From f998dc22f26c3b953ee6aa5b4b093e454e8eeba4 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 09:17:06 +0000 Subject: [PATCH] chore(ci): bump the actions-minor-and-patch group with 5 updates Bumps the actions-minor-and-patch group with 5 updates: | Package | From | To | | --- | --- | --- | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.1.0` | `10.2.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [getplumber/plumber](https://github.com/getplumber/plumber) | `0.4.63` | `0.5.8` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](https://github.com/astral-sh/setup-uv/compare/bec219d24cd3e171d82865faccec33120bb574f4...c18668ad3cf93ea998bef934396af7bb5c839dc7) Updates `github/codeql-action/init` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) Updates `getplumber/plumber` from 0.4.63 to 0.5.8 - [Release notes](https://github.com/getplumber/plumber/releases) - [Changelog](https://github.com/getplumber/plumber/blob/main/CHANGELOG.md) - [Commits](https://github.com/getplumber/plumber/compare/10837e44cddfed934eaa2b509e677286af23e149...de6c889e24c9147baa064db656b71c8e98595d15) Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch - dependency-name: getplumber/plumber dependency-version: 0.5.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 6 +++--- .github/workflows/plumber.yml | 2 +- .github/workflows/scorecard.yml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8f03e77..9e57958 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -152,7 +152,7 @@ jobs: fetch-depth: 0 # trufflehog walks git history - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 - name: Install trufflehog (verified release binary; the hook runs with --no-update) # Download the pinned release tarball and verify its SHA-256 against the @@ -221,7 +221,7 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: ${{ matrix.language }} # Neither Python nor workflows compile: there is no build to observe, @@ -231,4 +231,4 @@ jobs: queries: security-extended - name: Analyze - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 diff --git a/.github/workflows/plumber.yml b/.github/workflows/plumber.yml index e016f37..7cf4324 100644 --- a/.github/workflows/plumber.yml +++ b/.github/workflows/plumber.yml @@ -52,7 +52,7 @@ jobs: persist-credentials: false - name: Plumber compliance scan - uses: getplumber/plumber@10837e44cddfed934eaa2b509e677286af23e149 # v0.4.63 + uses: getplumber/plumber@de6c889e24c9147baa064db656b71c8e98595d15 # v0.5.8 with: version: "v0.4.3" verify-attestation: "true" # check the binary's SLSA provenance before running diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 37685da..918ed50 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -80,6 +80,6 @@ jobs: publish_results: true # publish to the OpenSSF viewer (drives the README badge) - name: Upload SARIF to Code Scanning - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: sarif_file: results.sarif