Skip to content

Commit 3dcd0f5

Browse files
Bump zgosalvez/github-actions-ensure-sha-pinned-actions from 3.0.25 to 4.0.0 (#1149)
Bumps [zgosalvez/github-actions-ensure-sha-pinned-actions](https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions) from 3.0.25 to 4.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/releases">zgosalvez/github-actions-ensure-sha-pinned-actions's releases</a>.</em></p> <blockquote> <h2>v4.0.0</h2> <h2>What's Changed</h2> <ul> <li>Bump <code>@​vercel/ncc</code> from 0.38.3 to 0.38.4 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/257">zgosalvez/github-actions-ensure-sha-pinned-actions#257</a></li> <li>Bump actions/checkout from 4.2.2 to 5.0.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/253">zgosalvez/github-actions-ensure-sha-pinned-actions#253</a></li> <li>Bump eslint from 9.26.0 to 9.36.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/256">zgosalvez/github-actions-ensure-sha-pinned-actions#256</a></li> <li>Bump jest from 29.7.0 to 30.1.3 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/255">zgosalvez/github-actions-ensure-sha-pinned-actions#255</a></li> <li>Bump actions/cache from 4.2.3 to 4.2.4 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/252">zgosalvez/github-actions-ensure-sha-pinned-actions#252</a></li> <li>Bump zgosalvez/github-actions-get-action-runs-using-version from 2.0.22 to 2.0.24 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/234">zgosalvez/github-actions-ensure-sha-pinned-actions#234</a></li> <li>Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/242">zgosalvez/github-actions-ensure-sha-pinned-actions#242</a></li> <li>Bump yaml from 2.7.1 to 2.8.1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/248">zgosalvez/github-actions-ensure-sha-pinned-actions#248</a></li> <li>Bump brace-expansion from 1.1.11 to 1.1.12 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/258">zgosalvez/github-actions-ensure-sha-pinned-actions#258</a></li> <li>fix <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/116">#116</a>: support composite actions by <a href="https://github.com/atchertchian"><code>@​atchertchian</code></a> in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/239">zgosalvez/github-actions-ensure-sha-pinned-actions#239</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/atchertchian"><code>@​atchertchian</code></a> made their first contribution in <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/239">zgosalvez/github-actions-ensure-sha-pinned-actions#239</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/compare/v3...v4.0.0">https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/compare/v3...v4.0.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/9e9574ef04ea69da568d6249bd69539ccc704e74"><code>9e9574e</code></a> fix <a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/116">#116</a>: support composite actions (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/239">#239</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/574bec881388e64d0d8e0c56dcbb496375d4374b"><code>574bec8</code></a> Bump brace-expansion from 1.1.11 to 1.1.12 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/258">#258</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/bdf825ce9be0f67756a2e0b806479e2c8290f618"><code>bdf825c</code></a> Bump yaml from 2.7.1 to 2.8.1 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/248">#248</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/12cd4d24acf3c6f74510506fa441447e4bd6339d"><code>12cd4d2</code></a> Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/242">#242</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/2783169172127fb9d223b6af54c3bc915b594a53"><code>2783169</code></a> Bump zgosalvez/github-actions-get-action-runs-using-version (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/234">#234</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/d952774b559ae45059ade91d67ae2bd0373be537"><code>d952774</code></a> Bump actions/cache from 4.2.3 to 4.2.4 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/252">#252</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/e839297c01ab5069940f48e00a82f376619980bb"><code>e839297</code></a> Bump jest from 29.7.0 to 30.1.3 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/255">#255</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/f1328f73d9e40866d49a38026d3349f8ed0eefb9"><code>f1328f7</code></a> Bump eslint from 9.26.0 to 9.36.0 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/256">#256</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/74db6f07221290991deecb6f0ab793100d000247"><code>74db6f0</code></a> Bump actions/checkout from 4.2.2 to 5.0.0 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/253">#253</a>)</li> <li><a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/commit/cae7e0675a80a3984967ae1e095169bc9442afad"><code>cae7e06</code></a> Bump <code>@​vercel/ncc</code> from 0.38.3 to 0.38.4 (<a href="https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/257">#257</a>)</li> <li>See full diff in <a href="https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/compare/fc87bb5b5a97953d987372e74478de634726b3e5...9e9574ef04ea69da568d6249bd69539ccc704e74">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=zgosalvez/github-actions-ensure-sha-pinned-actions&package-manager=github_actions&previous-version=3.0.25&new-version=4.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 14004b3 commit 3dcd0f5

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

.github/workflows/ci.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -558,7 +558,7 @@ jobs:
558558

559559
# The next action simply fails if there are any unpinned actions.
560560
- name: Verify that all workflow actions have pinned versions
561-
uses: zgosalvez/github-actions-ensure-sha-pinned-actions@fc87bb5b5a97953d987372e74478de634726b3e5
561+
uses: zgosalvez/github-actions-ensure-sha-pinned-actions@9e9574ef04ea69da568d6249bd69539ccc704e74
562562

563563
# If we didn't fail the previous check, go on to more time-consuming ones.
564564
- name: Install actionlint

0 commit comments

Comments
 (0)