chore(deps): bump the github-actions group with 15 updates#337
Merged
Nick2bad4u merged 1 commit intomainfrom Mar 3, 2026
Merged
Conversation
Bumps the github-actions group with 15 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.1` | `2.15.0` | | [devops-actions/actionlint](https://github.com/devops-actions/actionlint) | `0.1.10` | `0.1.11` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.0` | `4.32.4` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.2` | `4.8.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6.0.0` | `7.0.0` | | [nick2bad4u/generate-repo-file-list](https://github.com/nick2bad4u/generate-repo-file-list) | `f1342075abdb94a6134398776eafce7931fd1444` | `07b49868e86da4ee6121ea33b3f2beabd87bb87f` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `9.3.0` | `9.4.0` | | [oke-py/npm-audit-action](https://github.com/oke-py/npm-audit-action) | `3.0.0` | `4.0.1` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.3.2` | `2.3.3` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `2.3.2` | `2.3.3` | | [actions/stale](https://github.com/actions/stale) | `10.1.1` | `10.2.0` | | [actions/ai-inference](https://github.com/actions/ai-inference) | `2.0.5` | `2.0.7` | | [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.4.0` | `8.5.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.92.5` | `3.93.6` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.42.3` | `1.44.0` | Updates `step-security/harden-runner` from 2.14.1 to 2.15.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@e3f713f...a90bcbc) Updates `devops-actions/actionlint` from 0.1.10 to 0.1.11 - [Release notes](https://github.com/devops-actions/actionlint/releases) - [Commits](devops-actions/actionlint@467e2ce...469810f) Updates `github/codeql-action` from 4.32.0 to 4.32.4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b20883b...89a39a4) Updates `actions/dependency-review-action` from 4.8.2 to 4.8.3 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@3c4e3dc...05fe457) Updates `actions/upload-artifact` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@b7c566a...bbbca2d) Updates `nick2bad4u/generate-repo-file-list` from f1342075abdb94a6134398776eafce7931fd1444 to 07b49868e86da4ee6121ea33b3f2beabd87bb87f - [Release notes](https://github.com/nick2bad4u/generate-repo-file-list/releases) - [Commits](Nick2bad4u/Generate-Repo-File-List@f134207...07b4986) Updates `oxsecurity/megalinter` from 9.3.0 to 9.4.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@42bb470...8fbdead) Updates `oke-py/npm-audit-action` from 3.0.0 to 4.0.1 - [Release notes](https://github.com/oke-py/npm-audit-action/releases) - [Commits](oke-py/npm-audit-action@6ec7878...f02a3cf) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.3.2 to 2.3.3 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@2a387ed...c5996e0) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.3.2 to 2.3.3 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@2a387ed...c5996e0) Updates `actions/stale` from 10.1.1 to 10.2.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@9971854...b5d41d4) Updates `actions/ai-inference` from 2.0.5 to 2.0.7 - [Release notes](https://github.com/actions/ai-inference/releases) - [Commits](actions/ai-inference@a6101c8...e09e659) Updates `super-linter/super-linter` from 8.4.0 to 8.5.0 - [Release notes](https://github.com/super-linter/super-linter/releases) - [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md) - [Commits](super-linter/super-linter@12562e4...61abc07) Updates `trufflesecurity/trufflehog` from 3.92.5 to 3.93.6 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@116e717...041f07e) Updates `crate-ci/typos` from 1.42.3 to 1.44.0 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@06d010d...631208b) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: devops-actions/actionlint dependency-version: 0.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.32.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.8.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: nick2bad4u/generate-repo-file-list dependency-version: 07b49868e86da4ee6121ea33b3f2beabd87bb87f dependency-type: direct:production dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-version: 9.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: oke-py/npm-audit-action dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: 2.3.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: 2.3.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/stale dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/ai-inference dependency-version: 2.0.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: super-linter/super-linter dependency-version: 8.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.93.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: crate-ci/typos dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Owner
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the github-actions group with 15 updates:
2.14.12.15.00.1.100.1.114.32.04.32.44.8.24.8.36.0.07.0.0f1342075abdb94a6134398776eafce7931fd144407b49868e86da4ee6121ea33b3f2beabd87bb87f9.3.09.4.03.0.04.0.12.3.22.3.32.3.22.3.310.1.110.2.02.0.52.0.78.4.08.5.03.92.53.93.61.42.31.44.0Updates
step-security/harden-runnerfrom 2.14.1 to 2.15.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
a90bcbcUpdate readme (#637)f0a59d8Release v2.15.0 (#639)5ef0c07Merge pull request #635 from step-security/rc-34eb43c7bupdate agentUpdates
devops-actions/actionlintfrom 0.1.10 to 0.1.11Release notes
Sourced from devops-actions/actionlint's releases.
Commits
469810fUpdate actionlint version to 1.7.11 (#161)16325c3Fix update-actionlint workflow failing on repeated runs (#160)1911209Merge pull request #159 from devops-actions/dependabot/github_actions/jesseho...0a8db88Bump jessehouwing/actions-semver-checker from 2.0.3 to 2.0.4be93a3dBump step-security/harden-runner from 2.14.1 to 2.14.2 (#157)7e2800dMerge pull request #156 from devops-actions/dependabot/github_actions/jesseho...4cb1ad0Bump jessehouwing/actions-semver-checker from 1.0.9 to 2.0.3191d0bcBump step-security/harden-runner from 2.14.0 to 2.14.1 (#154)9b61223Merge pull request #155 from devops-actions/dependabot/github_actions/jesseho...6154f0aBump jessehouwing/actions-semver-checker from 1.0.8 to 1.0.9Updates
github/codeql-actionfrom 4.32.0 to 4.32.4Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
89a39a4Merge pull request #3494 from github/update-v4.32.4-39ba80c47e5d84c8Apply remaining review suggestions0c20209Apply suggestions from code review314172eFix typocdda72dAdd changelog entriescfda84cUpdate changelog for v4.32.439ba80cMerge pull request #3493 from github/update-bundle/codeql-bundle-v2.24.200150daAdd changelog noted97dce6Update default bundle to codeql-bundle-v2.24.250fdbb9Merge pull request #3492 from github/henrymercer/new-repository-properties-ffUpdates
actions/dependency-review-actionfrom 4.8.2 to 4.8.3Release notes
Sourced from actions/dependency-review-action's releases.
Commits
05fe457Merge pull request #1054 from actions/ahpook/release-4.8.33a8496cUpdate generated package files for v4.8.30f22a01Update CONTRIBUTING for new release process58be343Updating package versions for 4.8.39284e0cMerge pull request #931 from actions/dependabot/npm_and_yarn/spdx-licenses-20...8b76656Bump spdx-expression-parse in the spdx-licenses group across 1 directory43f5f02Merge pull request #1052 from actions/juxtin/fix-long-summariesf0033fcMerge pull request #1053 from actions/dependabot/npm_and_yarn/fast-xml-parser...b379e2eBump fast-xml-parser from 5.3.5 to 5.3.62e1cf54Properly truncate long summaries and catch errorsUpdates
actions/upload-artifactfrom 6.0.0 to 7.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testUpdates
nick2bad4u/generate-repo-file-listfrom f1342075abdb94a6134398776eafce7931fd1444 to 07b49868e86da4ee6121ea33b3f2beabd87bb87fCommits
07b4986Merge PR #407633960Merge PR #416f00b75Bump the github-actions group with 6 updates0fa4e2bBump tqdm from 4.67.1 to 4.67.2 in the github-actions groupUpdates
oxsecurity/megalinterfrom 9.3.0 to 9.4.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
8fbdeadRelease MegaLinter v9.4.09f605c4Fix custom flavor builder workflow (#7306)b7dcb60Update changelog to prepare release (#7304)3077b04chore(deps): update dependency regex to v2026.2.28 (#7303)edba876[automation] Auto-update linters version, help and documentation (#7299)07fb84dchore(deps): update dependency python-gitlab to v8.1.0 (#7302)4d42e33chore(deps): update dependency fastapi to v0.134.0 (#7301)649726cchore(deps): update dependency rumdl to v0.1.32 (#7300)768b5a3chore(deps): update dependency virtualenv to v21.1.0 (#7298)7e73a76chore(deps): update dependency eslint-plugin-jsonc to v3 (#7260)Updates
oke-py/npm-audit-actionfrom 3.0.0 to 4.0.1Release notes
Sourced from oke-py/npm-audit-action's releases.
Commits
f02a3cfMerge pull request #318 from oke-py/chore/release-flowec06595docs: unify release process3caf7bbchore(release): drop PR label bump and set v4.0.1c121642Merge pull request #317 from oke-py/chore/husky-biome69ef773fix(deps): dedupe husky and lint-staged11ac110chore: add husky hooks for biome and testsb74e8bechore: update dist [skip ci]7ed8760Merge pull request #316 from oke-py/chore/issue-handler34b44fdrefactor(issue): extract issue handlingf5aee93chore: update dist [skip ci]Updates
google/osv-scanner-action/.github/workflows/osv-scanner-reusable.ymlfrom 2.3.2 to 2.3.3Release notes
Sourced from google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml's releases.
Commits
c5996e0Merge pull request #118 from google/update-to-v2.3.3f4fac92Update unified workflow example to point to v2.3.3 reusable workflows8ae4be8Update reusable workflows to point to v2.3.3 actions8018483"Update actions to use v2.3.3 osv-scanner image"2c222dbMerge pull request #115 from renovate-bot/renovate/workflows115472dchore(deps): update github/codeql-action action to v4.31.10Updates
google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.ymlfrom 2.3.2 to 2.3.3Release notes
Sourced from google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml's releases.
Commits
c5996e0Merge pull request #118 from google/update-to-v2.3.3f4fac92Update unified workflow example to point to v2.3.3 reusable workflows8ae4be8Update reusable workflows to point to v2.3.3 actions8018483"Update actions to use v2.3.3 osv-scanner image"2c222dbMerge pull request #115 from renovate-bot/renovate/workflows115472dchore(deps): update github/codeql-action action to v4.31.10Updates
actions/stalefrom 10.1.1 to 10.2.0Release notes
Sourced from actions/stale's releases.
Commits
b5d41d4build(deps-dev): bump lodash from 4.17.21 to 4.17.23 (#1313)dcd2b94Fix punycode and url.parse Deprecation Warnings (#1312)d6f8a33build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (#1304)a21a081Fix checking state cache (fix #1136), also switch to octokit methods (#1152)Updates
actions/ai-inferencefrom 2.0.5 to 2.0.7Release notes
Sourced from actions/ai-inference's releases.
Commits
e09e659Merge pull request #173 from GitPaulo/maine608d2bupdate dist27965bcupdated docs for missing prompt.yml model parametersa8bddadupdate dist