Skip to content

Commit e845488

Browse files
chore(deps): bump the dependencies group across 1 directory with 7 updates (eclipse-tractusx#194)
Bumps the dependencies group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [docker/build-push-action](https://github.com/docker/build-push-action) | `3` | `6` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.25.10` | `3.25.11` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.3.0` | `3.4.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.3.3` | `4.3.4` | | [checkmarx/kics-github-action](https://github.com/checkmarx/kics-github-action) | `2.1.0` | `2.1.1` | | [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) | `5.5.2` | `5.5.3` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.22.0` | `0.23.0` | Updates `docker/build-push-action` from 3 to 6 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@v3...v6) Updates `github/codeql-action` from 3.25.10 to 3.25.11 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@23acc5c...b611370) Updates `docker/setup-buildx-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@d70bba7...4fd8129) Updates `actions/upload-artifact` from 4.3.3 to 4.3.4 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6546280...0b2256b) Updates `checkmarx/kics-github-action` from 2.1.0 to 2.1.1 - [Release notes](https://github.com/checkmarx/kics-github-action/releases) - [Commits](Checkmarx/kics-github-action@aacf8e8...252e739) Updates `amannn/action-semantic-pull-request` from 5.5.2 to 5.5.3 - [Release notes](https://github.com/amannn/action-semantic-pull-request/releases) - [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md) - [Commits](amannn/action-semantic-pull-request@cfb6070...0723387) Updates `aquasecurity/trivy-action` from 0.22.0 to 0.23.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@595be6a...7c2007b) --- updated-dependencies: - dependency-name: docker/build-push-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: checkmarx/kics-github-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: amannn/action-semantic-pull-request dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: aquasecurity/trivy-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 6e5abcf commit e845488

14 files changed

+48
-48
lines changed

.github/workflows/chart-test.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ jobs:
6262

6363
- name: Build migration image
6464
id: build-migration-image
65-
uses: docker/build-push-action@v3
65+
uses: docker/build-push-action@v6
6666
with:
6767
context: .
6868
file: ./docker/Dockerfile-credential-issuer-migrations
@@ -71,7 +71,7 @@ jobs:
7171

7272
- name: Build service image
7373
id: build-service-image
74-
uses: docker/build-push-action@v3
74+
uses: docker/build-push-action@v6
7575
with:
7676
context: .
7777
file: ./docker/Dockerfile-credential-issuer-service
@@ -80,7 +80,7 @@ jobs:
8080

8181
- name: Build expiry app
8282
id: build-expiry-app-image
83-
uses: docker/build-push-action@v3
83+
uses: docker/build-push-action@v6
8484
with:
8585
context: .
8686
file: ./docker/Dockerfile-credential-expiry-app
@@ -89,7 +89,7 @@ jobs:
8989

9090
- name: Build processes worker
9191
id: build-processes-worker-image
92-
uses: docker/build-push-action@v3
92+
uses: docker/build-push-action@v6
9393
with:
9494
context: .
9595
file: ./docker/Dockerfile-credential-issuer-processes-worker

.github/workflows/codeql.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ jobs:
7373

7474
# Initializes the CodeQL tools for scanning.
7575
- name: Initialize CodeQL
76-
uses: github/codeql-action/init@23acc5c183826b7a8a97bce3cecc52db901f8251 # v2.227
76+
uses: github/codeql-action/init@b611370bb5703a7efb587f9d136a52ea24c5c38c # v2.227
7777
with:
7878
languages: ${{ matrix.language }}
7979
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -87,7 +87,7 @@ jobs:
8787
# Automates dependency installation for Python, Ruby, and JavaScript, optimizing the CodeQL analysis setup.
8888
# If this step fails, then you should remove it and run the build manually (see below)
8989
- name: Autobuild
90-
uses: github/codeql-action/autobuild@23acc5c183826b7a8a97bce3cecc52db901f8251 # v2.227
90+
uses: github/codeql-action/autobuild@b611370bb5703a7efb587f9d136a52ea24c5c38c # v2.227
9191

9292
# ℹ️ Command-line programs to run using the OS shell.
9393
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
@@ -100,6 +100,6 @@ jobs:
100100
# ./location_of_script_within_repo/buildscript.sh
101101

102102
- name: Perform CodeQL Analysis
103-
uses: github/codeql-action/analyze@23acc5c183826b7a8a97bce3cecc52db901f8251 # v2.227
103+
uses: github/codeql-action/analyze@b611370bb5703a7efb587f9d136a52ea24c5c38c # v2.227
104104
with:
105105
category: "/language:${{matrix.language}}"

.github/workflows/credential-expiry-app-docker.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
password: ${{ secrets.DOCKER_HUB_TOKEN }}
5656

5757
- name: Set up Docker Buildx
58-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
58+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
5959

6060
- name: Docker meta
6161
id: meta
@@ -67,7 +67,7 @@ jobs:
6767
type=raw,value=${{ github.sha }}
6868
6969
- name: Build and push Docker image
70-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
70+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7171
with:
7272
context: .
7373
file: ./docker/Dockerfile-credential-expiry-app

.github/workflows/dependencies.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ jobs:
8787
if: steps.dependencies-changed.outputs.changed == 'true'
8888

8989
- name: Upload DEPENDENCIES file
90-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
90+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
9191
with:
9292
path: DEPENDENCIES
9393
if: steps.dependencies-changed.outputs.changed == 'true'

.github/workflows/kics.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ jobs:
4545
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
4646

4747
- name: KICS scan
48-
uses: checkmarx/kics-github-action@aacf8e81cd48e227259c937c215b352e02ad447a # v2.1.0
48+
uses: checkmarx/kics-github-action@252e73959bd4809a14863cbfbb42d7a90d5a4860 # v2.1.1
4949
with:
5050
# Scanning directory .
5151
path: "."
@@ -69,7 +69,7 @@ jobs:
6969
# Upload findings to GitHub Advanced Security Dashboard
7070
- name: Upload SARIF file for GitHub Advanced Security Dashboard
7171
if: always()
72-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
72+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
7373
with:
7474
sarif_file: kicsResults/results.sarif
7575

.github/workflows/lint-pull-request.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
name: Validate PR title
3232
runs-on: ubuntu-latest
3333
steps:
34-
- uses: amannn/action-semantic-pull-request@cfb60706e18bc85e8aec535e3c577abe8f70378e # v5.5.2
34+
- uses: amannn/action-semantic-pull-request@0723387faaf9b38adef4775cd42cfd5155ed6017 # v5.5.3
3535
id: lint_pr_title
3636
env:
3737
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/migrations-docker.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ jobs:
5656
password: ${{ secrets.DOCKER_HUB_TOKEN }}
5757

5858
- name: Set up Docker Buildx
59-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
59+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
6060

6161
- name: Docker meta
6262
id: meta
@@ -68,7 +68,7 @@ jobs:
6868
type=raw,value=${{ github.sha }}
6969
7070
- name: Build and push Docker image
71-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
71+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7272
with:
7373
context: .
7474
file: ./docker/Dockerfile-credential-issuer-migrations

.github/workflows/owasp-zap.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ jobs:
6262

6363
- name: Build migration image
6464
id: build-migration-image
65-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
65+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
6666
with:
6767
context: .
6868
file: ./docker/Dockerfile-credential-issuer-migrations
@@ -71,7 +71,7 @@ jobs:
7171

7272
- name: Build service image
7373
id: build-service-image
74-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
74+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7575
with:
7676
context: .
7777
file: ./docker/Dockerfile-credential-issuer-service
@@ -80,7 +80,7 @@ jobs:
8080

8181
- name: Build Worker image
8282
id: build-worker-image
83-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
83+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
8484
with:
8585
context: .
8686
file: ./docker/Dockerfile-credential-issuer-processes-worker
@@ -89,7 +89,7 @@ jobs:
8989

9090
- name: Build Expiry image
9191
id: build-expiry-image
92-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
92+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
9393
with:
9494
context: .
9595
file: ./docker/Dockerfile-credential-expiry-app
@@ -144,7 +144,7 @@ jobs:
144144
145145
- name: Upload HTML report
146146
if: success() || failure()
147-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
147+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
148148
with:
149149
name: ZAP scan report
150150
path: ./report_html.html

.github/workflows/processes-worker-docker.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
password: ${{ secrets.DOCKER_HUB_TOKEN }}
5656

5757
- name: Set up Docker Buildx
58-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
58+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
5959

6060
- name: Docker meta
6161
id: meta
@@ -67,7 +67,7 @@ jobs:
6767
type=raw,value=${{ github.sha }}
6868
6969
- name: Build and push Docker image
70-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
70+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7171
with:
7272
context: .
7373
file: ./docker/Dockerfile-credential-issuer-processes-worker

.github/workflows/release.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ jobs:
119119
password: ${{ secrets.DOCKER_HUB_TOKEN }}
120120

121121
- name: Set up Docker Buildx
122-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
122+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
123123

124124
# Create SemVer or ref tags dependent of trigger event
125125
- name: Docker meta
@@ -138,7 +138,7 @@ jobs:
138138
type=semver,pattern={{major}}.{{minor}},value=${{ needs.release-helm-chart.outputs.app-version }}
139139
140140
- name: Build and push Docker images
141-
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
141+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
142142
with:
143143
context: .
144144
file: ${{ matrix.dockerfile }}

.github/workflows/release_candidate.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ jobs:
5959
password: ${{ secrets.DOCKER_HUB_TOKEN }}
6060

6161
- name: Set up Docker Buildx
62-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
62+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
6363

6464
- name: Docker meta
6565
id: meta
@@ -71,7 +71,7 @@ jobs:
7171
type=raw,value=${{ github.sha }}
7272
7373
- name: Build and push Docker images
74-
uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
74+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7575
with:
7676
context: .
7777
file: ${{ matrix.dockerfile }}

.github/workflows/service-docker.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
password: ${{ secrets.DOCKER_HUB_TOKEN }}
5656

5757
- name: Set up Docker Buildx
58-
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
58+
uses: docker/setup-buildx-action@4fd812986e6c8c2a69e18311145f9371337f27d4 # v3.4.0
5959

6060
- name: Docker meta
6161
id: meta
@@ -67,7 +67,7 @@ jobs:
6767
type=raw,value=${{ github.sha }}
6868
6969
- name: Build and push Docker image
70-
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5.1.0
70+
uses: docker/build-push-action@1a162644f9a7e87d8f4b053101d1d9a712edc18c # v6.3.0
7171
with:
7272
context: .
7373
file: ./docker/Dockerfile-credential-issuer-service

.github/workflows/trivy-main.yml

+10-10
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ jobs:
5353
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
5454

5555
- name: Run Trivy vulnerability scanner in repo mode
56-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
56+
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
5757
with:
5858
scan-type: "config"
5959
hide-progress: false
@@ -63,7 +63,7 @@ jobs:
6363
timeout: "3600s"
6464

6565
- name: Upload Trivy scan results to GitHub Security tab
66-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
66+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
6767
if: always()
6868
with:
6969
sarif_file: "trivy-results1.sarif"
@@ -86,7 +86,7 @@ jobs:
8686
# For public images, no ENV vars must be set.
8787
- name: Run Trivy vulnerability scanner
8888
if: always()
89-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
89+
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
9090
with:
9191
# Path to Docker image
9292
image-ref: "${{ env.IMAGE_NAMESPACE }}/ssi-credential-issuer-service:main"
@@ -96,7 +96,7 @@ jobs:
9696

9797
- name: Upload Trivy scan results to GitHub Security tab
9898
if: always()
99-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
99+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
100100
with:
101101
sarif_file: "trivy-results2.sarif"
102102

@@ -118,7 +118,7 @@ jobs:
118118
# For public images, no ENV vars must be set.
119119
- name: Run Trivy vulnerability scanner
120120
if: always()
121-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
121+
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
122122
with:
123123
# Path to Docker image
124124
image-ref: "${{ env.IMAGE_NAMESPACE }}/ssi-credential-issuer-migrations:main"
@@ -129,7 +129,7 @@ jobs:
129129

130130
- name: Upload Trivy scan results to GitHub Security tab
131131
if: always()
132-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
132+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
133133
with:
134134
sarif_file: "trivy-results3.sarif"
135135

@@ -151,7 +151,7 @@ jobs:
151151
# For public images, no ENV vars must be set.
152152
- name: Run Trivy vulnerability scanner
153153
if: always()
154-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
154+
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
155155
with:
156156
# Path to Docker image
157157
image-ref: "${{ env.IMAGE_NAMESPACE }}/ssi-credential-expiry-app:main"
@@ -162,7 +162,7 @@ jobs:
162162

163163
- name: Upload Trivy scan results to GitHub Security tab
164164
if: always()
165-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
165+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
166166
with:
167167
sarif_file: "trivy-results4.sarif"
168168

@@ -184,7 +184,7 @@ jobs:
184184
# For public images, no ENV vars must be set.
185185
- name: Run Trivy vulnerability scanner
186186
if: always()
187-
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
187+
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
188188
with:
189189
# Path to Docker image
190190
image-ref: "${{ env.IMAGE_NAMESPACE }}/ssi-credential-issuer-processes-worker:main"
@@ -195,6 +195,6 @@ jobs:
195195

196196
- name: Upload Trivy scan results to GitHub Security tab
197197
if: always()
198-
uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
198+
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
199199
with:
200200
sarif_file: "trivy-results5.sarif"

0 commit comments

Comments
 (0)