Skip to content

Chore: Update dependencies #1

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 98 commits into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
98 commits
Select commit Hold shift + click to select a range
488f2fe
Update Node.js to v22 (#452)
renovate[bot] Feb 12, 2025
0e2b52b
Update dependency eslint to ^9.20.1 (#454)
renovate[bot] Feb 12, 2025
9cddae1
Update dependency semver to ^7.7.1 (#455)
renovate[bot] Feb 12, 2025
b17e2a5
Update dependency prettier to v3.5.0 (#458)
renovate[bot] Feb 12, 2025
77189ca
Update github/codeql-action action to v3.28.9 (#456)
renovate[bot] Feb 18, 2025
519cf8c
Update dependency prettier to v3.5.1 (#459)
renovate[bot] Feb 18, 2025
7a2c6a2
Update dependency rollup to ^4.34.8 (#460)
renovate[bot] Feb 18, 2025
ebbf5b8
Update dependency @docker/actions-toolkit to ^0.54.0 (#457)
renovate[bot] Feb 18, 2025
16eb6c7
Update typescript-eslint monorepo to ^8.24.1 (#462)
renovate[bot] Feb 18, 2025
9d48911
Update reviewdog/action-actionlint action to v1.65.0 (#461)
renovate[bot] Feb 19, 2025
e78be78
Set pre-commit schedule to quarterly (#464)
lucacome Feb 24, 2025
91df04a
[pre-commit.ci] pre-commit autoupdate (#463)
pre-commit-ci[bot] Feb 24, 2025
356e1c0
Test the JSON output properly (#465)
lucacome Feb 26, 2025
0ccc2c5
Add yamllint to pre-commit config and markdownlint (#466)
lucacome Feb 26, 2025
3e85fb2
Add more data in tests (#467)
lucacome Feb 26, 2025
a4fba0e
Add actionlint to pre-commit config (#468)
lucacome Feb 26, 2025
10d6275
Update typescript-eslint monorepo to ^8.25.0 (#478)
renovate[bot] Feb 26, 2025
c380e54
Update eslint monorepo to ^9.21.0 (#477)
renovate[bot] Feb 26, 2025
4e9eb72
Update ossf/scorecard-action action to v2.4.1 (#475)
renovate[bot] Feb 26, 2025
3c5c419
Update github/codeql-action action to v3.28.10 (#474)
renovate[bot] Feb 26, 2025
bb74928
Update actions/upload-artifact action to v4.6.1 (#469)
renovate[bot] Feb 26, 2025
3332642
Update dependency @eslint/compat to ^1.2.7 (#470)
renovate[bot] Feb 26, 2025
e6cf2a9
Update dependency @types/node to ^22.13.5 (#471)
renovate[bot] Feb 26, 2025
b341400
Update dependency prettier to v3.5.2 (#472)
renovate[bot] Feb 26, 2025
95600c6
Update dependency ts-jest to ^29.2.6 (#473)
renovate[bot] Feb 26, 2025
d9b088f
Update dependency @docker/actions-toolkit to ^0.56.0 (#476)
renovate[bot] Feb 26, 2025
0b9c5bd
Update dependency eslint-config-prettier to ^10.0.2 (#479)
renovate[bot] Feb 26, 2025
7205c58
Add option to group updates of the same dependency (#480)
lucacome Feb 26, 2025
003ab1c
📝 Add docstrings to context and notes (#481)
coderabbitai[bot] Feb 26, 2025
fe0839a
Handle pre-commit deps and more renovate options (#482)
lucacome Feb 26, 2025
008faa8
Update Node.js (#485)
renovate[bot] Feb 27, 2025
658ffdb
Lock file maintenance (#486)
renovate[bot] Feb 27, 2025
54ef61a
Support conventional commits (#484)
lucacome Feb 28, 2025
2688ed7
Add ignore generated file for CodeQL (#487)
lucacome Feb 28, 2025
49a7b6e
Add permissions in test workflow (#488)
lucacome Feb 28, 2025
aab8b2e
Update actions/setup-node action to v4.2.0 (#489)
renovate[bot] Feb 28, 2025
89013b0
Lock file maintenance (#490)
renovate[bot] Feb 28, 2025
903d87d
Order PRs by number (#491)
lucacome Feb 28, 2025
b8e53f1
Update dependency typescript to ^5.8.2 (#494)
renovate[bot] Mar 1, 2025
44a6deb
Update dependency @types/node to ^22.13.7 (#493)
renovate[bot] Mar 1, 2025
b4c5db0
Fix missing sections (#492)
lucacome Mar 1, 2025
e8f80d7
New line after collapsing (#495)
lucacome Mar 1, 2025
54df08f
Fix removing lines where no new contributors (#496)
lucacome Mar 1, 2025
4fd1ea6
Update dependency @types/node to ^22.13.8 (#499)
renovate[bot] Mar 1, 2025
b0aeebc
Add newlines after sections (#498)
lucacome Mar 1, 2025
9e620cf
Update dependency rollup to ^4.34.9 (#500)
renovate[bot] Mar 1, 2025
c60e7d6
Update dependency prettier to v3.5.3 (#501)
renovate[bot] Mar 4, 2025
70ecdbc
Update dependency lucacome/draft-release to v1.2.1 (#504)
renovate[bot] Mar 4, 2025
86518e1
Update Yarn to v4.7.0 (#503)
renovate[bot] Mar 4, 2025
9a39dc2
Lock file maintenance (#497)
renovate[bot] Mar 4, 2025
4acd611
Update typescript-eslint monorepo to ^8.26.1 (#507)
renovate[bot] Mar 11, 2025
71ebb39
Update eslint monorepo to ^9.22.0 (#511)
renovate[bot] Mar 11, 2025
b8359c6
Update dependency @rollup/plugin-commonjs to ^28.0.3 (#505)
renovate[bot] Mar 12, 2025
64790e9
Update dependency rollup to ^4.35.0 (#510)
renovate[bot] Mar 12, 2025
ab97b31
Update github/codeql-action action to v3.28.11 (#506)
renovate[bot] Mar 12, 2025
0031fe7
Update Node.js to v20.18.3 (#508)
renovate[bot] Mar 12, 2025
441344e
Update dependency @docker/actions-toolkit to ^0.57.0 (#513)
renovate[bot] Mar 12, 2025
4f9b0b7
Update pre-commit hook adrienverge/yamllint to v1.36.0 (#514)
renovate[bot] Mar 12, 2025
7f90081
Update dependency @rollup/plugin-node-resolve to ^16.0.1 (#512)
renovate[bot] Mar 12, 2025
7605d53
Update dependency eslint-config-prettier to ^10.1.1 (#509)
renovate[bot] Mar 12, 2025
83bed83
Update typescript-eslint monorepo to ^8.29.1 (#533)
renovate[bot] Apr 8, 2025
17718ae
Update github/codeql-action action to v3.28.15 (#519)
renovate[bot] Apr 8, 2025
9511a8e
Update pre-commit hook adrienverge/yamllint to v1.37.0 (#531)
renovate[bot] Apr 8, 2025
735293b
Update actions/upload-artifact action to v4.6.2 (#515)
renovate[bot] Apr 8, 2025
354f99a
Update reviewdog/action-actionlint action to v1.65.2 (#521)
renovate[bot] Apr 8, 2025
4cfd564
Update dependency @eslint/compat to ^1.2.8 (#516)
renovate[bot] Apr 8, 2025
7fd5f66
Update actions/dependency-review-action action to v4.6.0 (#524)
renovate[bot] Apr 9, 2025
25c71b9
Update Yarn to v4.9.0 (#523)
renovate[bot] Apr 9, 2025
6d6e472
Update reviewdog/action-yamllint action to v1.21.0 (#532)
renovate[bot] Apr 9, 2025
9fd42f7
Update pre-commit hook gitleaks/gitleaks to v8.24.2 (#520)
renovate[bot] Apr 9, 2025
d6c5441
Update dependency typescript to ^5.8.3 (#518)
renovate[bot] Apr 9, 2025
4fcf7bf
Update eslint monorepo to ^9.24.0 (#530)
renovate[bot] Apr 9, 2025
9f46391
Update dependency ts-jest to ^29.3.1 (#529)
renovate[bot] Apr 10, 2025
8636cf5
Update dependency rollup to ^4.39.0 (#528)
renovate[bot] Apr 10, 2025
ed830cb
Update dependency @types/semver to ^7.7.0 (#527)
renovate[bot] Apr 13, 2025
3899975
Update dependency @docker/actions-toolkit to ^0.59.0 (#526)
renovate[bot] Apr 14, 2025
d8f40a9
Update actions/setup-node action to v4.3.0 (#525)
renovate[bot] Apr 14, 2025
6322ffe
Update dependency eslint-plugin-prettier to ^5.2.6 (#517)
renovate[bot] Apr 14, 2025
890876e
Update dependency eslint-config-prettier to ^10.1.2 (#536)
renovate[bot] Apr 14, 2025
c2f5dd6
Update pre-commit hook gitleaks/gitleaks to v8.24.3 (#538)
renovate[bot] Apr 14, 2025
f94aa4b
Update dependency ts-jest to ^29.3.2 (#537)
renovate[bot] Apr 14, 2025
7c367dc
Update dependency rollup to ^4.40.0 (#539)
renovate[bot] Apr 14, 2025
e4d3ee6
Update actions/setup-node action to v4.4.0 (#540)
renovate[bot] Apr 14, 2025
ac2d53b
Update Yarn to v4.9.1 (#541)
renovate[bot] Apr 14, 2025
b4fb68b
Update typescript-eslint monorepo to ^8.30.1 (#542)
renovate[bot] Apr 14, 2025
72c8dce
Use node 20 (#543)
lucacome Apr 14, 2025
59fb8ba
Update Node.js to v20.19.0 (#522)
renovate[bot] Apr 14, 2025
7bc6320
Migrate renovate config (#544)
renovate[bot] Apr 14, 2025
f15262d
Lock file maintenance (#545)
renovate[bot] Apr 14, 2025
7083b0b
Update typescript-eslint monorepo to ^8.31.1 (#553)
renovate[bot] Apr 29, 2025
f094c2c
Update stefanzweifel/git-auto-commit-action action to v5.2.0 (#552)
renovate[bot] Apr 29, 2025
42641bc
Update dependency @docker/actions-toolkit to ^0.61.0 (#550)
renovate[bot] Apr 29, 2025
6770c68
Update Node.js to v20.19.1 (#549)
renovate[bot] Apr 30, 2025
dac2eae
Update github/codeql-action action to v3.28.16 (#548)
renovate[bot] Apr 30, 2025
955313c
Update dependency lucacome/draft-release to v1.2.2 (#546)
renovate[bot] Apr 30, 2025
5958e6b
Update eslint monorepo to ^9.25.1 (#551)
renovate[bot] Apr 30, 2025
c637372
Update pre-commit hook gitleaks/gitleaks to v8.25.1 (#554)
renovate[bot] Apr 30, 2025
9a005e6
Update dependency rollup to ^4.40.1 (#547)
renovate[bot] Apr 30, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/codeql-config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
paths-ignore:
- dist/
- lib/
4 changes: 2 additions & 2 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@ documentation:
- any-glob-to-any-file: '**/*.md'

dependencies:
- head-branch: ['^deps/', '^dep/', '^dependabot/']
- head-branch: ['^deps/', '^dep/', '^dependabot/', '^renovate/']
- changed-files:
- any-glob-to-any-file: ['package.json', 'package-lock.json']
- any-glob-to-any-file: ['package.json', 'yarn.lock']
13 changes: 10 additions & 3 deletions .github/workflows/check-dist.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,11 +14,18 @@ on:
pull_request:
paths-ignore:
- '**.md'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: ${{ github.ref_name }}-check-dist
cancel-in-progress: true

defaults:
run:
shell: bash

jobs:
check-dist:
runs-on: ubuntu-24.04
Expand All @@ -28,7 +35,7 @@ jobs:
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Set Node.js
uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2.0
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: .nvmrc

Expand All @@ -51,7 +58,7 @@ jobs:
id: diff

# If index.js was different than expected, upload the expected version as an artifact
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ failure() && steps.diff.conclusion == 'failure' }}
with:
name: dist
Expand Down
87 changes: 29 additions & 58 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,79 +1,50 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
push:
branches: [ "main" ]
branches:
- main
pull_request:
# The branches below must be a subset of the branches above
branches: [ "main" ]
branches:
- main
schedule:
- cron: '30 8 * * 1'
- cron: '18 16 * * 3'

concurrency:
group: ${{ github.ref_name }}-codeql
cancel-in-progress: true

permissions:
contents: read

jobs:
analyze:
name: Analyze
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-24.04
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
# Use only 'java' to analyze code written in Java, Kotlin or both
# Use only 'javascript' to analyze code written in JavaScript, TypeScript or both
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
include:
- language: javascript-typescript
build-mode: none

steps:
- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality


# Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun

# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.

# - run: |
# echo "Run, Build Application using script"
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
with:
category: "/language:${{matrix.language}}"
- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@28deaeda66b76a05916b6923827895f2b14ab387 # v3.28.16
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
queries: security-and-quality
config-file: ./.github/codeql-config.yml

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@28deaeda66b76a05916b6923827895f2b14ab387 # v3.28.16
with:
category: "/language:${{matrix.language}}"
Comment on lines +22 to +50
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use F5 approved codeql workflow

    permissions:
      actions: read # for github/codeql-action/init to get workflow details
      contents: read # for actions/checkout to fetch code
      packages: read
      security-events: write # for github/codeql-action/autobuild to send a status report
    uses: nginxinc/compliance-rules/.github/workflows/codeql.yml@a27656f8f9a8748085b434ebe007f5b572709aad # v0.2
    with:
      requested_languages: javascript-typescript

22 changes: 9 additions & 13 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -1,22 +1,18 @@
# Dependency Review Action
#
# This Action will scan dependency manifest files that change as part of a Pull Request,
# surfacing known-vulnerable versions of the packages declared or updated in the PR.
# Once installed, if the workflow run is marked as required,
# PRs introducing known-vulnerable packages will be blocked from merging.
#
# Source repository: https://github.com/actions/dependency-review-action
name: 'Dependency Review'
name: Dependency Review
on: [pull_request]

permissions:
contents: read

jobs:
dependency-review:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
permissions:
contents: read
pull-requests: write
steps:
- name: 'Checkout Repository'
- name: Checkout Repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: 'Dependency Review'
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0

- name: Dependency Review
uses: actions/dependency-review-action@ce3cf9537a52e8119d91fd484ab5b8a807627bf8 # v4.6.0
11 changes: 6 additions & 5 deletions .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: "Pull Request Labeler"
name: Pull Request Labeler
on:
- pull_request_target

Expand All @@ -12,7 +12,8 @@ jobs:
pull-requests: write
runs-on: ubuntu-24.04
steps:
- uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5.0.0
with:
repo-token: "${{ secrets.GITHUB_TOKEN }}"
sync-labels: true
- name: Run Labeler
uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5.0.0
with:
repo-token: "${{ secrets.GITHUB_TOKEN }}"
sync-labels: true
31 changes: 26 additions & 5 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,20 @@
name: 'lint'
name: Lint

on:
pull_request:
branches:
- main
push:
branches:
- main

concurrency:
group: ${{ github.ref_name }}-lint
cancel-in-progress: true

permissions:
contents: read

jobs:
lint:
runs-on: ubuntu-24.04
Expand All @@ -14,7 +23,7 @@ jobs:
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Set Node.js
uses: actions/setup-node@1d0ff469b7ec7b3cb9d8673fde0c81c44821de2a # v4.2.0
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: .nvmrc

Expand Down Expand Up @@ -45,7 +54,8 @@ jobs:
- name: Checkout Repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- uses: reviewdog/action-actionlint@abd537417cf4991e1ba8e21a67b1119f4f53b8e0 # v1.64.1
- name: Lint Actions
uses: reviewdog/action-actionlint@a5524e1c19e62881d79c1f1b9b6f09f16356e281 # v1.65.2
with:
actionlint_flags: -shellcheck ""

Expand All @@ -56,8 +66,19 @@ jobs:
- name: Checkout Repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- uses: DavidAnson/markdownlint-cli2-action@05f32210e84442804257b2a6f20b273450ec8265 # v19.1.0
- name: Lint Markdown
uses: DavidAnson/markdownlint-cli2-action@05f32210e84442804257b2a6f20b273450ec8265 # v19.1.0
with:
config: .markdownlint-cli2.yaml
globs: '**/*.md'
globs: "**/*.md"
fix: false

yaml-lint:
name: YAML lint
runs-on: ubuntu-24.04
steps:
- name: Checkout Repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Lint YAML
uses: reviewdog/action-yamllint@f01d8a48fd8d89f89895499fca2cff09f9e9e8c0 # v1.21.0
11 changes: 6 additions & 5 deletions .github/workflows/renovate-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,7 @@ on:
types: [opened, synchronize]

permissions:
contents: write
pull-requests: read
contents: read

defaults:
run:
Expand All @@ -33,6 +32,9 @@ jobs:
if: ${{ github.actor == 'renovate[bot]' && needs.check.outputs.javascript == 'true' }}
runs-on: ubuntu-24.04
needs: check
permissions:
contents: write
pull-requests: read
steps:
- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
Expand All @@ -41,8 +43,7 @@ jobs:
token: ${{ secrets.COMMIT_PAT }}

- name: Set up Node.js
uses:
actions/setup-node@1e60f620b9541d16bece96c5465dc8ee9832be0b # v4.0.3
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: .nvmrc

Expand All @@ -54,6 +55,6 @@ jobs:

- name: Commit changes
id: commit
uses: stefanzweifel/git-auto-commit-action@e348103e9026cc0eee72ae06630dbe30c8bf7a79 # v5.1.0
uses: stefanzweifel/git-auto-commit-action@b863ae1933cb653a53c021fe36dbb774e1fb9403 # v5.2.0
with:
commit_message: 'Update dist/ after build'
19 changes: 8 additions & 11 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
@@ -1,26 +1,23 @@
# This workflow uses actions that are not certified by GitHub. They are provided
# by a third-party and are governed by separate terms of service, privacy
# policy, and support documentation.

name: Scorecard supply-chain security
name: OpenSSF Scorecard
on:
# For Branch-Protection check. Only the default branch is supported. See
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
branch_protection_rule:
branch_protection_rule: # yamllint disable-line rule:empty-values
# To guarantee Maintained check is occasionally updated. See
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
schedule:
- cron: '20 7 * * 2'
push:
branches: ["main"]
branches:
- main

# Declare default permissions as read only.
permissions: read-all

jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
permissions:
# Needed to upload the results to code-scanning dashboard.
security-events: write
Expand All @@ -36,7 +33,7 @@ jobs:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
uses: ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
with:
results_file: results.sarif
results_format: sarif
Expand All @@ -58,14 +55,14 @@ jobs:
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
uses: github/codeql-action/upload-sarif@28deaeda66b76a05916b6923827895f2b14ab387 # v3.28.16
with:
sarif_file: results.sarif
Loading