build(deps): Bump the actions-deps group with 3 updates - #30
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions-deps group with 3 updates: [actions/setup-java](https://github.com/actions/setup-java), [lfit/gerrit-review-action](https://github.com/lfit/gerrit-review-action) and [lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml](https://github.com/lfreleng-actions/security-workflows). Updates `actions/setup-java` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@dd06d9c...de7274f) Updates `lfit/gerrit-review-action` from 1.1.2 to 1.1.3 - [Release notes](https://github.com/lfit/gerrit-review-action/releases) - [Commits](lfreleng-actions/gerrit-review-action@v1.1.2...1e3eae7) Updates `lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml` from 0.6.0 to 0.7.0 - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@747b06d...bdcf7d8) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: lfit/gerrit-review-action dependency-version: 1.1.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR: #30 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://git.opendaylight.org/gerrit/c/openflowplugin/+/126195 |
Bumps the actions-deps group with 3 updates: [actions/setup-java](https://github.com/actions/setup-java), [lfit/gerrit-review-action](https://github.com/lfit/gerrit-review-action) and [lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml](https://github.com/lfreleng-actions/security-workflows). Updates `actions/setup-java` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@dd06d9c...de7274f) Updates `lfit/gerrit-review-action` from 1.1.2 to 1.1.3 - [Release notes](https://github.com/lfit/gerrit-review-action/releases) - [Commits](lfreleng-actions/gerrit-review-action@v1.1.2...1e3eae7) Updates `lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml` from 0.6.0 to 0.7.0 - [Release notes](https://github.com/lfreleng-actions/security-workflows/releases) - [Commits](lfreleng-actions/security-workflows@747b06d...bdcf7d8) Signed-off-by: dependabot[bot] <support@github.com> Change-Id: I2377f06a22f08eb3d677dbffc44856b86977ce9a GitHub-PR: #30 GitHub-Hash: eee156ce88dd9ed7 Signed-off-by: gh2gerrit <releng+odl-gh2gerrit@linuxfoundation.org>
|
Automated PR Closure This pull request has been automatically closed by GitHub2Gerrit. The corresponding Gerrit change has been accepted and merged ✅ The changes from this PR are now part of the main codebase in Gerrit. This is an automated action performed by the GitHub2Gerrit tool. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the actions-deps group with 3 updates: actions/setup-java, lfit/gerrit-review-action and lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml.
Updates
actions/setup-javafrom 6.0.0 to 6.0.1Release notes
Sourced from actions/setup-java's releases.
Commits
de7274fAvoid macOS GPG socket overflow on long runner paths (#1266)134912aFix import-safe checks when scripts are run from a path with symlinks (#1265)0781fc6Fix alpine failures by switching default back to only warn on verification fa...4889c4aFix Temurin EA E2E signature verification (#1260)8fd3240[WIP] Fix failing GitHub Actions job for temurin 17 (#1259)2732291chore(deps-dev): update eslint and globals (#1256)1a8f22bchore: streamline Dependabot updates (#1255)85030b7docs: complete v6 release highlights (#1254)Updates
lfit/gerrit-review-actionfrom 1.1.2 to 1.1.3Release notes
Sourced from lfit/gerrit-review-action's releases.
Commits
1e3eae7Merge pull request #146 from lfreleng-actions/dependabot/github_actions/step-...cf518f9Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0c0cf518Merge pull request #145 from lfreleng-actions/pre-commit-ci-update-config4ecb804Chore: pre-commit autoupdate9658839Merge pull request #144 from lfreleng-actions/dependabot/github_actions/step-...bd38f6aMerge pull request #143 from lfreleng-actions/dependabot/github_actions/lfit/...ee2e5aeChore: Bump step-security/harden-runner from 2.20.0 to 2.20.1e82f354Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc...364f7f6Merge pull request #142 from lfreleng-actions/pre-commit-ci-update-config31fb5bdMerge pull request #141 from lfreleng-actions/dependabot/github_actions/relea...Updates
lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yamlfrom 0.6.0 to 0.7.0Release notes
Sourced from lfreleng-actions/security-workflows/.github/workflows/sonarqube-cloud.yaml's releases.
Commits
bdcf7d8Merge pull request #89 from modeseven-lfreleng-actions/feat/assert-coverage-f...60fe804Merge pull request #90 from modeseven-lfreleng-actions/feat/go-list-scan-targeta8b7890Merge pull request #98 from lfreleng-actions/dependabot/github_actions/github...039b81aMerge pull request #97 from lfreleng-actions/dependabot/github_actions/github...6fcfcdeMerge pull request #96 from lfreleng-actions/dependabot/github_actions/lfrele...041aa80Merge pull request #95 from lfreleng-actions/dependabot/github_actions/step-s...c4c3891Merge pull request #94 from lfreleng-actions/dependabot/github_actions/github...7bb43b6Merge pull request #93 from lfreleng-actions/dependabot/github_actions/lfrele...7fa374eMerge pull request #92 from lfreleng-actions/dependabot/github_actions/lfrele...60082a1CI(actions): Bump github/codeql-action/analyze from 4.37.8 to 4.37.9Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions