Bump the actions group across 1 directory with 9 updates #288
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 9 updates in the / directory:
5.3.15.5.10.0.160.0.242.3.02.4.04.5.04.8.24.6.05.0.02.0.02.1.04.1.86.0.0f456a002d58f0de60b44383d10ae82316b18a1669b0e87d012c1f27ad7b823389e5d826a0aff2c422.4.02.4.3Updates
codecov/codecov-actionfrom 5.3.1 to 5.5.1Release notes
Sourced from codecov/codecov-action's releases.
... (truncated)
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)a4803c1build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)3139621build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)fdcc847chore(release): 5.5.0 (#1865)Updates
sigstore/sigstore-conformancefrom 0.0.16 to 0.0.24Release notes
Sourced from sigstore/sigstore-conformance's releases.
... (truncated)
Commits
b7856cfVarious small fixes (#294)dd1ad2bPass client_sha and client_sha_url as pytest metadata (#288)e791f60Bump the python-minor-and-patch-updates group with 2 updates (#289)183d5afBump pytest from 8.4.2 to 9.0.0 (#290)6570148action: Fix if-clause (#286)51e74cdfeat: Include conformance action version in client report (#283)8c484c2feat: Add links to client SHA and workflow run (#284)8c2405cAllow skipping of artifact upload (#277)30c1d4dBump platformdirs in the python-minor-and-patch-updates group (#281)63f50feBump actions/upload-artifact from 4 to 5 in the actions group (#282)Updates
theupdateframework/tuf-conformancefrom 2.3.0 to 2.4.0Release notes
Sourced from theupdateframework/tuf-conformance's releases.
Commits
500c525Prepare 2.4 release (#324)68e81e9Publish a conformance report (#322)daf5ad1Bump ruff from 0.14.2 to 0.14.3 in the python-dependencies group (#320)8b425a2Bump ruff from 0.14.1 to 0.14.2 in the python-dependencies group (#319)eaca9f1Bump actions/upload-artifact from 4.6.2 to 5.0.0 (#318)032d542Bump ruff from 0.14.0 to 0.14.1 in the python-dependencies group (#317)0e9e191Bump ruff from 0.13.3 to 0.14.0 in the python-dependencies group (#316)78f59abBump ruff from 0.13.2 to 0.13.3 in the python-dependencies group (#315)f678c10Bump the python-dependencies group with 2 updates (#314)f01395dBump the python-dependencies group with 2 updates (#312)Updates
actions/dependency-review-actionfrom 4.5.0 to 4.8.2Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
3c4e3dcMerge pull request #1016 from actions/dra-release02930b2Update CONTRIBUTING to reflect new guidelines49ffd9fUpdate CONTRIBUTING to reflect the need to build70cb25e4.8.2 releaseebabd31Merge pull request #1008 from danielhardej/danielhardej-patch-2025102319f9360Update package-lock.json5fd2f98Bump@types/jestto version 29.5.1428647f4Fix PURL parsing by removing encodeURIf620fd1Merge pull request #1013 from actions/dangoor/token-fix9b42b7eRemove bad token referenceUpdates
actions/upload-artifactfrom 4.6.0 to 5.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.mdUpdates
slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.ymlfrom 2.0.0 to 2.1.0Release notes
Sourced from slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml's releases.
... (truncated)
Changelog
Sourced from slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml's changelog.
Commits
f7dd8c5update the ref in the pre-submit0a5124bfix jq for the sigstore bundlesfbeecf0update docsf701310update workflows3618598v2.1.0-rc.346f81fcchore: update refs to v2.1.0-rc.1 (#4120)5d20c93chore: use builder tag v2.1.0-rc.0 (#4118)e27b237chore: braces and ejs vulns (#4116)8967e1cchore: Update CODEOWNERS (#4115)47d1954chore: update octokit deps (#4114)Updates
actions/download-artifactfrom 4.1.8 to 6.0.0Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
018cc2cMerge pull request #438 from actions/danwkennedy/prepare-6.0.0815651cRevert "Removegithub.dep.yml"bb3a066Removegithub.dep.ymlfa1ce46Preparev6.0.04a24838Merge pull request #431 from danwkennedy/patch-15e3251cReadme: spell out the first use of GHESabefc31Merge pull request #424 from actions/yacaovsnc/update_readmeac43a60Update README with artifact extraction detailsde96f46Merge pull request #417 from actions/yacaovsnc/update_readme7993cb4Remove migration guide for artifact download changesUpdates
rubygems/configure-rubygems-credentialsfrom f456a00...Description has been truncated