Skip to content

Commit f5c928c

Browse files
Bump the gha-updates group across 1 directory with 10 updates (#163)
Bumps the gha-updates group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `7.3.1` | `8.1.0` | | [extractions/setup-just](https://github.com/extractions/setup-just) | `3.1.0` | `4.0.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `8.0.0` | `8.0.1` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.13.0` | `1.14.0` | | [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) | `3.2.0` | `3.3.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.5` | `4.35.2` | | [rhysd/action-setup-vim](https://github.com/rhysd/action-setup-vim) | `1.6.0` | `1.6.1` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.2` | `6.0.0` | | [actions-rust-lang/setup-rust-toolchain](https://github.com/actions-rust-lang/setup-rust-toolchain) | `1.15.3` | `1.16.0` | Updates `astral-sh/setup-uv` from 7.3.1 to 8.1.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@5a095e7...0880764) Updates `extractions/setup-just` from 3.1.0 to 4.0.0 - [Release notes](https://github.com/extractions/setup-just/releases) - [Commits](extractions/setup-just@f8a3cce...53165ef) Updates `actions/upload-artifact` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@bbbca2d...043fb46) Updates `actions/download-artifact` from 8.0.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@70fc10c...3e5f45b) Updates `pypa/gh-action-pypi-publish` from 1.13.0 to 1.14.0 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@ed0c539...cef2210) Updates `sigstore/gh-action-sigstore-python` from 3.2.0 to 3.3.0 - [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases) - [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/gh-action-sigstore-python@a5caf34...04cffa1) Updates `github/codeql-action` from 4.32.5 to 4.35.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@c793b71...95e58e9) Updates `rhysd/action-setup-vim` from 1.6.0 to 1.6.1 - [Release notes](https://github.com/rhysd/action-setup-vim/releases) - [Changelog](https://github.com/rhysd/action-setup-vim/blob/master/CHANGELOG.md) - [Commits](rhysd/action-setup-vim@19e3dd3...febef33) Updates `codecov/codecov-action` from 5.5.2 to 6.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@671740a...57e3a13) Updates `actions-rust-lang/setup-rust-toolchain` from 1.15.3 to 1.16.0 - [Release notes](https://github.com/actions-rust-lang/setup-rust-toolchain/releases) - [Changelog](https://github.com/actions-rust-lang/setup-rust-toolchain/blob/main/CHANGELOG.md) - [Commits](actions-rust-lang/setup-rust-toolchain@a0b538f...2b1f5e9) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 8.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-updates - dependency-name: extractions/setup-just dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-updates - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gha-updates - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gha-updates - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gha-updates - dependency-name: sigstore/gh-action-sigstore-python dependency-version: 3.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gha-updates - dependency-name: github/codeql-action dependency-version: 4.35.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gha-updates - dependency-name: rhysd/action-setup-vim dependency-version: 1.6.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gha-updates - dependency-name: codecov/codecov-action dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gha-updates - dependency-name: actions-rust-lang/setup-rust-toolchain dependency-version: 1.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gha-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent d0b9d64 commit f5c928c

5 files changed

Lines changed: 28 additions & 28 deletions

File tree

.github/workflows/lint.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,11 +36,11 @@ jobs:
3636
python-version: ${{ matrix.python-version }}
3737
allow-prereleases: true
3838
- name: Install uv
39-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
39+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
4040
with:
4141
enable-cache: true
4242
- name: Install Just
43-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
43+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
4444
- name: Install Dependencies
4545
env:
4646
PYTHON_PATH: ${{ steps.sp.outputs.python-path }}

.github/workflows/release.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -47,13 +47,13 @@ jobs:
4747
with:
4848
python-version: ">=3.11" # for tomlib
4949
- name: Install uv
50-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
50+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
5151
with:
5252
enable-cache: false
5353
restore-cache: false
5454
save-cache: false
5555
- name: Setup Just
56-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
56+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
5757
- name: Verify Tag
5858
run: |
5959
TAG_NAME=${GITHUB_REF#refs/tags/}
@@ -74,7 +74,7 @@ jobs:
7474
- name: Build the binary wheel and a source tarball
7575
run: just build
7676
- name: Store the distribution packages
77-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
77+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
7878
with:
7979
name: python-package-distributions
8080
path: dist/
@@ -98,12 +98,12 @@ jobs:
9898
id-token: write # IMPORTANT: mandatory for trusted publishing
9999
steps:
100100
- name: Download all the dists
101-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3
101+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
102102
with:
103103
name: python-package-distributions
104104
path: dist/
105105
- name: Publish distribution 📦 to PyPI
106-
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e
106+
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b
107107

108108
github-release:
109109
name: Publish GitHub Release
@@ -118,12 +118,12 @@ jobs:
118118

119119
steps:
120120
- name: Download all the dists
121-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3
121+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
122122
with:
123123
name: python-package-distributions
124124
path: dist/
125125
- name: Sign the dists with Sigstore
126-
uses: sigstore/gh-action-sigstore-python@a5caf349bc536fbef3668a10ed7f5cd309a4b53d
126+
uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc
127127
with:
128128
inputs: >-
129129
./dist/*.tar.gz

.github/workflows/scorecard.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ jobs:
4848
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
4949
# format to the repository Actions tab.
5050
- name: "Upload artifact"
51-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
51+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
5252
with:
5353
name: SARIF file
5454
path: results.sarif
@@ -57,6 +57,6 @@ jobs:
5757
# Upload the results to GitHub's code scanning dashboard (optional).
5858
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
5959
- name: "Upload to code-scanning"
60-
uses: github/codeql-action/upload-sarif@c793b717bc78562f491db7b0e93a3a178b099162
60+
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225
6161
with:
6262
sarif_file: results.sarif

.github/workflows/test.yml

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -52,9 +52,9 @@ jobs:
5252
python-version: ${{ matrix.python-version }}
5353
allow-prereleases: true
5454
- name: Install Just
55-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
55+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
5656
- name: Install uv
57-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
57+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
5858
with:
5959
enable-cache: true
6060
- name: Install Emacs
@@ -76,7 +76,7 @@ jobs:
7676
just test
7777
7878
- name: Store coverage files
79-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
79+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
8080
with:
8181
name: ${{ env.COVERAGE_FILE }}
8282
path: ${{ env.COVERAGE_FILE }}
@@ -107,9 +107,9 @@ jobs:
107107
python-version: ${{ matrix.python-version }}
108108
allow-prereleases: true
109109
- name: Install Just
110-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
110+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
111111
- name: Install uv
112-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
112+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
113113
with:
114114
enable-cache: true
115115
- name: install-emacs-macos
@@ -131,7 +131,7 @@ jobs:
131131
just test
132132
133133
- name: Store coverage files
134-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
134+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
135135
with:
136136
name: ${{ env.COVERAGE_FILE }}
137137
path: ${{ env.COVERAGE_FILE }}
@@ -161,14 +161,14 @@ jobs:
161161
python-version: ${{ matrix.python-version }}
162162
allow-prereleases: true
163163
- name: Install Just
164-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
164+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
165165
- name: Install uv
166-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
166+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
167167
with:
168168
enable-cache: true
169169
- name: install-vim-windows
170170
if: ${{ github.event.inputs.debug == 'true' }}
171-
uses: rhysd/action-setup-vim@19e3dd31a84dbc2c5445d65e9b363f616cab96c1
171+
uses: rhysd/action-setup-vim@febef33995d6649302e9d88dda81e071b68f16a7
172172
- name: Setup tmate session
173173
if: ${{ github.event.inputs.debug == 'true' }}
174174
uses: mxschmitt/action-tmate@c0afd6f790e3a5564914980036ebf83216678101
@@ -184,7 +184,7 @@ jobs:
184184
just test
185185
186186
- name: Store coverage files
187-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
187+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
188188
with:
189189
name: ${{ env.COVERAGE_FILE }}
190190
path: ${{ env.COVERAGE_FILE }}
@@ -203,27 +203,27 @@ jobs:
203203
python-version: '3.14'
204204

205205
- name: Install uv
206-
uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098
206+
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
207207
with:
208208
enable-cache: true
209209
- name: Setup Just
210-
uses: extractions/setup-just@f8a3cce218d9f83db3a2ecd90e41ac3de6cdfd9b
210+
uses: extractions/setup-just@53165ef7e734c5c07cb06b3c8e7b647c5aa16db3
211211
- name: Install Release Dependencies
212212
env:
213213
PYTHON_PATH: ${{ steps.sp.outputs.python-path }}
214214
run: |
215215
just setup "$PYTHON_PATH"
216216
217217
- name: Get coverage files
218-
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3
218+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
219219
with:
220220
pattern: "*.coverage"
221221
merge-multiple: true
222222
- run: ls -la *.coverage
223223
- run: just coverage
224224

225225
- name: Upload coverage to Codecov
226-
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de
226+
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2
227227
with:
228228
token: ${{ secrets.CODECOV_TOKEN }}
229229
file: ./coverage.xml

.github/workflows/zizmor.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
persist-credentials: false
2828

2929
- name: Set up Rust
30-
uses: actions-rust-lang/setup-rust-toolchain@a0b538fa0b742a6aa35d6e2c169b4bd06d225a98
30+
uses: actions-rust-lang/setup-rust-toolchain@2b1f5e9b395427c92ee4e3331786ca3c37afe2d7
3131
- name: Install jq
3232
run: |
3333
sudo apt-get update
@@ -41,14 +41,14 @@ jobs:
4141
zizmor --format sarif .github/workflows/ > results.sarif
4242
4343
- name: Upload analysis results
44-
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
44+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
4545
with:
4646
name: zizmor-results
4747
path: results.sarif
4848
retention-days: 7
4949

5050
- name: Upload to code-scanning
51-
uses: github/codeql-action/upload-sarif@c793b717bc78562f491db7b0e93a3a178b099162
51+
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225
5252
with:
5353
sarif_file: results.sarif
5454

0 commit comments

Comments
 (0)