From a3af0f90ce2be2056113b339c7822c2a1b51c5d7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 7 Sep 2026 17:45:33 +0000 Subject: [PATCH] ci: bump the actions group across 1 directory with 8 updates Bumps the actions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [bounded-systems/.github/.github/workflows/_claim-sweep.yml](https://github.com/bounded-systems/.github) | `14c1a9b3ade8bb6416f46c890eda21823647da09` | `2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445` | | [bounded-systems/ci-workflows/.github/workflows/osv-scan.yml](https://github.com/bounded-systems/ci-workflows) | `0.1.4` | `0.1.5` | | [bounded-systems/.github/.github/actions/broker-gh-token](https://github.com/bounded-systems/.github) | `99e88a0335519cb78be8a1b6623105613fa6aca1` | `2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445` | | [bounded-systems/.github/.github/workflows/_pr-claim.yml](https://github.com/bounded-systems/.github) | `8a56f22f32bd007affbef503a4f1ac736c9aa52d` | `2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445` | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.21.0` | `2.21.1` | | [bounded-systems/mint/.github/workflows/release-provenance.yml](https://github.com/bounded-systems/mint) | `0.5.0` | `0.8.0` | | [bounded-systems/.github/.github/workflows/repo-standard.yml](https://github.com/bounded-systems/.github) | `99e88a0335519cb78be8a1b6623105613fa6aca1` | `2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445` | | [bounded-systems/mint/.github/workflows/version.yml](https://github.com/bounded-systems/mint) | `0.5.0` | `0.8.0` | Updates `bounded-systems/.github/.github/workflows/_claim-sweep.yml` from 14c1a9b3ade8bb6416f46c890eda21823647da09 to 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 - [Release notes](https://github.com/bounded-systems/.github/releases) - [Commits](https://github.com/bounded-systems/.github/compare/14c1a9b3ade8bb6416f46c890eda21823647da09...2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445) Updates `bounded-systems/ci-workflows/.github/workflows/osv-scan.yml` from 0.1.4 to 0.1.5 - [Commits](https://github.com/bounded-systems/ci-workflows/compare/30978ba6776c30081379e23fa20a12f36db3a48c...fb7ca62fd9fb8af90af1097a0b21ee703c103dc4) Updates `bounded-systems/.github/.github/actions/broker-gh-token` from 99e88a0335519cb78be8a1b6623105613fa6aca1 to 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 - [Release notes](https://github.com/bounded-systems/.github/releases) - [Commits](https://github.com/bounded-systems/.github/compare/99e88a0335519cb78be8a1b6623105613fa6aca1...2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445) Updates `bounded-systems/.github/.github/workflows/_pr-claim.yml` from 8a56f22f32bd007affbef503a4f1ac736c9aa52d to 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 - [Release notes](https://github.com/bounded-systems/.github/releases) - [Commits](https://github.com/bounded-systems/.github/compare/8a56f22f32bd007affbef503a4f1ac736c9aa52d...2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445) Updates `step-security/harden-runner` from 2.21.0 to 2.21.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/05e31511f85b41b11d1cf0ef85d0992719546e2c...e14015d583714f6e62063499dc959a02595150a1) Updates `bounded-systems/mint/.github/workflows/release-provenance.yml` from 0.5.0 to 0.8.0 - [Release notes](https://github.com/bounded-systems/mint/releases) - [Changelog](https://github.com/bounded-systems/mint/blob/main/CHANGELOG.md) - [Commits](https://github.com/bounded-systems/mint/compare/v0.5.0...v0.8.0) Updates `bounded-systems/.github/.github/workflows/repo-standard.yml` from 99e88a0335519cb78be8a1b6623105613fa6aca1 to 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 - [Release notes](https://github.com/bounded-systems/.github/releases) - [Commits](https://github.com/bounded-systems/.github/compare/99e88a0335519cb78be8a1b6623105613fa6aca1...2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445) Updates `bounded-systems/mint/.github/workflows/version.yml` from 0.5.0 to 0.8.0 - [Release notes](https://github.com/bounded-systems/mint/releases) - [Changelog](https://github.com/bounded-systems/mint/blob/main/CHANGELOG.md) - [Commits](https://github.com/bounded-systems/mint/compare/v0.5.0...v0.8.0) --- updated-dependencies: - dependency-name: bounded-systems/.github/.github/workflows/_claim-sweep.yml dependency-version: 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 dependency-type: direct:production dependency-group: actions - dependency-name: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml dependency-version: 0.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: bounded-systems/.github/.github/actions/broker-gh-token dependency-version: 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 dependency-type: direct:production dependency-group: actions - dependency-name: bounded-systems/.github/.github/workflows/_pr-claim.yml dependency-version: 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 dependency-type: direct:production dependency-group: actions - dependency-name: step-security/harden-runner dependency-version: 2.21.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: bounded-systems/mint/.github/workflows/release-provenance.yml dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: bounded-systems/.github/.github/workflows/repo-standard.yml dependency-version: 2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 dependency-type: direct:production dependency-group: actions - dependency-name: bounded-systems/mint/.github/workflows/version.yml dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/claim-sweep.yml | 2 +- .github/workflows/deps.yml | 2 +- .github/workflows/front-desk-add.yml | 2 +- .github/workflows/pr-claim.yml | 2 +- .github/workflows/publish-jsr.yml | 2 +- .github/workflows/release.yml | 2 +- .github/workflows/standard.yml | 2 +- .github/workflows/version.yml | 2 +- 8 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/claim-sweep.yml b/.github/workflows/claim-sweep.yml index 318a448..5d42e5b 100644 --- a/.github/workflows/claim-sweep.yml +++ b/.github/workflows/claim-sweep.yml @@ -69,7 +69,7 @@ concurrency: jobs: sweep: # SHA-pinned, per org policy — never a branch. - uses: bounded-systems/.github/.github/workflows/_claim-sweep.yml@14c1a9b3ade8bb6416f46c890eda21823647da09 + uses: bounded-systems/.github/.github/workflows/_claim-sweep.yml@2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 permissions: contents: read issues: write diff --git a/.github/workflows/deps.yml b/.github/workflows/deps.yml index e6a0543..b634ae3 100644 --- a/.github/workflows/deps.yml +++ b/.github/workflows/deps.yml @@ -53,6 +53,6 @@ jobs: osv: # SHA-pinned per org policy. `# main` records what the SHA was at the time, so a # reviewer can tell an intentional bump from a drifted one. - uses: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml@30978ba6776c30081379e23fa20a12f36db3a48c # main + uses: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml@fb7ca62fd9fb8af90af1097a0b21ee703c103dc4 # main with: report-only: true # adoption grace — delete this once findings are clear (ci-workflows#2) diff --git a/.github/workflows/front-desk-add.yml b/.github/workflows/front-desk-add.yml index 4934806..b9a8f22 100644 --- a/.github/workflows/front-desk-add.yml +++ b/.github/workflows/front-desk-add.yml @@ -59,7 +59,7 @@ jobs: id: app-token if: ${{ vars.CF_BROKER_URL != '' }} continue-on-error: true - uses: bounded-systems/.github/.github/actions/broker-gh-token@99e88a0335519cb78be8a1b6623105613fa6aca1 # broker-gh-token (prx-26bq), .github#109 + uses: bounded-systems/.github/.github/actions/broker-gh-token@2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 # broker-gh-token (prx-26bq), .github#109 with: app: front-desk broker-url: ${{ vars.CF_BROKER_URL }} diff --git a/.github/workflows/pr-claim.yml b/.github/workflows/pr-claim.yml index 65c6008..ec390da 100644 --- a/.github/workflows/pr-claim.yml +++ b/.github/workflows/pr-claim.yml @@ -53,4 +53,4 @@ jobs: issues: read pull-requests: read # SHA-pinned, per org policy — never a branch. - uses: bounded-systems/.github/.github/workflows/_pr-claim.yml@8a56f22f32bd007affbef503a4f1ac736c9aa52d \ No newline at end of file + uses: bounded-systems/.github/.github/workflows/_pr-claim.yml@2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 \ No newline at end of file diff --git a/.github/workflows/publish-jsr.yml b/.github/workflows/publish-jsr.yml index 4af3ef1..a530a7f 100644 --- a/.github/workflows/publish-jsr.yml +++ b/.github/workflows/publish-jsr.yml @@ -27,7 +27,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Harden runner - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f6be1bc..abe2592 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,6 +16,6 @@ permissions: jobs: release: - uses: bounded-systems/mint/.github/workflows/release-provenance.yml@v0.5.0 # mint + uses: bounded-systems/mint/.github/workflows/release-provenance.yml@v0.8.0 # mint with: ref: v0.3.1 diff --git a/.github/workflows/standard.yml b/.github/workflows/standard.yml index f387aab..9f647fb 100644 --- a/.github/workflows/standard.yml +++ b/.github/workflows/standard.yml @@ -7,7 +7,7 @@ permissions: contents: read jobs: standard: - uses: bounded-systems/.github/.github/workflows/repo-standard.yml@99e88a0335519cb78be8a1b6623105613fa6aca1 + uses: bounded-systems/.github/.github/workflows/repo-standard.yml@2cd9ebc0a2543b3ba11dc7673b351a9d1f6c9445 with: security: true test: true diff --git a/.github/workflows/version.yml b/.github/workflows/version.yml index 8d324ec..d662975 100644 --- a/.github/workflows/version.yml +++ b/.github/workflows/version.yml @@ -13,6 +13,6 @@ permissions: jobs: version: - uses: bounded-systems/mint/.github/workflows/version.yml@v0.5.0 # mint + uses: bounded-systems/mint/.github/workflows/version.yml@v0.8.0 # mint with: ref: v0.3.1