From 72ad835330cfc8e6cf74eefd90e597e0ec88fc47 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Tue, 11 Aug 2026 11:24:39 +0000
Subject: [PATCH] ci: bump the github-actions group with 10 updates (#28021)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps the github-actions group with 10 updates:
| Package | From | To |
| --- | --- | --- |
|
[step-security/harden-runner](https://github.com/step-security/harden-runner)
| `2.20.0` | `2.20.1` |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` |
`7.0.1` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | `6.0.9` |
`6.0.10` |
| [docker/login-action](https://github.com/docker/login-action) |
`4.5.2` | `4.6.0` |
| [actions/setup-java](https://github.com/actions/setup-java) | `5.6.0`
| `5.7.0` |
| [actions/attest](https://github.com/actions/attest) | `4.2.0` |
`4.2.2` |
|
[github/codeql-action/upload-sarif](https://github.com/github/codeql-action)
| `4.37.3` | `4.37.6` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.37.3` | `4.37.6` |
|
[github/codeql-action/analyze](https://github.com/github/codeql-action)
| `4.37.3` | `4.37.6` |
|
[umbrelladocs/action-linkspector](https://github.com/umbrelladocs/action-linkspector)
| `1.5.4` | `1.5.5` |
Updates `step-security/harden-runner` from 2.20.0 to 2.20.1
Release notes
Sourced from step-security/harden-runner's
releases.
v2.20.1
What's Changed
- AWS CodeBuild-hosted runner support
- Implicitly allow single-labeled (internal) domains in
block-mode
Full Changelog: https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1
Commits
b09bb98
Merge pull request #680
from step-security/aws-code-build
35cd77b
docs: document the Global Block List in the features list
bb6dbef
chore: rebuild dist with clean dependency install
98f73c5
chore: update eBPF agent to v1.8.14
54193c1
Reapply "feat(runners): detect AWS CodeBuild-hosted runners as
third-party pr...
d22dd48
Revert "fix(self-hosted): flush agent events at job end when
deploy-on-self-h...
0ff0941
fix(self-hosted): flush agent events at job end when
deploy-on-self-hosted-vm...
a3c333d
Revert "feat(runners): detect AWS CodeBuild-hosted runners as
third-party pro...
bf94c00
feat(runners): detect AWS CodeBuild-hosted runners as third-party
provider
514522c
fix(self-hosted): resolve runner user when USER env var is unset
- See full diff in compare
view
Updates `actions/checkout` from 7.0.0 to 7.0.1
Release notes
Sourced from actions/checkout's
releases.
v7.0.1
What's Changed
Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1
Changelog
Sourced from actions/checkout's
changelog.
Changelog
v7.0.1
v7.0.0
v6.0.3
v6.0.2
v6.0.1
v6.0.0
v5.0.1
v5.0.0
v4.3.1
v4.3.0
v4.2.2
v4.2.1
... (truncated)
Commits
Updates `pnpm/action-setup` from 6.0.9 to 6.0.10
Release notes
Sourced from pnpm/action-setup's
releases.
v6.0.10
What's Changed
New Contributors
Full Changelog: https://github.com/pnpm/action-setup/compare/v6...v6.0.10
Commits
Updates `docker/login-action` from 4.5.2 to 4.6.0
Release notes
Sourced from docker/login-action's
releases.
v4.6.0
Full Changelog: https://github.com/docker/login-action/compare/v4.5.2...v4.6.0
Commits
dbcb813
Merge pull request #1051
from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
5bcb015
[dependabot skip] chore: update generated content
b30b2f2
build(deps): bump the aws-sdk-dependencies group across 1 directory with
2 up...
9087f1e
Merge pull request #1057
from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
0009830
[dependabot skip] chore: update generated content
2325523
build(deps): bump js-yaml from 5.2.1 to 5.2.2
4ec1d4a
Merge pull request #1056
from docker/dependabot/npm_and_yarn/postcss-8.5.22
5fc99ba
Merge pull request #1053
from docker/dependabot/github_actions/aws-actions/co...
e512bd5
Merge pull request #1052
from docker/dependabot/github_actions/codeql-actions...
a146c91
Merge pull request #1059
from crazy-max/harden-buildx-scope-paths
- Additional commits viewable in compare
view
Updates `actions/setup-java` from 5.6.0 to 5.7.0
Release notes
Sourced from actions/setup-java's
releases.
v5.7.0
What's Changed
Full Changelog: https://github.com/actions/setup-java/compare/v5.6.0...v5.7.0
Commits
Updates `actions/attest` from 4.2.0 to 4.2.2
Release notes
Sourced from actions/attest's
releases.
v4.2.2
What's Changed
Full Changelog: https://github.com/actions/attest/compare/v4.2.1...v4.2.2
v4.2.1
What's Changed
Full Changelog: https://github.com/actions/attest/compare/v4.2.0...v4.2.1
Commits
1e69f48
Bump ip-address from 10.2.0 to 10.4.0 (#467)
02787ce
Bump brace-expansion (#468)
98ac037
bump @sigstore/oci from 0.7.1 to 0.7.2 (#469)
508db95
fix: strip OCI image tag when pushing attestation to registry (#464)
dda48f2
Bump the npm-development group across 1 directory with 6 updates (#461)
7d789a3
Bump the actions-minor group with 3 updates (#463)
1f3ca2f
Add release-cutter canvas extension (#454)
d215549
Bump tar from 7.5.17 to 7.5.21 (#459)
20c90ed
Bump the npm-development group with 2 updates (#455)
43c2c81
Bump the actions-minor group with 4 updates (#456)
- Additional commits viewable in compare
view
Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.6
Release notes
Sourced from github/codeql-action/upload-sarif's
releases.
v4.37.6
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
v4.37.5
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
v4.37.4
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
Changelog
Sourced from github/codeql-action/upload-sarif's
changelog.
CodeQL Action Changelog
See the releases
page for the relevant changes to the CodeQL CLI and language
packs.
[UNRELEASED]
No user facing changes.
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-file input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the remote= prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. #4023
- The CodeQL Action can now make use of configured
private registries in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1.
#4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0.
#3995
- In addition to the existing input format, the
config-file input for the codeql-action/init
step will soon support a new [owner/]repo[@ref][:path]
format. All components except the repository name are optional. If
omitted, owner defaults to the same owner as the repository
the analysis is running for, ref to main, and
path to .github/codeql-action.yaml. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. #3973
4.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using
exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6.
#3948
... (truncated)
Commits
5595cca
Merge pull request #4071
from github/update-v4.37.6-6a9359a1b
ec9c757
Add change note for PR 4070
45c8742
Update changelog for v4.37.6
6a9359a
Merge pull request #4070
from github/mbg/remote-address/change-file-default
065cdc0
Change DEFAULT_CONFIG_FILE_NAME
f99dd5a
Merge pull request #4066
from github/dependabot/npm_and_yarn/js-yaml-5.2.2
1804b21
Merge pull request #4068
from github/mergeback/v4.37.5-to-main-d1ba80a1
3020a2f
Rebuild
93c3a5a
Update changelog and version after v4.37.5
d1ba80a
Merge pull request #4067
from github/update-v4.37.5-1cd4d01d5
- Additional commits viewable in compare
view
Updates `github/codeql-action/init` from 4.37.3 to 4.37.6
Release notes
Sourced from github/codeql-action/init's
releases.
v4.37.6
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
v4.37.5
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
v4.37.4
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
Changelog
Sourced from github/codeql-action/init's
changelog.
CodeQL Action Changelog
See the releases
page for the relevant changes to the CodeQL CLI and language
packs.
[UNRELEASED]
No user facing changes.
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-file input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the remote= prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. #4023
- The CodeQL Action can now make use of configured
private registries in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1.
#4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0.
#3995
- In addition to the existing input format, the
config-file input for the codeql-action/init
step will soon support a new [owner/]repo[@ref][:path]
format. All components except the repository name are optional. If
omitted, owner defaults to the same owner as the repository
the analysis is running for, ref to main, and
path to .github/codeql-action.yaml. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. #3973
4.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using
exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6.
#3948
... (truncated)
Commits
5595cca
Merge pull request #4071
from github/update-v4.37.6-6a9359a1b
ec9c757
Add change note for PR 4070
45c8742
Update changelog for v4.37.6
6a9359a
Merge pull request #4070
from github/mbg/remote-address/change-file-default
065cdc0
Change DEFAULT_CONFIG_FILE_NAME
f99dd5a
Merge pull request #4066
from github/dependabot/npm_and_yarn/js-yaml-5.2.2
1804b21
Merge pull request #4068
from github/mergeback/v4.37.5-to-main-d1ba80a1
3020a2f
Rebuild
93c3a5a
Update changelog and version after v4.37.5
d1ba80a
Merge pull request #4067
from github/update-v4.37.5-1cd4d01d5
- Additional commits viewable in compare
view
Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.6
Release notes
Sourced from github/codeql-action/analyze's
releases.
v4.37.6
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
v4.37.5
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
v4.37.4
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
Changelog
Sourced from github/codeql-action/analyze's
changelog.
CodeQL Action Changelog
See the releases
page for the relevant changes to the CodeQL CLI and language
packs.
[UNRELEASED]
No user facing changes.
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.yml to align it with the suggested
path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the
init Action instead
of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
tools input for the codeql-action/init step to
be specified using a github-codeql-tools repository
property. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to toolcache to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for tools in the workflow definition
always takes precedence unless the value of the repository property
starts with !. #4037
- Update default CodeQL bundle version to 2.26.2.
#4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-file input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the remote= prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. #4023
- The CodeQL Action can now make use of configured
private registries in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1.
#4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0.
#3995
- In addition to the existing input format, the
config-file input for the codeql-action/init
step will soon support a new [owner/]repo[@ref][:path]
format. All components except the repository name are optional. If
omitted, owner defaults to the same owner as the repository
the analysis is running for, ref to main, and
path to .github/codeql-action.yaml. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. #3973
4.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using
exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6.
#3948
... (truncated)
Commits
5595cca
Merge pull request #4071
from github/update-v4.37.6-6a9359a1b
ec9c757
Add change note for PR 4070
45c8742
Update changelog for v4.37.6
6a9359a
Merge pull request #4070
from github/mbg/remote-address/change-file-default
065cdc0
Change DEFAULT_CONFIG_FILE_NAME
f99dd5a
Merge pull request #4066
from github/dependabot/npm_and_yarn/js-yaml-5.2.2
1804b21
Merge pull request #4068
from github/mergeback/v4.37.5-to-main-d1ba80a1
3020a2f
Rebuild
93c3a5a
Update changelog and version after v4.37.5
d1ba80a
Merge pull request #4067
from github/update-v4.37.5-1cd4d01d5
- Additional commits viewable in compare
view
Updates `umbrelladocs/action-linkspector` from 1.5.4 to 1.5.5
Release notes
Sourced from umbrelladocs/action-linkspector's
releases.
Release v1.5.5
v1.5.5: PR #70
- Update linkspector version to 0.5.6
Commits
568ec8d
Merge pull request #70
from UmbrellaDocs/update-linkspector-version
6132d93
Update linkspector version to 0.5.6
2f82e25
Merge pull request #68
from sschuberth/patch-1
72f6bee
fix brackets around dpkg
e0946b3
ci(github): Run all tests on Ubuntu 24.04 and 26.04
8b13e46
fix: Extend the AppArmor check to Ubuntu > 24.04
- See full diff in compare
view
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore ` will
remove the ignore condition of the specified dependency and ignore
conditions
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
.github/workflows/audit-docs-paths.yaml | 6 +--
.github/workflows/ci.yaml | 46 ++++++++++-----------
.github/workflows/deploy.yaml | 6 +--
.github/workflows/docker-base.yaml | 4 +-
.github/workflows/dogfood.yaml | 8 ++--
.github/workflows/flake-go.yaml | 2 +-
.github/workflows/nightly-gauntlet.yaml | 2 +-
.github/workflows/pr-auto-assign.yaml | 2 +-
.github/workflows/pr-cherry-pick-check.yaml | 2 +-
.github/workflows/pr-cleanup.yaml | 2 +-
.github/workflows/pr-deploy.yaml | 12 +++---
.github/workflows/release-validation.yaml | 2 +-
.github/workflows/release.yaml | 18 ++++----
.github/workflows/scorecard.yml | 4 +-
.github/workflows/security.yaml | 10 ++---
.github/workflows/stale.yaml | 6 +--
.github/workflows/weekly-docs.yaml | 6 +--
17 files changed, 69 insertions(+), 69 deletions(-)
diff --git a/.github/workflows/audit-docs-paths.yaml b/.github/workflows/audit-docs-paths.yaml
index b7fb5dac8c..268d40705a 100644
--- a/.github/workflows/audit-docs-paths.yaml
+++ b/.github/workflows/audit-docs-paths.yaml
@@ -63,14 +63,14 @@ jobs:
issues: write # open/update/close the tracked issue via GITHUB_TOKEN
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
# coder/coder at the workspace root so the local composite actions
# under ./.github/actions/* resolve normally.
- name: Checkout coder/coder
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
+ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
@@ -80,7 +80,7 @@ jobs:
# ".../coder.com/src/" path segments, which the absolute --roots
# below preserve.
- name: Checkout coder/coder.com
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
+ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ${{ github.repository_owner }}/coder.com
path: coder.com
diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml
index f69937ffae..e323e618e8 100644
--- a/.github/workflows/ci.yaml
+++ b/.github/workflows/ci.yaml
@@ -49,7 +49,7 @@ jobs:
tailnet-integration: ${{ steps.filter.outputs.tailnet-integration }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -141,7 +141,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -311,7 +311,7 @@ jobs:
runs-on: ${{ github.repository_owner == 'coder' && 'depot-ubuntu-22.04-8' || 'ubuntu-latest' }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -401,7 +401,7 @@ jobs:
runs-on: ${{ github.repository_owner == 'coder' && 'depot-ubuntu-24.04-8' || 'ubuntu-24.04' }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -431,7 +431,7 @@ jobs:
if: ${{ !cancelled() }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -486,7 +486,7 @@ jobs:
timeout-minutes: 20
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -537,7 +537,7 @@ jobs:
- windows-2022
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -741,7 +741,7 @@ jobs:
timeout-minutes: 30
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -816,7 +816,7 @@ jobs:
timeout-minutes: 30
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -897,7 +897,7 @@ jobs:
timeout-minutes: 20
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -926,7 +926,7 @@ jobs:
timeout-minutes: 20
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -964,7 +964,7 @@ jobs:
name: ${{ matrix.variant.name }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -1083,7 +1083,7 @@ jobs:
with:
persist-credentials: false
- - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9
+ - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10
name: Install dependencies
with:
run_install: true
@@ -1112,7 +1112,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -1177,7 +1177,7 @@ jobs:
if: always()
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -1216,7 +1216,7 @@ jobs:
runs-on: ${{ github.repository_owner == 'coder' && 'depot-ubuntu-22.04-8' || 'ubuntu-latest' }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -1269,7 +1269,7 @@ jobs:
IMAGE: ghcr.io/coder/coder-preview:${{ steps.build-docker.outputs.tag }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -1280,7 +1280,7 @@ jobs:
persist-credentials: false
- name: GHCR Login
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -1320,7 +1320,7 @@ jobs:
# Necessary for signing Windows binaries.
- name: Setup Java
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0
+ uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
with:
distribution: "zulu"
java-version: "11.0"
@@ -1499,7 +1499,7 @@ jobs:
id: attest_main
if: github.ref == 'refs/heads/main' && steps.docker_digests.outputs.main_digest != ''
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder-preview
subject-digest: ${{ steps.docker_digests.outputs.main_digest }}
@@ -1509,7 +1509,7 @@ jobs:
id: attest_latest
if: github.ref == 'refs/heads/main' && steps.docker_digests.outputs.latest_digest != ''
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder-preview
subject-digest: ${{ steps.docker_digests.outputs.latest_digest }}
@@ -1519,7 +1519,7 @@ jobs:
id: attest_version
if: github.ref == 'refs/heads/main' && steps.docker_digests.outputs.version_digest != ''
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder-preview
subject-digest: ${{ steps.docker_digests.outputs.version_digest }}
@@ -1636,7 +1636,7 @@ jobs:
if: needs.changes.outputs.db == 'true' || needs.changes.outputs.ci == 'true' || github.ref == 'refs/heads/main'
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml
index 7f067a73fd..5323d7978f 100644
--- a/.github/workflows/deploy.yaml
+++ b/.github/workflows/deploy.yaml
@@ -25,7 +25,7 @@ jobs:
verdict: ${{ steps.check.outputs.verdict }} # DEPLOY or NOOP
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -54,7 +54,7 @@ jobs:
packages: write # to retag image as dogfood
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -65,7 +65,7 @@ jobs:
persist-credentials: false
- name: GHCR Login
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
diff --git a/.github/workflows/docker-base.yaml b/.github/workflows/docker-base.yaml
index 964f66eaea..cfe32b33f7 100644
--- a/.github/workflows/docker-base.yaml
+++ b/.github/workflows/docker-base.yaml
@@ -45,7 +45,7 @@ jobs:
if: github.repository_owner == 'coder'
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -55,7 +55,7 @@ jobs:
persist-credentials: false
- name: Docker login
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
diff --git a/.github/workflows/dogfood.yaml b/.github/workflows/dogfood.yaml
index 12a3a5a293..80dca7ce51 100644
--- a/.github/workflows/dogfood.yaml
+++ b/.github/workflows/dogfood.yaml
@@ -70,7 +70,7 @@ jobs:
MISE_EXPERIMENTAL: "1"
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -126,7 +126,7 @@ jobs:
# ghcr.io. Skip the entire GHCR-dependent pipeline (base push +
# mise oci build) for fork PRs.
if: ${{ !github.event.pull_request.head.repo.fork }}
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -134,7 +134,7 @@ jobs:
- name: Login to DockerHub
if: github.ref == 'refs/heads/main'
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_PASSWORD }}
@@ -258,7 +258,7 @@ jobs:
id-token: write
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/flake-go.yaml b/.github/workflows/flake-go.yaml
index 41b2cefa58..8a368111e5 100644
--- a/.github/workflows/flake-go.yaml
+++ b/.github/workflows/flake-go.yaml
@@ -30,7 +30,7 @@ jobs:
timeout-minutes: 30
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/nightly-gauntlet.yaml b/.github/workflows/nightly-gauntlet.yaml
index 55a8774581..0fd61bb9a2 100644
--- a/.github/workflows/nightly-gauntlet.yaml
+++ b/.github/workflows/nightly-gauntlet.yaml
@@ -28,7 +28,7 @@ jobs:
- windows-2022
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr-auto-assign.yaml b/.github/workflows/pr-auto-assign.yaml
index a910bc9600..91f7f7b936 100644
--- a/.github/workflows/pr-auto-assign.yaml
+++ b/.github/workflows/pr-auto-assign.yaml
@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr-cherry-pick-check.yaml b/.github/workflows/pr-cherry-pick-check.yaml
index dedc730d8a..ad24e33483 100644
--- a/.github/workflows/pr-cherry-pick-check.yaml
+++ b/.github/workflows/pr-cherry-pick-check.yaml
@@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr-cleanup.yaml b/.github/workflows/pr-cleanup.yaml
index a6a48c4a2a..0b90bf685c 100644
--- a/.github/workflows/pr-cleanup.yaml
+++ b/.github/workflows/pr-cleanup.yaml
@@ -19,7 +19,7 @@ jobs:
packages: write
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr-deploy.yaml b/.github/workflows/pr-deploy.yaml
index dbd6872bfd..be48fb30fd 100644
--- a/.github/workflows/pr-deploy.yaml
+++ b/.github/workflows/pr-deploy.yaml
@@ -39,7 +39,7 @@ jobs:
PR_OPEN: ${{ steps.check_pr.outputs.pr_open }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -76,7 +76,7 @@ jobs:
runs-on: "ubuntu-latest"
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -184,7 +184,7 @@ jobs:
pull-requests: write # needed for commenting on PRs
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -228,7 +228,7 @@ jobs:
CODER_IMAGE_TAG: ${{ needs.get_info.outputs.CODER_IMAGE_TAG }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -250,7 +250,7 @@ jobs:
run: ./.github/scripts/retry.sh -- mise install --locked go:github.com/coder/sqlc/cmd/sqlc
- name: GHCR Login
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -290,7 +290,7 @@ jobs:
PR_HOSTNAME: "pr${{ needs.get_info.outputs.PR_NUMBER }}.${{ secrets.PR_DEPLOYMENTS_DOMAIN }}"
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/release-validation.yaml b/.github/workflows/release-validation.yaml
index fe4a309f26..b668a0c21d 100644
--- a/.github/workflows/release-validation.yaml
+++ b/.github/workflows/release-validation.yaml
@@ -14,7 +14,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml
index 297ac1cbeb..5f6a97ad5b 100644
--- a/.github/workflows/release.yaml
+++ b/.github/workflows/release.yaml
@@ -81,7 +81,7 @@ jobs:
version: ${{ steps.version.outputs.version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -166,7 +166,7 @@ jobs:
cat "$CODER_RELEASE_NOTES_FILE"
- name: Docker Login
- uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -185,7 +185,7 @@ jobs:
# Necessary for signing Windows binaries.
- name: Setup Java
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0
+ uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
with:
distribution: "zulu"
java-version: "11.0"
@@ -353,7 +353,7 @@ jobs:
id: attest_base
if: ${{ !inputs.dry_run && steps.build_base_image.outputs.digest != '' }}
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder-base
subject-digest: ${{ steps.build_base_image.outputs.digest }}
@@ -460,7 +460,7 @@ jobs:
id: attest_main
if: ${{ !inputs.dry_run && steps.docker_digests.outputs.multiarch_digest != '' }}
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder
subject-digest: ${{ steps.docker_digests.outputs.multiarch_digest }}
@@ -470,7 +470,7 @@ jobs:
id: attest_latest
if: ${{ !inputs.dry_run && steps.docker_digests.outputs.latest_digest != '' }}
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ghcr.io/coder/coder
subject-digest: ${{ steps.docker_digests.outputs.latest_digest }}
@@ -480,7 +480,7 @@ jobs:
id: attest_binaries
if: ${{ !inputs.dry_run }}
continue-on-error: true
- uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
+ uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: |
./build/*.tar.gz
@@ -683,7 +683,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -759,7 +759,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 125efbad54..b151cb8b15 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -20,7 +20,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -47,6 +47,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
- uses: github/codeql-action/upload-sarif@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3.29.5
+ uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v3.29.5
with:
sarif_file: results.sarif
diff --git a/.github/workflows/security.yaml b/.github/workflows/security.yaml
index d493345f69..969d058013 100644
--- a/.github/workflows/security.yaml
+++ b/.github/workflows/security.yaml
@@ -27,7 +27,7 @@ jobs:
runs-on: ${{ github.repository_owner == 'coder' && 'depot-ubuntu-22.04-8' || 'ubuntu-latest' }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -42,7 +42,7 @@ jobs:
install-args: "go"
- name: Initialize CodeQL
- uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3.29.5
+ uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v3.29.5
with:
languages: go, javascript
@@ -52,7 +52,7 @@ jobs:
rm Makefile
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3.29.5
+ uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v3.29.5
- name: Send Slack notification on failure
if: ${{ failure() }}
@@ -74,7 +74,7 @@ jobs:
OSV_SCANNER_VERSION: v2.3.5
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -114,7 +114,7 @@ jobs:
- name: Upload OSV-Scanner scan results to GitHub Security tab
if: ${{ always() && hashFiles('osv-results.sarif') != '' }}
- uses: github/codeql-action/upload-sarif@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3.29.5
+ uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v3.29.5
with:
sarif_file: osv-results.sarif
category: "OSV-Scanner"
diff --git a/.github/workflows/stale.yaml b/.github/workflows/stale.yaml
index 9051a7e42a..37684da7d7 100644
--- a/.github/workflows/stale.yaml
+++ b/.github/workflows/stale.yaml
@@ -18,7 +18,7 @@ jobs:
pull-requests: write
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -96,7 +96,7 @@ jobs:
contents: write
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -120,7 +120,7 @@ jobs:
actions: write
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
diff --git a/.github/workflows/weekly-docs.yaml b/.github/workflows/weekly-docs.yaml
index 58d1d4c4b2..eaab58737f 100644
--- a/.github/workflows/weekly-docs.yaml
+++ b/.github/workflows/weekly-docs.yaml
@@ -26,7 +26,7 @@ jobs:
chrome-path: ${{ steps.install-chrome.outputs.path }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -68,7 +68,7 @@ jobs:
pull-requests: write # required to post PR review comments by the action
steps:
- name: Harden Runner
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
+ uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
@@ -108,7 +108,7 @@ jobs:
key: ${{ needs.prepare-linkspector-browser.outputs.browser-cache-key }}
- name: Check Markdown links
- uses: umbrelladocs/action-linkspector@6c637d70424624231467a4ca918be54fa3b792d0 # v1.5.4
+ uses: umbrelladocs/action-linkspector@568ec8d29fa92b31fd9ea5381e155c51e922af83 # v1.5.5
id: markdown-link-check
# checks all markdown files from /docs including all subfolders
env: