-
Notifications
You must be signed in to change notification settings - Fork 2
chore(deps): update all non-major dependencies #206
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
✅MegaLinter analysis: Success
See detailed reports in MegaLinter artifacts Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining
|
39e4f16 to
1e70166
Compare
a8953c8 to
aa76830
Compare
9a1511a to
df55ff7
Compare
571809d to
9d45ca8
Compare
77486a4 to
16e27ea
Compare
c3135ec to
72a063c
Compare
23c6a05 to
934dc3a
Compare
934dc3a to
1d09661
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Trivy image scan report
|
Trivy image scan report
|
Trivy image scan report
|
|
🎉 This PR is included in version 1.11.10 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |

This PR contains the following updates:
v2.1.4->v2.2.1v4.8.1->v4.8.2v5.0.0->v5.0.1v5.0.0->v5.1.0v6.0.0->v6.1.00.67.2->0.68.1v7.1.1->v7.1.63.14.0-slim->3.14.2-slimv5.8.0->v5.10.0v3.6.0->v3.7.0v4.30.9->v4.31.8v9.1.0->v9.2.0v2.4.1->v2.5.0v2.13.1->v2.14.01.15.2->1.18.0Release Notes
actions/create-github-app-token (actions/create-github-app-token)
v2.2.1Compare Source
Bug Fixes
v2.2.0Compare Source
Bug Fixes
Features
actions/dependency-review-action (actions/dependency-review-action)
v4.8.2Compare Source
Minor fixes:
actions/setup-dotnet (actions/setup-dotnet)
v5.0.1Compare Source
What's Changed
Full Changelog: actions/setup-dotnet@v5...v5.0.1
actions/setup-java (actions/setup-java)
v5.1.0Compare Source
What's Changed
New Features
.sdkmanrcfile injava-version-fileparameter by @guicamest in #736Bug Fixes & Improvements
Documentation changes
Dependency updates
New Contributors
Full Changelog: actions/setup-java@v5...v5.1.0
actions/setup-node (actions/setup-node)
v6.1.0Compare Source
What's Changed
Enhancement:
Dependency updates:
Documentation update:
Full Changelog: actions/setup-node@v6...v6.1.0
aquasecurity/trivy (aquasecurity/trivy)
v0.68.1Compare Source
👉 Trivy v0.68.1 release notes (click here)
⬇️ Download Trivy
🐳 Docker Install
docker pull get.trivy.dev/image/trivy:0.68.1Changelog
https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0680-2025-12-02
astral-sh/setup-uv (astral-sh/setup-uv)
v7.1.6Compare Source
v7.1.5: 🌈 allow settingcache-local-pathwithoutenable-cache: trueCompare Source
Changes
#612 fixed a faulty behavior where this action set
UV_CACHE_DIReven thoughenable-cachewasfalse. It also fixed the cases were the cache dir is already configured in a settings file likepyproject.tomlorUV_CACHE_DIRwas already set. Here the action shouldn't overwrite or setUV_CACHE_DIR.These fixes introduced an unwanted behavior: You can still set
cache-local-pathbut this action didn't do anything. This release fixes that.You can now use
cache-local-pathto automatically setUV_CACHE_DIReven whenenable-cacheisfalse(or gets set to false by default e.g. on self-hosted runners)🐛 Bug fixes
🧰 Maintenance
npm ci --ignore-scriptseverywhere @woodruffw (#699)⬆️ Dependency updates
v7.1.4: 🌈 Fix libuv closing bug on WindowsCompare Source
Changes
This release fixes the bug
Assertion failed: !(handle->flags & UV_HANDLE_CLOSING)on Windows runners🐛 Bug fixes
🧰 Maintenance
v7.1.3: 🌈 Support actCompare Source
Changes
This bug fix release adds support for https://github.com/nektos/act
It was previously broken because of a too new
undiciversion and TS transpilation target.Compatibility with act is now automatically tested.
🐛 Bug fixes
🧰 Maintenance
📚 Documentation
cache-dependency-glob@allanlewis (#676)v7.1.2: 🌈 Speed up extraction on WindowsCompare Source
Changes
@lazka fixed a bug that caused extracting uv to take up to 30s. Thank you!
🐛 Bug fixes
🧰 Maintenance
⬆️ Dependency updates
docker/metadata-action (docker/metadata-action)
v5.10.0Compare Source
Full Changelog: docker/metadata-action@v5.9.0...v5.10.0
v5.9.0Compare Source
tag-namesoutput to return tag names without image base name by @crazy-max in #553Full Changelog: docker/metadata-action@v5.8.0...v5.9.0
docker/setup-qemu-action (docker/setup-qemu-action)
v3.7.0Compare Source
Full Changelog: docker/setup-qemu-action@v3.6.0...v3.7.0
github/codeql-action (github/codeql-action)
v4.31.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.8 - 11 Dec 2025
See the full CHANGELOG.md for more information.
v4.31.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.7 - 05 Dec 2025
See the full CHANGELOG.md for more information.
v4.31.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.6 - 01 Dec 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v4.31.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.5 - 24 Nov 2025
See the full CHANGELOG.md for more information.
v4.31.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.4 - 18 Nov 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v4.31.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.3 - 13 Nov 2025
See the full CHANGELOG.md for more information.
v4.31.2Compare Source
v4.31.1Compare Source
v4.31.0Compare Source
oxsecurity/megalinter (oxsecurity/megalinter)
v9.2.0Compare Source
New linters
Disabled linters
Deprecated linters
SALESFORCE_SFDX_SCANNER_*linters have been deprecated and will be removed in a future version. (they are replaced bySALESFORCE_CODE_ANALYZER_*linters)Media
Linters enhancements
Fixes
Reporters
Doc
build.py --doc, by @echoix in #6447Flavors
CI
mega-linter-runner
Linter versions upgrades (53)
softprops/action-gh-release (softprops/action-gh-release)
v2.5.0Compare Source
What's Changed
Exciting New Features 🎉
Other Changes 🔄
New Contributors
Full Changelog: softprops/action-gh-release@v2.4.2...v2.5.0
v2.4.2Compare Source
What's Changed
Exciting New Features 🎉
Other Changes 🔄
New Contributors
Full Changelog: softprops/action-gh-release@v2.4.1...v2.4.2
step-security/harden-runner (step-security/harden-runner)
v2.14.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.3...v2.14.0
v2.13.3Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.2...v2.13.3
v2.13.2Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.13.1...v2.13.2
zizmorcore/zizmor (zizmor)
v1.18.0Compare Source
Enhancements 🌱🔗
The use-trusted-publishing audit now detects NuGet publishing commands (#1369)
The dependabot-cooldown audit now flags cooldown periods of less than 7 days by default (#1375)
The dependabot-cooldown audit can now be configured with a custom minimum cooldown period via rules.dependabot-cooldown.config.days (#1377)
zizmor now produces slightly more useful error messages when the user supplies an invalid configuration for the forbidden-uses audit (#1381)
Bug Fixes 🐛🔗
v1.17.0Compare Source
Enhancements 🌱🔗
zizmor now produces a more useful error message when asked to collect only workflows from a remote input that contains no workflows (#1324)
zizmor now produces more precise severities on actions/checkout versions that have more misuse-resistant credentials persistence behavior (#1353)
Many thanks to @ManuelLerchnerQC for proposing and implementing this improvement!
The use-trusted-publishing audit now correctly detecting more "dry-run" patterns, making it significantly more accurate (#1357)
The obfuscation audit now detects usages of shell: cmd and similar, as the Windows CMD shell lacks a formal grammar and limits analysis of run: blocks in other audits (#1361)
Performance Improvements 🚄🔗
Bug Fixes 🐛🔗
Fixed a bug where auto-fixes would fail to preserve a document's final newline (#1323)
zizmor now uses the native (OS) TLS roots when performing HTTPS requests, improving compatibility with user environments that perform TLS interception (#1328)
The github-env audit now falls back to assuming bash-like shell syntax in run: blocks if it can't infer the shell being used (#1336)
The concurrency-limits audit now correctly detects job-level concurrency settings, in addition to workflow-level settings (#1338)
Fixed a bug where zizmor would fail to collect workflows with names that overlapped with other input types (e.g. action.yml and dependabot.yml) when passed explicitly by path (#1345)
v1.16.3Compare Source
Bug Fixes 🐛🔗
v1.16.2Compare Source
Enhancements 🌱🔗
Bug Fixes 🐛🔗
v1.16.1Compare Source
Enhancements 🌱🔗
v1.16.0Compare Source
New Features 🌈🔗
New audit: concurrency-limits detects insufficient concurrency limits in workflows (#1227)
Many thanks to @jwallwork23 for proposing and implementing this audit!
Performance Improvements 🚄🔗
zizmor's online mode is now significantly (40% to over 95%) faster on common workloads, thanks to a combination of caching improvements and conversion of GitHub API requests into Git remote lookups (#1257)
Many thanks to @Bo98 for implementing these improvements!
Enhancements 🌱🔗
When running in --fix mode and all fixes are successfully applied, zizmor now has similar exit code behavior as the --no-exit-codes and --format=sarif flags (#1242)
Many thanks to @cnaples79 for implementing this improvement!
The dependabot-cooldown audit now supports auto-fixes for many findings (#1229)
Many thanks to @mostafa for implementing this improvement!
The dependabot-execution audit now supports auto-fixes for many findings (#1229)
Many thanks to @mostafa for implementing this improvement!
zizmor now has limited, experimental support for handling inputs that contain YAML anchors (#1266)
Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.