chore(deps): update github actions minor and patch updates #210
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.2
->v4.3.0
v0.20.0
->v0.20.8
v3.4.0
->v3.6.0
v6.3.0
->v6.4.0
v3.8.2
->v3.10.1
v2.7.0
->v2.7.1
v2.12.0
->v2.13.1
Release Notes
actions/checkout (actions/checkout)
v4.3.0
Compare Source
What's Changed
New Contributors
Full Changelog: actions/checkout@v4...v4.3.0
anchore/sbom-action (anchore/sbom-action)
v0.20.8
Compare Source
Changes in v0.20.8
v0.20.7
Compare Source
Changes in v0.20.7
v0.20.6
Compare Source
Changes in v0.20.6
v0.20.5
Compare Source
Changes in v0.20.5
v0.20.4
Compare Source
Changes in v0.20.4
v0.20.3
Compare Source
Changes in v0.20.3
v0.20.2
Compare Source
Changes in v0.20.2
v0.20.1
Compare Source
Changes in v0.20.1
docker/login-action (docker/login-action)
v3.6.0
Compare Source
registry-auth
input for raw authentication to registries by @crazy-max in #887Full Changelog: docker/login-action@v3.5.0...v3.6.0
v3.5.0
Compare Source
Full Changelog: docker/login-action@v3.4.0...v3.5.0
goreleaser/goreleaser-action (goreleaser/goreleaser-action)
v6.4.0
Compare Source
What's Changed
New Contributors
Full Changelog: goreleaser/goreleaser-action@v6.3.0...v6.4.0
sigstore/cosign-installer (sigstore/cosign-installer)
v3.10.1
Compare Source
What's Changed?
Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.
Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.
v3.10.0
Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0
v3.9.2
Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.1...v3.9.2
v3.9.1
Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.0...v3.9.1
v3.9.0
Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3...v3.9.0
slsa-framework/slsa-verifier (slsa-framework/slsa-verifier)
v2.7.1
Compare Source
What's Changed
cc458d7
by @renovate-bot in #838dcc06ee
by @renovate-bot in #839dd5cc4b
by @renovate-bot in #8470a0dc20
by @renovate-bot in #844New Contributors
Full Changelog: slsa-framework/slsa-verifier@v2.7.0...v2.7.1
step-security/harden-runner (step-security/harden-runner)
v2.13.1
Compare Source
What's Changed
Graceful handling of HTTP errors: Improved error handling when fetching Harden Runner policies from the StepSecurity Policy Store API, ensuring more reliable execution even in case of temporary network/API issues.
Security updates for npm dependencies: Updated vulnerable npm package dependencies to the latest secure versions.
Faster enterprise agent downloads: The enterprise agent is now downloaded from GitHub Releases instead of packages.stepsecurity.io, improving download speed and reliability.
Full Changelog: step-security/harden-runner@v2.13.0...v2.13.1
v2.13.0
Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.13.0
v2.12.2
Compare Source
What's Changed
Added HTTPS Monitoring for additional destinations - *.githubusercontent.com
Bug fixes:
Full Changelog: step-security/harden-runner@v2...v2.12.2
v2.12.1
Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2...v2.12.1
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.