name: rich dependency-version: 13.9.4 dependency-type: direct:production dependency-group: dependencies ... Signed-off-by: dependabot[bot] --- .github/workflows/auto-module-tagging.yml | 4 +- .github/workflows/ci-tests.yml | 16 +- .github/workflows/commit-override-handler.yml | 4 +- .github/workflows/documentation.yml | 4 +- .github/workflows/manager-sync-dispatcher.yml | 4 +- .github/workflows/on-release-published.yml | 6 +- .github/workflows/performance-monitoring.yml | 10 +- .github/workflows/pr-automation.yml | 30 ++-- .github/workflows/reusable-advanced-cache.yml | 8 +- .github/workflows/reusable-burndown.yml | 12 +- .github/workflows/reusable-ci-minimal.yml | 24 +-- .github/workflows/reusable-ci.yml | 90 +++++----- .../workflows/reusable-issue-automation.yml | 4 +- .github/workflows/reusable-maintenance.yml | 10 +- .github/workflows/reusable-release.yml | 38 ++-- .github/workflows/reusable-security.yml | 18 +- .github/workflows/security.yml | 16 +- .github/workflows/sync-receiver.yml | 4 +- .github/workflows/sync-repos.yml | 4 +- .github/workflows/test-super-linter.yml | 56 +++--- .github/workflows/todo-collect.yml | 4 +- .github/workflows/unified-automation.yml | 4 +- .github/workflows/workflow-analytics.yml | 4 +- package-lock.json | 162 +++++++++--------- package.json | 10 +- requirements.txt | 2 +- scripts/copilot-firewall/requirements.txt | 4 +- 27 files changed, 276 insertions(+), 276 deletions(-) mode change 100755 => 100644 scripts/copilot-firewall/requirements.txt diff --git a/.github/workflows/auto-module-tagging.yml b/.github/workflows/auto-module-tagging.yml index 4174d59e..2292535e 100644 --- a/.github/workflows/auto-module-tagging.yml +++ b/.github/workflows/auto-module-tagging.yml @@ -24,13 +24,13 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 # Fetch all history for all tags - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' diff --git a/.github/workflows/ci-tests.yml b/.github/workflows/ci-tests.yml index 19f59be2..d3c8308e 100644 --- a/.github/workflows/ci-tests.yml +++ b/.github/workflows/ci-tests.yml @@ -31,12 +31,12 @@ jobs: runs-on: ${{ matrix.os }} continue-on-error: ${{ matrix.rust == 'nightly' }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Install Rust ${{ matrix.rust }} - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # master + uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # master with: toolchain: ${{ matrix.rust }} components: rustfmt, clippy @@ -74,12 +74,12 @@ jobs: if: needs.rust-tests.result == 'success' runs-on: ubuntu-latest steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Install Rust stable - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable + uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable - name: Restore cargo cache uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 @@ -121,12 +121,12 @@ jobs: python: ['3.13'] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Python ${{ matrix.python }} - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python }} cache: pip @@ -177,12 +177,12 @@ jobs: node: [18, 20, 22] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Node.js ${{ matrix.node }} - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ matrix.node }} cache: npm diff --git a/.github/workflows/commit-override-handler.yml b/.github/workflows/commit-override-handler.yml index 7698c99b..44ee8a8b 100644 --- a/.github/workflows/commit-override-handler.yml +++ b/.github/workflows/commit-override-handler.yml @@ -50,7 +50,7 @@ jobs: # 'fatal: bad revision' / exit 128 errors when computing commit range # on PRs. (Previously the job failed before producing outputs.) - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive # Need full history (or at least all commits in PR) plus base branch ref for range comparisons @@ -76,7 +76,7 @@ jobs: echo "ref=${ref}" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common diff --git a/.github/workflows/documentation.yml b/.github/workflows/documentation.yml index 244dad80..bd3d5048 100644 --- a/.github/workflows/documentation.yml +++ b/.github/workflows/documentation.yml @@ -29,7 +29,7 @@ jobs: name: Build Documentation runs-on: ubuntu-latest steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Generate helper documentation @@ -111,7 +111,7 @@ jobs: echo "DOCS_DEPLOY_TOKEN secret not set; skipping deployment." exit 0 - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive if: env.DOCS_DEPLOY_TOKEN != '' diff --git a/.github/workflows/manager-sync-dispatcher.yml b/.github/workflows/manager-sync-dispatcher.yml index 30c44801..9b9acf19 100644 --- a/.github/workflows/manager-sync-dispatcher.yml +++ b/.github/workflows/manager-sync-dispatcher.yml @@ -64,13 +64,13 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' diff --git a/.github/workflows/on-release-published.yml b/.github/workflows/on-release-published.yml index 2926d22b..2e1975d9 100644 --- a/.github/workflows/on-release-published.yml +++ b/.github/workflows/on-release-published.yml @@ -26,7 +26,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -87,13 +87,13 @@ jobs: if: '!github.event.release.prerelease' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' diff --git a/.github/workflows/performance-monitoring.yml b/.github/workflows/performance-monitoring.yml index b7316ee2..3fa6dff8 100644 --- a/.github/workflows/performance-monitoring.yml +++ b/.github/workflows/performance-monitoring.yml @@ -28,12 +28,12 @@ jobs: best: ${{ steps.capture.outputs.best }} worst: ${{ steps.capture.outputs.worst }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: submodules: recursive - name: Install toolchain - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable + uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable - name: Restore cache uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 @@ -86,7 +86,7 @@ jobs: best: ${{ steps.capture.outputs.best }} worst: ${{ steps.capture.outputs.worst }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: submodules: recursive @@ -139,11 +139,11 @@ jobs: best: ${{ steps.capture.outputs.best }} worst: ${{ steps.capture.outputs.worst }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: submodules: recursive - - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 with: python-version: '3.11' diff --git a/.github/workflows/pr-automation.yml b/.github/workflows/pr-automation.yml index a67533c3..fca93ed0 100644 --- a/.github/workflows/pr-automation.yml +++ b/.github/workflows/pr-automation.yml @@ -44,14 +44,14 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout Code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 token: ${{ secrets.GITHUB_TOKEN }} - name: Setup Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' @@ -81,21 +81,21 @@ jobs: - name: Setup Go (if go.mod present) if: steps.detect_langs.outputs.go_present == 'true' - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.24' cache: true - name: Setup Rust (if Cargo.toml present) if: steps.detect_langs.outputs.rust_present == 'true' - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable + uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable with: toolchain: stable components: rustfmt, clippy - name: Setup Node.js (if package.json present) if: steps.detect_langs.outputs.node_present == 'true' - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: '22' cache: npm @@ -127,7 +127,7 @@ jobs: # but a lint finding must not hard-fail the PR. Real linting is enforced # separately by reusable-ci.yml. Without this the job blocked every PR. continue-on-error: true - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -256,12 +256,12 @@ jobs: if: github.event_name == 'pull_request' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Apply file-based labels - uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0 + uses: actions/labeler@bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13 # v7.0.0 with: repo-token: ${{ secrets.GITHUB_TOKEN }} configuration-path: .github/labeler.yml @@ -274,13 +274,13 @@ jobs: if: github.event.action == 'opened' || github.event.action == 'edited' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' @@ -311,7 +311,7 @@ jobs: if: github.event_name == 'pull_request' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -371,7 +371,7 @@ jobs: if: github.event_name == 'pull_request' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -554,7 +554,7 @@ jobs: if: github.event_name == 'pull_request' && github.event.action != 'closed' steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -625,7 +625,7 @@ jobs: attestations: write steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -659,7 +659,7 @@ jobs: sbom-path: sbom.spdx.json - name: Build Provenance Attestation - uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 + uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 with: subject-path: pr-automation-context.tar.gz diff --git a/.github/workflows/reusable-advanced-cache.yml b/.github/workflows/reusable-advanced-cache.yml index 355c3cf2..b9a9adda 100644 --- a/.github/workflows/reusable-advanced-cache.yml +++ b/.github/workflows/reusable-advanced-cache.yml @@ -48,7 +48,7 @@ jobs: cache-paths: ${{ steps.generate-key.outputs.cache-paths }} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -62,7 +62,7 @@ jobs: fi - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -78,7 +78,7 @@ jobs: echo "GHCOMMON_SCRIPTS_DIR=$GITHUB_WORKSPACE/.ghcommon/.github/workflows/scripts" >> "$GITHUB_ENV" - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' @@ -111,7 +111,7 @@ jobs: - name: Configure cache id: cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: key: ${{ steps.generate-key.outputs.cache-key }} restore-keys: | diff --git a/.github/workflows/reusable-burndown.yml b/.github/workflows/reusable-burndown.yml index d60cb58a..23282260 100644 --- a/.github/workflows/reusable-burndown.yml +++ b/.github/workflows/reusable-burndown.yml @@ -166,14 +166,14 @@ jobs: steps: - name: Create GitHub App token id: app-token - uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: app-id: ${{ secrets.BURNDOWN_BOT_APP_ID }} private-key: ${{ secrets.BURNDOWN_BOT_PRIVATE_KEY }} owner: ${{ github.repository_owner }} - name: Checkout target repo - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive token: ${{ steps.app-token.outputs.token }} @@ -263,7 +263,7 @@ jobs: task_count: ${{ steps.emit.outputs.task_count }} steps: - name: Checkout target repo (sparse) - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive path: targets/${{ github.event.repository.name }} @@ -349,7 +349,7 @@ jobs: index: ${{ fromJson(needs.triage.outputs.task_indices) }} steps: - name: Checkout target repo (sparse) - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive path: targets/${{ github.event.repository.name }} @@ -491,14 +491,14 @@ jobs: steps: - name: Create GitHub App token id: app-token - uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: app-id: ${{ secrets.BURNDOWN_BOT_APP_ID }} private-key: ${{ secrets.BURNDOWN_BOT_PRIVATE_KEY }} owner: ${{ github.repository_owner }} - name: Checkout target repo - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive token: ${{ steps.app-token.outputs.token }} diff --git a/.github/workflows/reusable-ci-minimal.yml b/.github/workflows/reusable-ci-minimal.yml index e782182c..5ad8d5ef 100644 --- a/.github/workflows/reusable-ci-minimal.yml +++ b/.github/workflows/reusable-ci-minimal.yml @@ -60,18 +60,18 @@ jobs: GOEXPERIMENT: ${{ inputs.go-experiment }} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Go (no built-in cache) - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ inputs.go-version }} cache: false - name: Restore Go cache (manual) - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: | ~/.cache/go-build @@ -104,18 +104,18 @@ jobs: GOEXPERIMENT: ${{ inputs.go-experiment }} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Go (no built-in cache) - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ inputs.go-version }} cache: false - name: Restore Go cache (manual) - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: | ~/.cache/go-build @@ -147,17 +147,17 @@ jobs: working-directory: ${{ inputs.frontend-working-dir }} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ inputs.node-version }} - name: Restore npm cache (manual) - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ~/.npm key: ${{ runner.os }}-npm-${{ inputs.node-version }}-${{ hashFiles(format('{0}/package-lock.json', inputs.frontend-working-dir)) }} @@ -186,17 +186,17 @@ jobs: working-directory: ${{ inputs.frontend-working-dir }} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ inputs.node-version }} - name: Restore npm cache (manual) - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ~/.npm key: ${{ runner.os }}-npm-${{ inputs.node-version }}-${{ hashFiles(format('{0}/package-lock.json', inputs.frontend-working-dir)) }} diff --git a/.github/workflows/reusable-ci.yml b/.github/workflows/reusable-ci.yml index fc186815..43c9c48b 100644 --- a/.github/workflows/reusable-ci.yml +++ b/.github/workflows/reusable-ci.yml @@ -112,19 +112,19 @@ jobs: coverage-threshold: ${{ steps.matrices.outputs.coverage-threshold }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Load repository configuration id: load - uses: falkcorp/gha-load-config@bb213cbf6b6e789bea8ad0787f2914760d00536b # v1.1.3 + uses: falkcorp/gha-load-config@3ec49a74178f365d9791be2d132583a5c2578d09 # v1.1.3 with: config-file: .github/repository-config.yml fail-on-missing: false - name: Generate language matrices id: matrices - uses: falkcorp/gha-ci-generate-matrices@8c36d080ec55e96d3532e9b02417054fc6aaaeac # v1.1.6 + uses: falkcorp/gha-ci-generate-matrices@7d5fdd49ccf4b6fe1cff4730e3695ebaafc4fc28 # v1.1.6 with: repository-config: ${{ steps.load.outputs.config }} fallback-go-version: ${{ inputs.go-version }} @@ -154,13 +154,13 @@ jobs: lint-files: ${{ steps.changes.outputs.lint_files }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 2 - name: Detect file changes - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 + uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2 id: changes with: base: ${{ github.event.pull_request.base.sha || github.event.before || github.sha }} @@ -257,13 +257,13 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.23' check-latest: true @@ -311,7 +311,7 @@ jobs: name: Cache npm (Workflow Scripts) needs: detect-changes if: needs.detect-changes.outputs.workflows-scripts == 'true' || github.event_name == 'workflow_dispatch' - uses: falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml@1e106b5c7bc2e80beb0c6019e8ac263d41f2ed5f # v1.10.3+ + uses: falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml@d0c3326b96557c8ea9117c1c196b628e5e028186 # v1.10.3+ with: language: 'node' cache-prefix: 'npm-workflow-scripts' @@ -327,13 +327,13 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ inputs.python-version }} @@ -351,7 +351,7 @@ jobs: fi - name: Set up Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ inputs.node-version }} @@ -394,11 +394,11 @@ jobs: contains(github.event.head_commit.message, '[buf]')) steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Generate protobuf - uses: falkcorp/gha-release-protobuf@1c07a62621ea5bdaf7fd46643fd4e650c69de8d9 # v1.0.1 + uses: falkcorp/gha-release-protobuf@0e3f1f18b2f2576895c359691f57de04dd9a37fb # v1.0.1 # Language-specific build and test jobs go-ci: @@ -417,7 +417,7 @@ jobs: GOEXPERIMENT: ${{ inputs.go-experiment }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -439,7 +439,7 @@ jobs: echo "ref=$ref" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -454,7 +454,7 @@ jobs: echo "GHCOMMON_SCRIPTS_DIR=$PWD/ghcommon-workflow-scripts/.github/workflows/scripts" >> "$GITHUB_ENV" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ matrix.go-version }} cache: true @@ -470,13 +470,13 @@ jobs: sudo apt-get install -y $PACKAGES - name: Build Go project - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: go-setup - name: Test Go project if: ${{ !inputs.skip-tests }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: go-test coverage-threshold: ${{ inputs.coverage-threshold || needs.load-config.outputs.coverage-threshold }} @@ -489,7 +489,7 @@ jobs: - name: Check Go test coverage if: ${{ !inputs.skip-tests }} continue-on-error: true - uses: vladopajic/go-test-coverage@a93b868a4cbcbf18dc3781650fad241f0020e609 # v2.18.8 + uses: vladopajic/go-test-coverage@5f3508324fc185e82048a2861f8bdd3d83db133b # v2.18.9 with: config: ./.testcoverage.yml @@ -508,7 +508,7 @@ jobs: REPOSITORY_CONFIG: ${{ needs.load-config.outputs.config }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -533,7 +533,7 @@ jobs: fi - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} cache: ${{ steps.py-manifest.outputs.cache }} @@ -549,7 +549,7 @@ jobs: echo "ref=$ref" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -564,7 +564,7 @@ jobs: echo "GHCOMMON_SCRIPTS_DIR=$PWD/ghcommon-workflow-scripts/.github/workflows/scripts" >> "$GITHUB_ENV" - name: Install Python dependencies - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: python-install @@ -575,7 +575,7 @@ jobs: - name: Test Python code if: ${{ !inputs.skip-tests }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: python-run-tests @@ -594,12 +594,12 @@ jobs: REPOSITORY_CONFIG: ${{ needs.load-config.outputs.config }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Rust - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable + uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable with: toolchain: ${{ matrix.rust-version }} components: rustfmt, clippy @@ -615,7 +615,7 @@ jobs: echo "ref=$ref" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -630,7 +630,7 @@ jobs: echo "GHCOMMON_SCRIPTS_DIR=$PWD/ghcommon-workflow-scripts/.github/workflows/scripts" >> "$GITHUB_ENV" - name: Cache Rust dependencies - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: | ~/.cargo/bin/ @@ -642,13 +642,13 @@ jobs: - name: Format Rust code if: ${{ !inputs.skip-linting }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: rust-format - name: Lint Rust code if: ${{ !inputs.skip-linting }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: rust-clippy @@ -668,7 +668,7 @@ jobs: name: Cache npm (Frontend) needs: detect-changes if: needs.detect-changes.outputs.frontend-files == 'true' - uses: falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml@1e106b5c7bc2e80beb0c6019e8ac263d41f2ed5f # v1.10.3+ + uses: falkcorp/github-common/.github/workflows/reusable-advanced-cache.yml@d0c3326b96557c8ea9117c1c196b628e5e028186 # v1.10.3+ with: language: 'node' cache-prefix: 'npm-frontend' @@ -689,13 +689,13 @@ jobs: REPOSITORY_CONFIG: ${{ needs.load-config.outputs.config }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Get frontend working directory id: frontend-dir - uses: falkcorp/gha-get-frontend-config@517d41adc382a541ea13dead79a12a57a7172dcf # v1.1.3 + uses: falkcorp/gha-get-frontend-config@97f9fea2ba59e35fa23a74f0733b7a07005c5809 # v1.1.3 with: repository-config: ${{ env.REPOSITORY_CONFIG }} @@ -710,7 +710,7 @@ jobs: echo "ref=$ref" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -725,7 +725,7 @@ jobs: echo "GHCOMMON_SCRIPTS_DIR=$PWD/ghcommon-workflow-scripts/.github/workflows/scripts" >> "$GITHUB_ENV" - name: Set up Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ matrix.node-version }} @@ -734,14 +734,14 @@ jobs: # No additional cache setup needed here. - name: Install dependencies - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: frontend-install frontend-working-dir: ${{ steps.frontend-dir.outputs.dir }} - name: Lint frontend code if: ${{ !inputs.skip-linting }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: frontend-run frontend-working-dir: ${{ steps.frontend-dir.outputs.dir }} @@ -750,7 +750,7 @@ jobs: frontend-failure-message: '❌ Linting failed or not configured' - name: Build frontend - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: frontend-run frontend-working-dir: ${{ steps.frontend-dir.outputs.dir }} @@ -760,7 +760,7 @@ jobs: - name: Test frontend if: ${{ !inputs.skip-tests }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: frontend-run frontend-working-dir: ${{ steps.frontend-dir.outputs.dir }} @@ -783,7 +783,7 @@ jobs: - name: Run E2E tests if: ${{ !inputs.skip-tests && !inputs.skip-e2e-tests }} - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: frontend-run frontend-working-dir: ${{ steps.frontend-dir.outputs.dir }} @@ -827,7 +827,7 @@ jobs: PR_TITLE: ${{ github.event.pull_request.title }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 @@ -893,7 +893,7 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -908,7 +908,7 @@ jobs: echo "ref=$ref" >> "$GITHUB_OUTPUT" - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -938,7 +938,7 @@ jobs: } >> "$GITHUB_ENV" - name: Generate summary - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: generate-ci-summary env: @@ -953,7 +953,7 @@ jobs: JOB_DOCS: skipped - name: Check overall status - uses: falkcorp/gha-ci-workflow-helpers@c8b87fae92ee0a0458e47b970ed892310323aa58 # v1.1.4 + uses: falkcorp/gha-ci-workflow-helpers@4b5f4d45d42c99d98ccf731624f2f4b91d849561 # v1.1.4 with: command: check-ci-status env: diff --git a/.github/workflows/reusable-issue-automation.yml b/.github/workflows/reusable-issue-automation.yml index 8185ff92..53483613 100644 --- a/.github/workflows/reusable-issue-automation.yml +++ b/.github/workflows/reusable-issue-automation.yml @@ -46,7 +46,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Mark and close stale issues - uses: actions/stale@eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899 # v10.3.0 + uses: actions/stale@1e223db275d687790206a7acac4d1a11bd6fe629 # v10.4.0 with: repo-token: ${{ secrets.GITHUB_TOKEN }} stale-issue-message: | @@ -92,7 +92,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive diff --git a/.github/workflows/reusable-maintenance.yml b/.github/workflows/reusable-maintenance.yml index 812e70a9..d346da86 100644 --- a/.github/workflows/reusable-maintenance.yml +++ b/.github/workflows/reusable-maintenance.yml @@ -40,7 +40,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -54,7 +54,7 @@ jobs: fi - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -121,7 +121,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -185,7 +185,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -233,7 +233,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/reusable-release.yml b/.github/workflows/reusable-release.yml index 16e38ac7..a91c3fef 100644 --- a/.github/workflows/reusable-release.yml +++ b/.github/workflows/reusable-release.yml @@ -135,12 +135,12 @@ jobs: has-config: ${{ steps.load-config.outputs.has-config }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Load repository configuration id: load-config - uses: falkcorp/gha-load-config@bb213cbf6b6e789bea8ad0787f2914760d00536b # v1.1.3 + uses: falkcorp/gha-load-config@3ec49a74178f365d9791be2d132583a5c2578d09 # v1.1.3 with: config-file: .github/repository-config.yml fail-on-missing: false @@ -173,7 +173,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -187,7 +187,7 @@ jobs: } >> "$GITHUB_OUTPUT" - name: Detect project languages and generate matrices id: detect - uses: falkcorp/gha-detect-languages@d5712363aae458b4bbb47bbb1780f02de2a03784 # v1.1.5 + uses: falkcorp/gha-detect-languages@b2e051b4ec8467f2a82fe195fc5a3bc3c7ccf983 # v1.1.5 with: skip-detection: ${{ inputs.skip-language-detection }} build-target: ${{ inputs.build-target || 'all' }} @@ -310,11 +310,11 @@ jobs: if: ${{ needs.detect-languages.outputs.protobuf-needed == 'true' }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Generate protobuf - uses: falkcorp/gha-release-protobuf@1c07a62621ea5bdaf7fd46643fd4e650c69de8d9 # v1.0.2+ + uses: falkcorp/gha-release-protobuf@0e3f1f18b2f2576895c359691f57de04dd9a37fb # v1.0.2+ # Go Build build-go: @@ -327,7 +327,7 @@ jobs: (inputs.build-target == 'all' || inputs.build-target == 'go') steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -381,7 +381,7 @@ jobs: (inputs.build-target == 'all' || inputs.build-target == 'python') steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Build Python @@ -400,7 +400,7 @@ jobs: (inputs.build-target == 'all' || inputs.build-target == 'rust') steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Build Rust @@ -420,7 +420,7 @@ jobs: (inputs.build-target == 'all' || inputs.build-target == 'frontend') steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Build Frontend @@ -437,7 +437,7 @@ jobs: (inputs.build-target == 'all' || inputs.build-target == 'docker') steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Build Docker @@ -471,7 +471,7 @@ jobs: release-created: ${{ steps.check-release.outputs.created }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -486,7 +486,7 @@ jobs: fi - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -566,7 +566,7 @@ jobs: - name: Create GitHub Release id: release - uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0 + uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2 if: github.event_name != 'pull_request' with: tag_name: ${{ steps.version.outputs.version }} @@ -852,7 +852,7 @@ jobs: REPOSITORY_CONFIG: ${{ needs.load-config.outputs.config }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -866,7 +866,7 @@ jobs: fi - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common @@ -936,7 +936,7 @@ jobs: !inputs.draft steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -1023,7 +1023,7 @@ jobs: release-created: ${{ needs.create-release.outputs.release-created || 'false' }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -1037,7 +1037,7 @@ jobs: fi - name: Checkout ghcommon workflow scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: # do not add submodules: recursive here — sparse-checkout can't lazy-fetch .gitmodules, causing a promisor-fetch 400 repository: falkcorp/github-common diff --git a/.github/workflows/reusable-security.yml b/.github/workflows/reusable-security.yml index 5c93b3d9..d2a09de4 100644 --- a/.github/workflows/reusable-security.yml +++ b/.github/workflows/reusable-security.yml @@ -43,7 +43,7 @@ jobs: has-languages: ${{ steps.detect.outputs.has-languages }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -94,7 +94,7 @@ jobs: language: ${{ fromJSON(needs.detect-languages.outputs.languages) }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -111,7 +111,7 @@ jobs: esac - name: Initialize CodeQL - uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/init@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality @@ -150,14 +150,14 @@ jobs: esac - name: Start proxy for registry access - uses: github/codeql-action/start-proxy@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/start-proxy@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 - name: Autobuild if: steps.build-config.outputs.mode == 'autobuild' - uses: github/codeql-action/autobuild@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/autobuild@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/analyze@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 with: category: '/language:${{ matrix.language }}' @@ -186,7 +186,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -219,7 +219,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -274,7 +274,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout ghcommon scripts - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive repository: falkcorp/github-common diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 368f09a1..bdb8c2e9 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -47,7 +47,7 @@ jobs: languages: ${{ steps.detect.outputs.languages }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -67,7 +67,7 @@ jobs: language: ${{ fromJSON(needs.detect-languages.outputs.languages) }} steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -84,7 +84,7 @@ jobs: esac - name: Initialize CodeQL - uses: github/codeql-action/init@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/init@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality @@ -112,10 +112,10 @@ jobs: - name: Autobuild if: steps.build-config.outputs.mode == 'autobuild' - uses: github/codeql-action/autobuild@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/autobuild@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4.36.1 + uses: github/codeql-action/analyze@e0647621c2984b5ed2f768cb892365bf2a616ad1 # v4.37.2 with: category: '/language:${{ matrix.language }}' @@ -127,7 +127,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -145,7 +145,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive @@ -192,7 +192,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive diff --git a/.github/workflows/sync-receiver.yml b/.github/workflows/sync-receiver.yml index 681c2d80..5637620c 100644 --- a/.github/workflows/sync-receiver.yml +++ b/.github/workflows/sync-receiver.yml @@ -49,14 +49,14 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout current repo - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 token: ${{ secrets.GITHUB_TOKEN }} - name: Checkout ghcommon - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive repository: falkcorp/github-common diff --git a/.github/workflows/sync-repos.yml b/.github/workflows/sync-repos.yml index c2bcf0c8..b2beb3c4 100644 --- a/.github/workflows/sync-repos.yml +++ b/.github/workflows/sync-repos.yml @@ -34,13 +34,13 @@ jobs: name: Sync to Target Repos steps: - name: Checkout ghcommon - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.11' diff --git a/.github/workflows/test-super-linter.yml b/.github/workflows/test-super-linter.yml index e59292aa..04686566 100644 --- a/.github/workflows/test-super-linter.yml +++ b/.github/workflows/test-super-linter.yml @@ -47,7 +47,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -139,13 +139,13 @@ jobs: github.event_name == 'push' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Cache Super Linter Docker image - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: /tmp/.superlinter-cache key: ${{ runner.os }}-superlinter-${{ hashFiles('super-linter-*.env') }} @@ -153,7 +153,7 @@ jobs: ${{ runner.os }}-superlinter- - name: Run Super Linter (Minimal) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -180,13 +180,13 @@ jobs: github.event_name == 'push' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Cache Super Linter Docker image - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: /tmp/.superlinter-cache key: ${{ runner.os }}-superlinter-${{ hashFiles('super-linter-*.env') }} @@ -199,7 +199,7 @@ jobs: cp super-linter-ci.env .github/test-configs/test-full.env || true - name: Run Super Linter (Full Config) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} ENV_FILE: super-linter-ci.env @@ -218,13 +218,13 @@ jobs: github.event.inputs.test_scenario == 'autofix' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Cache Super Linter Docker image - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: /tmp/.superlinter-cache key: ${{ runner.os }}-superlinter-${{ hashFiles('super-linter-*.env') }} @@ -232,7 +232,7 @@ jobs: ${{ runner.os }}-superlinter- - name: Run Super Linter (Auto-Fix) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} ENV_FILE: super-linter-pr.env @@ -256,7 +256,7 @@ jobs: github.event.inputs.test_scenario == 'config-paths' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 @@ -326,7 +326,7 @@ jobs: fi - name: Run Super Linter with explicit config paths - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -358,13 +358,13 @@ jobs: github.event.inputs.test_scenario == 'filter-patterns' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter with filters - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -385,13 +385,13 @@ jobs: github.event.inputs.test_scenario == 'disabled-validators' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (Some Disabled) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -415,13 +415,13 @@ jobs: github.event.inputs.test_scenario == 'markdown-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (Markdown Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -440,13 +440,13 @@ jobs: github.event.inputs.test_scenario == 'python-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (Python Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -469,13 +469,13 @@ jobs: github.event.inputs.test_scenario == 'javascript-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (JavaScript/TypeScript Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -496,13 +496,13 @@ jobs: github.event.inputs.test_scenario == 'rust-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (Rust Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -521,13 +521,13 @@ jobs: github.event.inputs.test_scenario == 'go-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (Go Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main @@ -545,13 +545,13 @@ jobs: github.event.inputs.test_scenario == 'yaml-only' steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 - name: Run Super Linter (YAML Only) - uses: super-linter/super-linter@9e863354e3ff62e0727d37183162c4a88873df41 # v8.6.0 + uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main diff --git a/.github/workflows/todo-collect.yml b/.github/workflows/todo-collect.yml index be856090..52c704b2 100644 --- a/.github/workflows/todo-collect.yml +++ b/.github/workflows/todo-collect.yml @@ -39,12 +39,12 @@ jobs: contents: write steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.12' diff --git a/.github/workflows/unified-automation.yml b/.github/workflows/unified-automation.yml index eedfe8ae..b6f91578 100644 --- a/.github/workflows/unified-automation.yml +++ b/.github/workflows/unified-automation.yml @@ -39,14 +39,14 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive fetch-depth: 0 token: ${{ secrets.GITHUB_TOKEN }} - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' diff --git a/.github/workflows/workflow-analytics.yml b/.github/workflows/workflow-analytics.yml index bff70b83..040b5723 100644 --- a/.github/workflows/workflow-analytics.yml +++ b/.github/workflows/workflow-analytics.yml @@ -25,12 +25,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: '3.13' diff --git a/package-lock.json b/package-lock.json index 8f6247a6..c183ec5f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -14,14 +14,14 @@ "devDependencies": { "@commitlint/cli": "^18.4.3", "@commitlint/config-conventional": "^18.4.3", - "@eslint/eslintrc": "^3.3.5", - "@eslint/js": "^9.39.4", - "@typescript-eslint/eslint-plugin": "^8.60.1", - "eslint": "^9.39.4", + "@eslint/eslintrc": "^3.3.6", + "@eslint/js": "^9.39.5", + "@typescript-eslint/eslint-plugin": "^8.65.0", + "eslint": "^9.39.5", "eslint-plugin": "^1.0.1", "globals": "^16.5.0", "typescript": "^5.9.3", - "typescript-eslint": "^8.60.1" + "typescript-eslint": "^8.65.0" }, "engines": { "node": ">=18.0.0" @@ -392,9 +392,9 @@ } }, "node_modules/@eslint/eslintrc": { - "version": "3.3.5", - "resolved": "https://registry.npmjs.org/@eslint/eslintrc/-/eslintrc-3.3.5.tgz", - "integrity": "sha512-4IlJx0X0qftVsN5E+/vGujTRIFtwuLbNsVUe7TO6zYPDR1O6nFwvwhIKEKSrl6dZchmYBITazxKoUYOjdtjlRg==", + "version": "3.3.6", + "resolved": "https://registry.npmjs.org/@eslint/eslintrc/-/eslintrc-3.3.6.tgz", + "integrity": "sha512-l2Ul9PrHsPCKcEY/ac7VgFj9D80C7S68sOKc618SyHDPK36s1XcFebXY0iTzUVn4Yq+YbwvSnDmCz9yxjX+QrA==", "dev": true, "license": "MIT", "dependencies": { @@ -404,7 +404,7 @@ "globals": "^14.0.0", "ignore": "^5.2.0", "import-fresh": "^3.2.1", - "js-yaml": "^4.1.1", + "js-yaml": "^4.3.0", "minimatch": "^3.1.5", "strip-json-comments": "^3.1.1" }, @@ -452,9 +452,9 @@ "license": "MIT" }, "node_modules/@eslint/js": { - "version": "9.39.4", - "resolved": "https://registry.npmjs.org/@eslint/js/-/js-9.39.4.tgz", - "integrity": "sha512-nE7DEIchvtiFTwBw4Lfbu59PG+kCofhjsKaCWzxTpt4lfRjRMqG6uMBzKXuEcyXhOHoUp9riAm7/aWYGhXZ9cw==", + "version": "9.39.5", + "resolved": "https://registry.npmjs.org/@eslint/js/-/js-9.39.5.tgz", + "integrity": "sha512-QywQuszQh77pIXCsq998c8hbhSTI/azTty1Z6N53dmAudKHhy573j3yvRLsX2BSp8YpLtoCEG8E9DJe+8zUh4A==", "dev": true, "license": "MIT", "engines": { @@ -573,17 +573,17 @@ "license": "MIT" }, "node_modules/@typescript-eslint/eslint-plugin": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.60.1.tgz", - "integrity": "sha512-JQ4S5GB0tfjO8BuJ4fcX+HodkzJjYBV+7OJ+wLygaX7OGQ7FudyHL4NSCA6ob+w3Yn+5MkKIozOwQhXeM7opVg==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.65.0.tgz", + "integrity": "sha512-IEgob78X12rHpUmtcwFsXhZdVGJtwTVP8FiCLZkR6GlYVrl2PcuB+KhCE5BlVC/eQpQnu8WXRtkHZuPar+gCRA==", "dev": true, "license": "MIT", "dependencies": { "@eslint-community/regexpp": "^4.12.2", - "@typescript-eslint/scope-manager": "8.60.1", - "@typescript-eslint/type-utils": "8.60.1", - "@typescript-eslint/utils": "8.60.1", - "@typescript-eslint/visitor-keys": "8.60.1", + "@typescript-eslint/scope-manager": "8.65.0", + "@typescript-eslint/type-utils": "8.65.0", + "@typescript-eslint/utils": "8.65.0", + "@typescript-eslint/visitor-keys": "8.65.0", "ignore": "^7.0.5", "natural-compare": "^1.4.0", "ts-api-utils": "^2.5.0" @@ -596,7 +596,7 @@ "url": "https://opencollective.com/typescript-eslint" }, "peerDependencies": { - "@typescript-eslint/parser": "^8.60.1", + "@typescript-eslint/parser": "^8.65.0", "eslint": "^8.57.0 || ^9.0.0 || ^10.0.0", "typescript": ">=4.8.4 <6.1.0" } @@ -611,16 +611,16 @@ } }, "node_modules/@typescript-eslint/parser": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.60.1.tgz", - "integrity": "sha512-A0M6ua6H252bVjPvvtSgl2QA4+ET9S5Mtkb2GDyTxIhH/C4qDItT7RQNO5PhMC6NXGYXOR9dIalcDDgBKT7oFA==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.65.0.tgz", + "integrity": "sha512-CZ4nMxWwgu1HEEFNkeaCptra9QCtkmKdgf3sWh1rl1trIhmxLilgTV4cwcbQ4wemnT4sWQN8CaKOmdYx+g2gMA==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/scope-manager": "8.60.1", - "@typescript-eslint/types": "8.60.1", - "@typescript-eslint/typescript-estree": "8.60.1", - "@typescript-eslint/visitor-keys": "8.60.1", + "@typescript-eslint/scope-manager": "8.65.0", + "@typescript-eslint/types": "8.65.0", + "@typescript-eslint/typescript-estree": "8.65.0", + "@typescript-eslint/visitor-keys": "8.65.0", "debug": "^4.4.3" }, "engines": { @@ -636,14 +636,14 @@ } }, "node_modules/@typescript-eslint/project-service": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.60.1.tgz", - "integrity": "sha512-eXkTH2bxmXlqD1RnOPmLZ9ZM9D3VwSx04JOwBnP9RQ+yUA5a2Mu7SfW8uaV2Aon53NJzZlZYuX7tn91Izf+xaw==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.65.0.tgz", + "integrity": "sha512-SxnPhbTsGahizDgbu7oqFH/xVtzIqMd/s+WtnSxNxJZJpLbdT5IPdzg8EZxO3+PoKahXmwJLeNQOpKJb3/bi7Q==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/tsconfig-utils": "^8.60.1", - "@typescript-eslint/types": "^8.60.1", + "@typescript-eslint/tsconfig-utils": "^8.65.0", + "@typescript-eslint/types": "^8.65.0", "debug": "^4.4.3" }, "engines": { @@ -658,14 +658,14 @@ } }, "node_modules/@typescript-eslint/scope-manager": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.60.1.tgz", - "integrity": "sha512-gvI5OQoptnxQnchOirukCuQ55svJSTuD/4k5+pC267xyBtYry748R9/c3tYUzb/iE6RZfllRz2lVulLCHkTm4w==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.65.0.tgz", + "integrity": "sha512-Esbl8OSYiVxBokYgWPf7VVWg/BE798wXhimnn9ML9Pt5qoDf8bfQlgjlKXR/k98+AcNzlLKYrpCcrcuZ9DZLgg==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/types": "8.60.1", - "@typescript-eslint/visitor-keys": "8.60.1" + "@typescript-eslint/types": "8.65.0", + "@typescript-eslint/visitor-keys": "8.65.0" }, "engines": { "node": "^18.18.0 || ^20.9.0 || >=21.1.0" @@ -676,9 +676,9 @@ } }, "node_modules/@typescript-eslint/tsconfig-utils": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.60.1.tgz", - "integrity": "sha512-nh8w4qAteiKuZu3pSSzG/yGKpw0OlkrKnzFmbVRenKaD4qc+7i1GrmZaLVkr8rk4uipiPGMOW4YsM6WmKZ5CvA==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.65.0.tgz", + "integrity": "sha512-j6GzGqCiRdA7Qhur2VVmKZAkBLfnHFQfx4TaJGL9RMveZqCo48jSHHO0DTgizEnGhtWnqmbtCUSrqSkdiY/0Hg==", "dev": true, "license": "MIT", "engines": { @@ -693,15 +693,15 @@ } }, "node_modules/@typescript-eslint/type-utils": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.60.1.tgz", - "integrity": "sha512-sdwTrpjosW7ANQYJ39ZBF1ZyEMEGVB2UsikrserVM/30a/F1dTLnu9bGxEdosugyu5caigjLrR2qiD11asjI1A==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.65.0.tgz", + "integrity": "sha512-YjaZ7PRI5qY7ax2L3PbvX0rRyGtipAReCWs0mhhDBHjH/vl0g0BonaGXrKdKpMbIIsMIwDgbk/xzkBTyAltS5g==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/types": "8.60.1", - "@typescript-eslint/typescript-estree": "8.60.1", - "@typescript-eslint/utils": "8.60.1", + "@typescript-eslint/types": "8.65.0", + "@typescript-eslint/typescript-estree": "8.65.0", + "@typescript-eslint/utils": "8.65.0", "debug": "^4.4.3", "ts-api-utils": "^2.5.0" }, @@ -718,9 +718,9 @@ } }, "node_modules/@typescript-eslint/types": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.60.1.tgz", - "integrity": "sha512-4h0tY8ppCkdCzcrl2YM5M3my0xsE1Tf8om3owEu5oPWmXwkKRmk0j0LGDzYBGUcAlesEbxBhazqu/K4cu3Ug7w==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.65.0.tgz", + "integrity": "sha512-JSSwWNy+H0E/01jJEM+hrX6N0OFDzFzeIhHFSAS01tlVaevpG8cFyYRPhS5yjGOvBUx3sqQHVMjCL1CAZZMxBg==", "dev": true, "license": "MIT", "engines": { @@ -732,16 +732,16 @@ } }, "node_modules/@typescript-eslint/typescript-estree": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.60.1.tgz", - "integrity": "sha512-alpRkfG8hlVE5kdJW2GkfgDgXxold3e8e4l6EnmhRmRLbekgAPCCGDVD++sABy9FcgPFroq+uFcCSM1vR57Cew==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.65.0.tgz", + "integrity": "sha512-JboAE2swaYt4tb1fHhHTABE2K+OLy09XfcTbhnk4Pw96f9dd2e9iYsJ28gBggHlo5z5x1rkyWvcPoTuNTd4oGg==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/project-service": "8.60.1", - "@typescript-eslint/tsconfig-utils": "8.60.1", - "@typescript-eslint/types": "8.60.1", - "@typescript-eslint/visitor-keys": "8.60.1", + "@typescript-eslint/project-service": "8.65.0", + "@typescript-eslint/tsconfig-utils": "8.65.0", + "@typescript-eslint/types": "8.65.0", + "@typescript-eslint/visitor-keys": "8.65.0", "debug": "^4.4.3", "minimatch": "^10.2.2", "semver": "^7.7.3", @@ -776,9 +776,9 @@ } }, "node_modules/@typescript-eslint/typescript-estree/node_modules/semver": { - "version": "7.8.1", - "resolved": "https://registry.npmjs.org/semver/-/semver-7.8.1.tgz", - "integrity": "sha512-rkVq3IXh+4FDGch+KwzX3aV9W3kO54GyEgpvBzSyctDA6Xtd7RJQV1xmXbeQp5v7+VzLOfVqiutSE6GICgPFvg==", + "version": "7.8.5", + "resolved": "https://registry.npmjs.org/semver/-/semver-7.8.5.tgz", + "integrity": "sha512-Y7/KDsb8LjooZpwaqGyulO6DQlksgCncchHGk+sZIY4SBvUocMBEFH5Ur1fI4dV+Jvl0w6cjvucaIi40puRioA==", "dev": true, "license": "ISC", "bin": { @@ -789,16 +789,16 @@ } }, "node_modules/@typescript-eslint/utils": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.60.1.tgz", - "integrity": "sha512-h2MPBLoNtjc3qZWfY3Tl51yPorQ2McHn8pJfcMNTcIvrrZrr90Ykffit0yjrPFWQcRcUxzH20+6OcVdW4yHtUg==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.65.0.tgz", + "integrity": "sha512-gXiwIHsYreboxeJucHKPvgwl7dXt50mF8s1/c00cP/WoVTyWKFdtfhRWwZiXYFU5H2O8vVoSLNrexFZjYS/SGA==", "dev": true, "license": "MIT", "dependencies": { "@eslint-community/eslint-utils": "^4.9.1", - "@typescript-eslint/scope-manager": "8.60.1", - "@typescript-eslint/types": "8.60.1", - "@typescript-eslint/typescript-estree": "8.60.1" + "@typescript-eslint/scope-manager": "8.65.0", + "@typescript-eslint/types": "8.65.0", + "@typescript-eslint/typescript-estree": "8.65.0" }, "engines": { "node": "^18.18.0 || ^20.9.0 || >=21.1.0" @@ -813,13 +813,13 @@ } }, "node_modules/@typescript-eslint/visitor-keys": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.60.1.tgz", - "integrity": "sha512-EbGRQg4FhrmwLodl+t3JNAnXHWVr9Vp+Zl1QBZVPY4ByfkzIT8cX3K6QWODHtkIZqqJVEWvhHSx3v5PDHsaQag==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.65.0.tgz", + "integrity": "sha512-8C71BQkGjiMmXtop7pHVJu1l2NNShFdkCyD6a2ezzs5vU/L3LRtb69EtcteFwz0mYMPzIgOw0n6OV4VBUWZd7A==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/types": "8.60.1", + "@typescript-eslint/types": "8.65.0", "eslint-visitor-keys": "^5.0.0" }, "engines": { @@ -1280,9 +1280,9 @@ } }, "node_modules/eslint": { - "version": "9.39.4", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-9.39.4.tgz", - "integrity": "sha512-XoMjdBOwe/esVgEvLmNsD3IRHkm7fbKIUGvrleloJXUZgDHig2IPWNniv+GwjyJXzuNqVjlr5+4yVUZjycJwfQ==", + "version": "9.39.5", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-9.39.5.tgz", + "integrity": "sha512-DgZS62aPLXKlnxILS/AYCoRvHaZeXceIzlXPkkGGzJWSow1aEk0lbTlxUSlyjC8jcaKxAdOnTDz+o1JFSBsyjw==", "dev": true, "license": "MIT", "dependencies": { @@ -1291,8 +1291,8 @@ "@eslint/config-array": "^0.21.2", "@eslint/config-helpers": "^0.4.2", "@eslint/core": "^0.17.0", - "@eslint/eslintrc": "^3.3.5", - "@eslint/js": "9.39.4", + "@eslint/eslintrc": "^3.3.6", + "@eslint/js": "9.39.5", "@eslint/plugin-kit": "^0.4.1", "@humanfs/node": "^0.16.6", "@humanwhocodes/module-importer": "^1.0.1", @@ -3083,16 +3083,16 @@ } }, "node_modules/typescript-eslint": { - "version": "8.60.1", - "resolved": "https://registry.npmjs.org/typescript-eslint/-/typescript-eslint-8.60.1.tgz", - "integrity": "sha512-6m5hkkRAp8lKvhVpcprAIn5KkehQEh+47oHH2VGnExEh7dhNxXlg6GPAOIu6TxbVQxhebrJDvjl3020ooiWCMA==", + "version": "8.65.0", + "resolved": "https://registry.npmjs.org/typescript-eslint/-/typescript-eslint-8.65.0.tgz", + "integrity": "sha512-/ggrHAwyjENDusvyxbuqxAC2dTnZg/Z8F+fgQtYIz+L6n/9HfSlEZcFGV/NsMNa6CkGk0xUjUAFwC0vHOflvIA==", "dev": true, "license": "MIT", "dependencies": { - "@typescript-eslint/eslint-plugin": "8.60.1", - "@typescript-eslint/parser": "8.60.1", - "@typescript-eslint/typescript-estree": "8.60.1", - "@typescript-eslint/utils": "8.60.1" + "@typescript-eslint/eslint-plugin": "8.65.0", + "@typescript-eslint/parser": "8.65.0", + "@typescript-eslint/typescript-estree": "8.65.0", + "@typescript-eslint/utils": "8.65.0" }, "engines": { "node": "^18.18.0 || ^20.9.0 || >=21.1.0" diff --git a/package.json b/package.json index e9e352b3..d58a535f 100644 --- a/package.json +++ b/package.json @@ -10,14 +10,14 @@ "devDependencies": { "@commitlint/cli": "^18.4.3", "@commitlint/config-conventional": "^18.4.3", - "@eslint/eslintrc": "^3.3.5", - "@eslint/js": "^9.39.4", - "@typescript-eslint/eslint-plugin": "^8.60.1", - "eslint": "^9.39.4", + "@eslint/eslintrc": "^3.3.6", + "@eslint/js": "^9.39.5", + "@typescript-eslint/eslint-plugin": "^8.65.0", + "eslint": "^9.39.5", "eslint-plugin": "^1.0.1", "globals": "^16.5.0", "typescript": "^5.9.3", - "typescript-eslint": "^8.60.1" + "typescript-eslint": "^8.65.0" }, "keywords": [ "github", diff --git a/requirements.txt b/requirements.txt index fe678334..7a9a196f 100644 --- a/requirements.txt +++ b/requirements.txt @@ -16,4 +16,4 @@ scriv>=1.8.0 # Transitive deps pinned to patched versions (Dependabot alerts #5, #3, #4, #29, #30) urllib3>=2.7.0 -idna>=3.15 +idna>=3.18 diff --git a/scripts/copilot-firewall/requirements.txt b/scripts/copilot-firewall/requirements.txt old mode 100755 new mode 100644 index 818721b1..30c29824 --- a/scripts/copilot-firewall/requirements.txt +++ b/scripts/copilot-firewall/requirements.txt @@ -3,8 +3,8 @@ # guid: c2d3e4f5-7g8h-9i0j-1k2l-3m4n5o6p7q8r # last-edited: 2026-07-14 -inquirer>=3.1.0 -rich>=13.0.0 +inquirer>=3.4.1 +rich>=13.9.4 # Transitive dep pinned to patched version (Dependabot alert #24) Pygments>=2.20.0