Skip to content

Commit 2eaecbf

Browse files
Bump the github-actions group with 3 updates (#516)
Bumps the github-actions group with 3 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner), [actions/cache](https://github.com/actions/cache) and [github/codeql-action](https://github.com/github/codeql-action). Updates `step-security/harden-runner` from 2.17.0 to 2.18.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@f808768...6c3c2f2) Updates `actions/cache` from 5.0.4 to 5.0.5 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@6682284...27d5ce7) Updates `github/codeql-action` from 4.35.1 to 4.35.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@c10b806...95e58e9) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/cache dependency-version: 5.0.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.35.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent ee3434d commit 2eaecbf

8 files changed

Lines changed: 45 additions & 45 deletions

File tree

.github/workflows/part_dependency_submission.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020

2121
steps:
2222
- name: Harden Runner
23-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
23+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
2424
with:
2525
egress-policy: audit
2626

.github/workflows/part_docs.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727

2828
steps:
2929
- name: Harden Runner
30-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
30+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
3131
with:
3232
egress-policy: audit
3333

@@ -37,13 +37,13 @@ jobs:
3737
with:
3838
version-file: .tool-versions
3939
version-type: strict
40-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
40+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
4141
with:
4242
path: _build
4343
key: docs-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('rebar.config') }}
4444
restore-keys: |
4545
docs-build-{{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-
46-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
46+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
4747
with:
4848
path: deps
4949
key: docs-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('rebar.config') }}

.github/workflows/part_license.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323

2424
steps:
2525
- name: Harden Runner
26-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
26+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
2727
with:
2828
egress-policy: audit
2929

@@ -44,7 +44,7 @@ jobs:
4444

4545
steps:
4646
- name: Harden Runner
47-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
47+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
4848
with:
4949
egress-policy: audit
5050

.github/workflows/part_publish.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626

2727
steps:
2828
- name: Harden Runner
29-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
29+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
3030
with:
3131
egress-policy: audit
3232

@@ -36,13 +36,13 @@ jobs:
3636
with:
3737
version-file: .tool-versions
3838
version-type: strict
39-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
39+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
4040
with:
4141
path: _build
4242
key: mix_hex_publish-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
4343
restore-keys: |
4444
mix_hex_publish-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-
45-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
45+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
4646
with:
4747
path: deps
4848
key: mix_hex_publish-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}

.github/workflows/part_release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828

2929
steps:
3030
- name: Harden Runner
31-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
31+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
3232
with:
3333
egress-policy: audit
3434

.github/workflows/part_test.yml

Lines changed: 32 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929

3030
steps:
3131
- name: Harden Runner
32-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
32+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
3333
with:
3434
egress-policy: audit
3535

@@ -56,7 +56,7 @@ jobs:
5656

5757
steps:
5858
- name: Harden Runner
59-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
59+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
6060
with:
6161
egress-policy: audit
6262

@@ -66,7 +66,7 @@ jobs:
6666
with:
6767
version-file: .tool-versions
6868
version-type: strict
69-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
69+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
7070
with:
7171
path: _build
7272
key: rebar_format-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -81,7 +81,7 @@ jobs:
8181

8282
steps:
8383
- name: Harden Runner
84-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
84+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
8585
with:
8686
egress-policy: audit
8787

@@ -91,13 +91,13 @@ jobs:
9191
with:
9292
version-file: .tool-versions
9393
version-type: strict
94-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
94+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
9595
with:
9696
path: _build
9797
key: mix_format-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
9898
restore-keys: |
9999
mix_format-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-
100-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
100+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
101101
with:
102102
path: deps
103103
key: mix_format-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
@@ -129,7 +129,7 @@ jobs:
129129

130130
steps:
131131
- name: Harden Runner
132-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
132+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
133133
with:
134134
egress-policy: audit
135135

@@ -140,7 +140,7 @@ jobs:
140140
otp-version: ${{ matrix.otp }}
141141
rebar3-version: "${{ needs.detectToolVersions.outputs.rebarVersion }}"
142142
version-type: strict
143-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
143+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
144144
with:
145145
path: _build
146146
key: eunit-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -177,7 +177,7 @@ jobs:
177177

178178
steps:
179179
- name: Harden Runner
180-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
180+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
181181
with:
182182
egress-policy: audit
183183

@@ -188,7 +188,7 @@ jobs:
188188
otp-version: ${{ matrix.otp }}
189189
rebar3-version: "${{ needs.detectToolVersions.outputs.rebarVersion }}"
190190
version-type: strict
191-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
191+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
192192
with:
193193
path: _build
194194
key: ct-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -228,7 +228,7 @@ jobs:
228228

229229
steps:
230230
- name: Harden Runner
231-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
231+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
232232
with:
233233
egress-policy: audit
234234

@@ -240,13 +240,13 @@ jobs:
240240
rebar3-version: "${{ needs.detectToolVersions.outputs.rebarVersion }}"
241241
elixir-version: "${{ matrix.elixir }}"
242242
version-type: strict
243-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
243+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
244244
with:
245245
path: _build
246246
key: mix_test-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('mix.exs') }}
247247
restore-keys: |
248248
mix_test-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-
249-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
249+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
250250
with:
251251
path: deps
252252
key: mix_test-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('mix.exs') }}
@@ -270,7 +270,7 @@ jobs:
270270

271271
steps:
272272
- name: Harden Runner
273-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
273+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
274274
with:
275275
egress-policy: audit
276276

@@ -280,7 +280,7 @@ jobs:
280280
with:
281281
version-file: .tool-versions
282282
version-type: strict
283-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
283+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
284284
with:
285285
path: _build
286286
key: mix_test_coverage-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('mix.exs') }}
@@ -294,7 +294,7 @@ jobs:
294294
mkdir cover
295295
mv artifacts/*/*.coverdata cover
296296
rm -rf artifacts
297-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
297+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
298298
with:
299299
path: deps
300300
key: mix_test_coverage-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ steps.setupBEAM.outputs.elixir-version }}-${{ hashFiles('mix.exs') }}
@@ -316,7 +316,7 @@ jobs:
316316

317317
steps:
318318
- name: Harden Runner
319-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
319+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
320320
with:
321321
egress-policy: audit
322322

@@ -326,7 +326,7 @@ jobs:
326326
with:
327327
version-file: .tool-versions
328328
version-type: strict
329-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
329+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
330330
with:
331331
path: _build
332332
key: cover-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -352,7 +352,7 @@ jobs:
352352

353353
steps:
354354
- name: Harden Runner
355-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
355+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
356356
with:
357357
egress-policy: audit
358358

@@ -362,7 +362,7 @@ jobs:
362362
with:
363363
version-file: .tool-versions
364364
version-type: strict
365-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
365+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
366366
with:
367367
path: _build
368368
key: lint-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -381,7 +381,7 @@ jobs:
381381

382382
steps:
383383
- name: Harden Runner
384-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
384+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
385385
with:
386386
egress-policy: audit
387387

@@ -391,13 +391,13 @@ jobs:
391391
with:
392392
version-file: .tool-versions
393393
version-type: strict
394-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
394+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
395395
with:
396396
path: _build
397397
key: credo-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
398398
restore-keys: |
399399
credo-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-
400-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
400+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
401401
with:
402402
path: deps
403403
key: credo-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
@@ -407,7 +407,7 @@ jobs:
407407
- run: mix deps.compile
408408
- run: mix credo --format sarif > results.sarif
409409
- name: Upload SARIF file
410-
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v3.29.5
410+
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v3.29.5
411411
with:
412412
sarif_file: results.sarif
413413
category: credo
@@ -419,7 +419,7 @@ jobs:
419419

420420
steps:
421421
- name: Harden Runner
422-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
422+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
423423
with:
424424
egress-policy: audit
425425

@@ -429,13 +429,13 @@ jobs:
429429
with:
430430
version-file: .tool-versions
431431
version-type: strict
432-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
432+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
433433
with:
434434
path: _build
435435
key: dialyxir-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
436436
restore-keys: |
437437
dialyxir-build-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-
438-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
438+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
439439
with:
440440
path: deps
441441
key: dialyxir-deps-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('mix.exs') }}
@@ -451,7 +451,7 @@ jobs:
451451

452452
steps:
453453
- name: Harden Runner
454-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
454+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
455455
with:
456456
egress-policy: audit
457457

@@ -461,7 +461,7 @@ jobs:
461461
with:
462462
version-file: .tool-versions
463463
version-type: strict
464-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
464+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
465465
with:
466466
path: _build
467467
key: dialyzer-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -476,7 +476,7 @@ jobs:
476476

477477
steps:
478478
- name: Harden Runner
479-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
479+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
480480
with:
481481
egress-policy: audit
482482

@@ -486,7 +486,7 @@ jobs:
486486
with:
487487
version-file: .tool-versions
488488
version-type: strict
489-
- uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
489+
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
490490
with:
491491
path: _build
492492
key: hank-${{ runner.os }}-${{ steps.setupBEAM.outputs.otp-version }}-${{ hashFiles('rebar.config') }}
@@ -501,7 +501,7 @@ jobs:
501501

502502
steps:
503503
- name: Harden Runner
504-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
504+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
505505
with:
506506
egress-policy: audit
507507

.github/workflows/pr.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555

5656
steps:
5757
- name: Harden Runner
58-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
58+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
5959
with:
6060
egress-policy: audit
6161

.github/workflows/scorecards.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ jobs:
3939

4040
steps:
4141
- name: Harden Runner
42-
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
42+
uses: step-security/harden-runner@6c3c2f2c1c457b00c10c4848d6f5491db3b629df # v2.18.0
4343
with:
4444
egress-policy: audit
4545

@@ -79,6 +79,6 @@ jobs:
7979

8080
# Upload the results to GitHub's code scanning dashboard.
8181
- name: "Upload to code-scanning"
82-
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v3.29.5
82+
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v3.29.5
8383
with:
8484
sarif_file: results.sarif

0 commit comments

Comments
 (0)