Skip to content

Dependency Dashboard #35

Description

@williaby

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Config Migration Needed

  • Select this checkbox to let Renovate create an automated Config Migration PR.

Repository Problems

Renovate tried to run on this repository, but found these problems.

  • ⚠️ WARN: Package lookup failures

Warning

Renovate failed to look up the following dependencies: Can't find version with tag v1 for github-digest package ByronWilliamsCPA/.github, Failed to look up github-digest package {{ cookiecutter.github_org_or_user }}/.github: no-result.

Files affected: .github/workflows/qlty.yml, .github/workflows/sbom.yml, .github/workflows/scorecard.yml, .github/workflows/security-analysis.yml, {{cookiecutter.project_slug}}/.github/workflows/ci.yml, {{cookiecutter.project_slug}}/.github/workflows/codecov.yml, {{cookiecutter.project_slug}}/.github/workflows/container-security.yml, {{cookiecutter.project_slug}}/.github/workflows/docs.yml, {{cookiecutter.project_slug}}/.github/workflows/mutation-testing.yml, {{cookiecutter.project_slug}}/.github/workflows/pr-validation.yml, {{cookiecutter.project_slug}}/.github/workflows/publish-pypi.yml, {{cookiecutter.project_slug}}/.github/workflows/python-compatibility.yml, {{cookiecutter.project_slug}}/.github/workflows/qlty.yml, {{cookiecutter.project_slug}}/.github/workflows/release.yml, {{cookiecutter.project_slug}}/.github/workflows/sbom.yml, {{cookiecutter.project_slug}}/.github/workflows/scorecard.yml, {{cookiecutter.project_slug}}/.github/workflows/security-analysis.yml, {{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml, {{cookiecutter.project_slug}}/.github/workflows/sonarcloud.yml


Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

  • chore(deps): Update GitHub Actions (actions/attest-build-provenance, actions/checkout, actions/setup-node, astral-sh/setup-uv, github/codeql-action, lycheeverse/lychee-action, ossf/scorecard-action, pypa/gh-action-pypi-publish, python-semantic-release/python-semantic-release, release-drafter/release-drafter, softprops/action-gh-release, step-security/harden-runner)
  • chore(deps)!: Update GitHub Actions (major) (actions/setup-node, actions/setup-python, astral-sh/setup-uv)
  • chore(deps): Update
  • Click on this checkbox to rebase all open PRs at once

Detected Dependencies

github-actions (34)
.github/workflows/ci.yml (15)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • python ${{ env.PYTHON_VERSION }}
  • python ${{ env.PYTHON_VERSION }}
  • python ${{ env.PYTHON_VERSION }}
.github/workflows/codeql.yml (7)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • github/codeql-action v4.36.2@8aad20d150bbac5944a9f9d289da16a4b0d87c1e → [Updates: v4.37.4]
  • github/codeql-action v4.36.2@8aad20d150bbac5944a9f9d289da16a4b0d87c1e → [Updates: v4.37.4]
  • python 3.12
.github/workflows/cruft-update.yml (9)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • actions/github-script v9.0.0@3a2844b7e9c422d3c10d287c895573f7108da1b3
.github/workflows/dependency-review.yml (3)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/dependency-review-action v5.0.0@a1d282b36b6f3519aa1f3fc636f609c47dddb294
.github/workflows/pr-validation.yml (4)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
.github/workflows/qlty.yml (1)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
.github/workflows/release-drafter.yml (2)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • release-drafter/release-drafter v7.4.0@ed4bc48ec97379be2258e7b7ac2624a3e26ab809 → [Updates: v7.7.0]
.github/workflows/reuse.yml (6)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • fsfe/reuse-action v6.0.0@676e2d560c9a403aa252096d99fcab3e1132b0f5
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
.github/workflows/sbom.yml (1)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
.github/workflows/scheduled-validation.yml (16)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/github-script v9.0.0@3a2844b7e9c422d3c10d287c895573f7108da1b3
  • actions/github-script v9.0.0@3a2844b7e9c422d3c10d287c895573f7108da1b3
  • python ${{ matrix.python-version }}
  • python ${{ env.PYTHON_VERSION }}
  • python ${{ env.PYTHON_VERSION }}
.github/workflows/scorecard.yml (1)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
.github/workflows/security-analysis.yml (2)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
.github/workflows/test-template.yml (31)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • python 3.12
  • python ${{ matrix.python-version }}
  • python 3.12
  • python 3.12
  • python 3.12
  • python 3.12
.github/workflows/validate-template.yml (4)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • python ${{ matrix.python-version }}
{{cookiecutter.project_slug}}/.github/workflows/ci.yml (14)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • Infisical/secrets-action v1.0.16@77ab1f4ccd183a543cb5b42435fbd181189f4995
  • google-github-actions/auth v3.0.0@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • codecov/codecov-action v7@fb8b3582c8e4def4969c97caa2f19720cb33a72f
  • codecov/codecov-action v7@fb8b3582c8e4def4969c97caa2f19720cb33a72f
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-node v6.4.0@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e → [Updates: v6.5.0, v7.0.0]
  • codecov/codecov-action v7@fb8b3582c8e4def4969c97caa2f19720cb33a72f
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
{{cookiecutter.project_slug}}/.github/workflows/cifuzzy.yml (6)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • google/clusterfuzzlite v1@884713a6c30a92e5e8544c39945cd7cb630abcd1
  • google/clusterfuzzlite v1@884713a6c30a92e5e8544c39945cd7cb630abcd1
  • github/codeql-action v4.36.2@8aad20d150bbac5944a9f9d289da16a4b0d87c1e → [Updates: v4.37.4]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
{{cookiecutter.project_slug}}/.github/workflows/codecov.yml (3)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
{{cookiecutter.project_slug}}/.github/workflows/container-security.yml (1)
  • {{ cookiecutter.github_org_or_user }}/.github main
{{cookiecutter.project_slug}}/.github/workflows/dependency-review.yml (3)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/dependency-review-action v5.0.0@a1d282b36b6f3519aa1f3fc636f609c47dddb294
{{cookiecutter.project_slug}}/.github/workflows/docs.yml (4)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
{{cookiecutter.project_slug}}/.github/workflows/fips-compatibility.yml (8)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • actions/github-script v9.0.0@3a2844b7e9c422d3c10d287c895573f7108da1b3
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
{{cookiecutter.project_slug}}/.github/workflows/mutation-testing.yml (2)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
{{cookiecutter.project_slug}}/.github/workflows/pr-validation.yml (10)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • lycheeverse/lychee-action v2.8.0@8646ba30535128ac92d33dfc9133794bfdd9b411 → [Updates: v2.9.0]
{{cookiecutter.project_slug}}/.github/workflows/publish-pypi.yml (1)
  • {{ cookiecutter.github_org_or_user }}/.github main
{{cookiecutter.project_slug}}/.github/workflows/python-compatibility.yml (5)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
{{cookiecutter.project_slug}}/.github/workflows/qlty.yml (1)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
{{cookiecutter.project_slug}}/.github/workflows/release.yml (18)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • python-semantic-release/python-semantic-release v10.5.3@350c48fcb3ffcdfd2e0a235206bc2ecea6b69df0 → [Updates: v10.6.1]
  • pypa/gh-action-pypi-publish release/v1@cef221092ed1bacb1cc03d23a2d87d1d172e277b → [Updates: release/v1]
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • softprops/action-gh-release v3.0.1@718ea10b132b3b2eba29c1007bb80653f286566b → [Updates: v3.0.2]
  • pypa/gh-action-pypi-publish release/v1@cef221092ed1bacb1cc03d23a2d87d1d172e277b → [Updates: release/v1]
{{cookiecutter.project_slug}}/.github/workflows/reuse.yml (6)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • fsfe/reuse-action v6.0.0@676e2d560c9a403aa252096d99fcab3e1132b0f5
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
{{cookiecutter.project_slug}}/.github/workflows/sbom.yml (1)
  • {{ cookiecutter.github_org_or_user }}/.github main
{{cookiecutter.project_slug}}/.github/workflows/scorecard.yml (6)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • ossf/scorecard-action v2.4.3@4eaacf0543bb3f2c246792bd56e8cdeffafb205a → [Updates: v2.4.4]
  • github/codeql-action v4.36.2@8aad20d150bbac5944a9f9d289da16a4b0d87c1e → [Updates: v4.37.4]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
{{cookiecutter.project_slug}}/.github/workflows/security-analysis.yml (8)
  • {{ cookiecutter.github_org_or_user }}/.github main
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • google/osv-scanner-action v2.3.8@9a498708959aeaef5ef730655706c5a1df1edbc2
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
{{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml (7)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • astral-sh/setup-uv v8.2.0@fac544c07dec837d0ccb6301d7b5580bf5edae39 → [Updates: v8.3.2, v9.0.0]
  • actions/upload-artifact v7.0.1@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
  • actions/attest-build-provenance v4.1.0@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 → [Updates: v4.1.1]
  • {{ cookiecutter.github_org_or_user }}/.github main
{{cookiecutter.project_slug}}/.github/workflows/sonarcloud.yml (1)
  • ByronWilliamsCPA/.github main@961eb17d8e9b7fe0d8bfc5dbe9d23c824484fb11
{{cookiecutter.project_slug}}/.github/workflows/validate-cruft.yml (4)
  • step-security/harden-runner v2.19.4@9af89fc71515a100421586dfdb3dc9c984fbf411 → [Updates: v2.20.0]
  • actions/checkout v7@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7]
  • actions/setup-python v6.3.0@ece7cb06caefa5fff74198d8649806c4678c61a1 → [Updates: v7.0.0]
  • python 3.12
pep621 (1)
pyproject.toml (19)
  • python >=3.10
  • codespell >=2.4.1
  • interrogate >=1.7.0
  • pydoclint >=0.8.4
  • pre-commit >=3.5.0
  • ruff >=0.14.6
  • basedpyright >=1.35.0
  • bandit >=1.7.5
  • pip-audit >=2.7.0
  • detect-secrets >=1.5.0
  • cookiecutter >=2.5.0
  • cruft >=2.15.0
  • pytest >=7.4.0
  • pytest-cov >=4.1.0
  • pytest-mock >=3.14.0
  • pytest-randomly >=3.15.0
  • pytest-xdist >=3.5.0
  • tomli >=2.0.1
  • tomli-w >=1.0.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions