From 497074961ce36830d1591c04eb64abf774393b54 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sun, 11 Oct 2026 09:23:35 +0000 Subject: [PATCH] Bump the actions group across 1 directory with 11 updates Bumps the actions group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.4.0` | `7.0.1` | | [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `b66acf5e9fe20f8aba065be86778a8a4c846f902` | `3c6349835b2b7b196a839186cb8b78e02f7b5f25` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.2` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `8.0.2` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.4.1` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.6.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.19.2` | `7.4.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3.0.0` | `4.2.2` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.3.2` | `3.0.3` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `7.1.0` | | [actions/cache](https://github.com/actions/cache) | `4.3.0` | `6.1.0` | Updates `actions/checkout` from 4.4.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/11d5960a326750d5838078e36cf38b85af677262...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `EmbarkStudios/cargo-deny-action` from b66acf5e9fe20f8aba065be86778a8a4c846f902 to 3c6349835b2b7b196a839186cb8b78e02f7b5f25 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](https://github.com/embarkstudios/cargo-deny-action/compare/b66acf5e9fe20f8aba065be86778a8a4c846f902...3c6349835b2b7b196a839186cb8b78e02f7b5f25) Updates `actions/upload-artifact` from 4.6.2 to 7.0.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/ea165f8d65b6e75b540449e92b4886f43607fa02...cf430e030ddbb5b0abf93d22962f4752f3646cd9) Updates `actions/download-artifact` from 4.3.0 to 8.0.2 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/d3f86a106a0bac45b974a628896c90dbdf5c8093...9000827ccba6bdab643e8b6fd33ac0654aef8333) Updates `docker/setup-buildx-action` from 3.12.0 to 4.4.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/8d2750c68a42422c14e847fe6c8ac0403b4cbd6f...f87e5991a6d7451dcb8d9637bfbc97413f497069) Updates `docker/login-action` from 3.7.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...dbcb813823bdd20940b903addbd779551569679f) Updates `docker/build-push-action` from 6.19.2 to 7.4.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/10e90e3645eae34f1e60eeb005ba3a3d33f178e8...c3c9e263c25d99ce0380d002d59b67737d91b0dc) Updates `actions/attest-build-provenance` from 3.0.0 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/977bb373ede98d70efdf65b84cb5f73e068dcc2a...4d101475d8b20a2381f78447822ac1eab6504dd8) Updates `softprops/action-gh-release` from 2.3.2 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/72f2c25fcb47643c292f7107632f7a47c1df5cd8...efb35369e0ad2afab669f228072c1b0d510eae64) Updates `actions/setup-node` from 4.4.0 to 7.1.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/49933ea5288caeca8642d1e84afbd3f7d6820020...949feb2413d6458794dcd2491c4babbbce0c15c1) Updates `actions/cache` from 4.3.0 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](https://github.com/actions/cache/compare/0057852bfaa89a56745cba8c7296529d2fc39830...55cc8345863c7cc4c66a329aec7e433d2d1c52a9) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 3c6349835b2b7b196a839186cb8b78e02f7b5f25 dependency-type: direct:production dependency-group: actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/cf-sync.yml | 2 +- .github/workflows/e2e.yml | 2 +- .github/workflows/image.yml | 38 ++++++++++++++++---------------- .github/workflows/kl-connect.yml | 10 ++++----- .github/workflows/web.yml | 14 ++++++------ 5 files changed, 33 insertions(+), 33 deletions(-) diff --git a/.github/workflows/cf-sync.yml b/.github/workflows/cf-sync.yml index c89559c58..b67b8c986 100644 --- a/.github/workflows/cf-sync.yml +++ b/.github/workflows/cf-sync.yml @@ -16,5 +16,5 @@ jobs: check: runs-on: ubuntu-latest steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - run: deploy/cf-sync.sh diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 6668ade73..967508084 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -22,7 +22,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 45 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 - run: cargo build --locked --bin kloudlite diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index fc5ea6ddd..5d681ce5a 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -36,7 +36,7 @@ jobs: # finds the last run's compiled tests instead of starting cold. CARGO_TARGET_DIR: /home/azureuser/ci-target-test steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # The VM's own toolchain (rustup in ~/.cargo); the runner service starts with a bare PATH. - run: echo "$HOME/.cargo/bin" >> "$GITHUB_PATH" # `--all-targets`: the test targets are gated too, so a lint there is fixed in the PR that @@ -56,7 +56,7 @@ jobs: # `audit-check` above covers advisories only. This adds the three checks a repo with this # much crypto surface wants: banned/duplicate crates, licence policy, and source # allowlisting. Config lives in deny.toml, next to Cargo.toml. - - uses: EmbarkStudios/cargo-deny-action@b66acf5e9fe20f8aba065be86778a8a4c846f902 # v2 + - uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2 with: command: check @@ -96,7 +96,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - run: > cargo build --release --locked --bin kloudlite --bin kloudlite-api --bin kloudlite-worker @@ -119,7 +119,7 @@ jobs: echo "::error::$b needs $need, bookworm-slim ships 2.36"; exit 1 fi done - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 with: name: bins path: | @@ -135,7 +135,7 @@ jobs: if-no-files-found: error retention-days: 1 - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 with: name: kl-musl path: | @@ -160,29 +160,29 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 - - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 with: name: bins path: target/release - - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + - uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 with: name: kl-musl path: target/x86_64-unknown-linux-musl/release # upload-artifact drops the mode bits and the Dockerfile COPYs the files as they are. - run: chmod +x target/release/kloudlite* target/release/kl-connect target/x86_64-unknown-linux-musl/release/kl target/x86_64-unknown-linux-musl/release/bench-net target/x86_64-unknown-linux-musl/release/kloudlite-intercept-proxy - - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 with: # The classic driver: the VM's own daemon keeps every layer between runs, which is the # cache `type=gha` used to stand in for. driver: docker - - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} # No cache options: the VM's daemon caches every layer locally between runs. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: server @@ -192,7 +192,7 @@ jobs: tags: | ghcr.io/kloudlite/kloudlite:latest ghcr.io/kloudlite/kloudlite:${{ github.sha }} - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: agent @@ -201,7 +201,7 @@ jobs: tags: | ghcr.io/kloudlite/kloudlite-agent:latest ghcr.io/kloudlite/kloudlite-agent:${{ github.sha }} - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: gateway @@ -211,7 +211,7 @@ jobs: ghcr.io/kloudlite/kloudlite-gateway:latest ghcr.io/kloudlite/kloudlite-gateway:${{ github.sha }} # The cluster controller. Same commit as everything else: it reconciles the same CRDs. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: controller @@ -221,7 +221,7 @@ jobs: ghcr.io/kloudlite/kloudlite-controller:latest ghcr.io/kloudlite/kloudlite-controller:${{ github.sha }} # The build gate. Same commit as the api whose internal routes it calls. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: builder-gate @@ -232,7 +232,7 @@ jobs: ghcr.io/kloudlite/kloudlite-builder-gate:${{ github.sha }} # The forwarder behind an intercepted service. Same commit as the agent that renders its # pod: the argv is a contract between the two. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: intercept-proxy @@ -243,7 +243,7 @@ jobs: ghcr.io/kloudlite/kloudlite-intercept-proxy:${{ github.sha }} # The SLO probe. Same commit as the tier it probes, deliberately: a probe pinned behind the # fleet reports the previous release's journey and calls it green. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: slo @@ -255,7 +255,7 @@ jobs: # No binary of ours inside: the default workspace image is alpine plus what sshd and VS # Code need. Built here so it is pinned by the same SHA as the agent that renders pods # from it. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: workspace @@ -266,7 +266,7 @@ jobs: ghcr.io/kloudlite/kloudlite-workspace:${{ github.sha }} # The bench image (deploy/bench/Dockerfile). A separate Dockerfile, same context, so it also # reaches the kl-musl artifact downloaded above. - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: deploy/bench/Dockerfile diff --git a/.github/workflows/kl-connect.yml b/.github/workflows/kl-connect.yml index 19244afc3..130cf2ed3 100644 --- a/.github/workflows/kl-connect.yml +++ b/.github/workflows/kl-connect.yml @@ -31,7 +31,7 @@ jobs: runs-on: ${{ matrix.os }} timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: targets: ${{ matrix.target }} @@ -61,7 +61,7 @@ jobs: name="kl-tui-${{ matrix.target }}" bun build --compile --target=${{ matrix.tui }} harness/apps/tui/src/remote.tsx --outfile "$name" shasum -a 256 "$name" > "$name.sha256" 2>/dev/null || sha256sum "$name" > "$name.sha256" - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 with: name: kl-connect-${{ matrix.target }} path: | @@ -80,7 +80,7 @@ jobs: id-token: write attestations: write steps: - - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 + - uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 with: path: dist merge-multiple: true @@ -89,12 +89,12 @@ jobs: # `sha256sums` proves a download is intact; this proves it came from THIS workflow on THIS # commit (`gh attestation verify kl-connect- -R kloudlite/kloudlite`). Free for a public # repo, and the only origin signal `install.sh`'s same-origin checksum cannot give. - - uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3 + - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-path: | dist/kl-connect-* dist/kl-tui-* - - uses: softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8 # v2 + - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v2 with: files: dist/* generate_release_notes: true diff --git a/.github/workflows/web.yml b/.github/workflows/web.yml index d6208876c..e7f00e6bc 100644 --- a/.github/workflows/web.yml +++ b/.github/workflows/web.yml @@ -20,15 +20,15 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version: 1.3.14 - - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 + - uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: 22 - name: Cache turbo - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: web/.turbo # Keyed on the lockfile, not the commit: a per-commit key can never hit and writes a @@ -53,9 +53,9 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 - - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3 - - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 + - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -63,7 +63,7 @@ jobs: # `/docs` reads `apps/web/content/docs` in the image (see `lib/docs.ts`); git-ignored, # so the docs are copied in here, the same way `deploy/dev/pod/ship.sh` does. - run: mkdir -p apps/web/content && cp -r ../docs/product apps/web/content/docs - - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: web platforms: linux/amd64