🌱 Bump the all-github-actions group across 1 directory with 13 updates#264
🌱 Bump the all-github-actions group across 1 directory with 13 updates#264dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the all-github-actions group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [sqren/backport-github-action](https://github.com/sqren/backport-github-action) | `9.2.2` | `11.0.0` | | [actions/checkout](https://github.com/actions/checkout) | `3` | `6` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.3.0` | `6.3.0` | | [actions/cache](https://github.com/actions/cache) | `4.2.0` | `5.0.4` | | [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) | `9.1.4` | `10.0.0` | | [actions/github-script](https://github.com/actions/github-script) | `7.0.1` | `8.0.0` | | [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `6.3.2` | `9.2.0` | | [gaurav-nelson/github-action-markdown-link-check](https://github.com/gaurav-nelson/github-action-markdown-link-check) | `1.0.16` | `1.0.17` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `dcc7a0cba800f454d79fff4b993e8c3555bcc0a8` | `3d37a7ff08a7ce64b4cab9669eac39b0709cdac9` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.2.1` | `2.6.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `1` | `4` | | [docker/login-action](https://github.com/docker/login-action) | `1` | `4` | | [mukunku/tag-exists-action](https://github.com/mukunku/tag-exists-action) | `1.2.0` | `1.7.0` | Updates `sqren/backport-github-action` from 9.2.2 to 11.0.0 - [Release notes](https://github.com/sqren/backport-github-action/releases) - [Commits](sorenlouv/backport-github-action@v9.2.2...v11.0.0) Updates `actions/checkout` from 3 to 6 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v3...v6) Updates `actions/setup-go` from 5.3.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@f111f33...4b73464) Updates `actions/cache` from 4.2.0 to 5.0.4 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@1bd1e32...6682284) Updates `EndBug/add-and-commit` from 9.1.4 to 10.0.0 - [Release notes](https://github.com/endbug/add-and-commit/releases) - [Commits](EndBug/add-and-commit@a94899b...290ea2c) Updates `actions/github-script` from 7.0.1 to 8.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@60a0d83...ed59741) Updates `golangci/golangci-lint-action` from 6.3.2 to 9.2.0 - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@051d919...1e7e51e) Updates `gaurav-nelson/github-action-markdown-link-check` from 1.0.16 to 1.0.17 - [Release notes](https://github.com/gaurav-nelson/github-action-markdown-link-check/releases) - [Commits](gaurav-nelson/github-action-markdown-link-check@1b916f2...3c3b66f) Updates `tj-actions/changed-files` from dcc7a0cba800f454d79fff4b993e8c3555bcc0a8 to 3d37a7ff08a7ce64b4cab9669eac39b0709cdac9 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](tj-actions/changed-files@dcc7a0c...3d37a7f) Updates `softprops/action-gh-release` from 2.2.1 to 2.6.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@c95fe14...153bb8e) Updates `docker/setup-buildx-action` from 1 to 4 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@v1...v4) Updates `docker/login-action` from 1 to 4 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v1...v4) Updates `mukunku/tag-exists-action` from 1.2.0 to 1.7.0 - [Release notes](https://github.com/mukunku/tag-exists-action/releases) - [Commits](mukunku/tag-exists-action@v1.2.0...v1.7.0) --- updated-dependencies: - dependency-name: sqren/backport-github-action dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: actions/setup-go dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: actions/cache dependency-version: 5.0.4 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: EndBug/add-and-commit dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: actions/github-script dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: golangci/golangci-lint-action dependency-version: 9.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: gaurav-nelson/github-action-markdown-link-check dependency-version: 1.0.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-github-actions - dependency-name: tj-actions/changed-files dependency-version: 3d37a7ff08a7ce64b4cab9669eac39b0709cdac9 dependency-type: direct:production dependency-group: all-github-actions - dependency-name: softprops/action-gh-release dependency-version: 2.6.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-github-actions - dependency-name: docker/setup-buildx-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: docker/login-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-github-actions - dependency-name: mukunku/tag-exists-action dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a spectrocloud member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
There was a problem hiding this comment.
- GO-2026-4394
- Module: go.opentelemetry.io/otel/sdk
- Found in: v1.28.0
- Fixed in: v1.40.0
- Example Traces:
1. internal/topology/variables/clusterclass_variable_validation.go:28:2: variables.init calls validation.init, which eventually calls tracing.init
2. cmd/clusterctl/client/repository/repository_gitlab.go:157:34: repository.GetFile calls http.Do, which eventually calls noop.Start
3. cmd/clusterctl/client/repository/repository_gitlab.go:157:34: repository.GetFile calls http.Do, which eventually calls otelhttp.RoundTrip
4. util/record/recorder.go:42:13: record.InitFromRecorder calls sync.Do, which eventually calls sync.doSlow
5. cmd/clusterctl/client/repository/repository_gitlab.go:157:34: repository.GetFile calls http.Do, which eventually calls otelhttp.RoundTrip
- GO-2025-3754
- Module: github.com/cloudflare/circl
- Found in: v1.3.7
- Fixed in: v1.6.1
- Example Traces:
1. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ed25519.init
2. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ecc.init
3. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ecc.init
4. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ecc.init
5. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ed448.init
- GO-2026-4550
- Module: github.com/cloudflare/circl
- Found in: v1.3.7
- Fixed in: v1.6.3
- Example Traces:
1. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ed25519.init
2. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ecc.init
3. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ecc.init
4. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls ed448.init
5. cmd/clusterctl/internal/test/fake_github.go:24:2: test.init calls github.init, which eventually calls x25519.init
Please review these findings and fix the issues before merging.
There was a problem hiding this comment.
- G115: integer overflow conversion int64 -> int32, Severity: HIGH
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/cluster/cluster_controller_status.go:107:63
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/cluster/cluster_controller_status.go:104:70
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/contract/types.go:129:22
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/test/envtest/environment.go:93:47
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machineset/machineset_controller_status.go:189:26
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machineset/machineset_controller_status.go:123:26
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machineset/machineset_controller.go:1211:28
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinehealthcheck/machinehealthcheck_controller.go:678:26
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinehealthcheck/machinehealthcheck_controller.go:666:27
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinehealthcheck/machinehealthcheck_controller.go:241:33
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinehealthcheck/machinehealthcheck_controller.go:226:35
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinedeployment/mdutil/util.go:726:14
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinedeployment/mdutil/util.go:655:58
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinedeployment/machinedeployment_sync.go:622:15
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/internal/controllers/machinedeployment/machinedeployment_rollout_ondelete.go:122:29
- ... (truncated), run gosec locally to capture all failure for the rule G115
-
- G404: Use of weak random number generator (math/rand or math/rand/v2 instead of crypto/rand), Severity: HIGH
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/util/util.go:61:8
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/util/conversion/conversion.go:160:18
-
- G402: TLS InsecureSkipVerify set to true., Severity: HIGH
-
- File: /home/runner/_work/bulwark/bulwark/target-repo/controlplane/kubeadm/internal/workload_cluster.go:469:62
-
Please review these findings and fix the issues before merging.
Bumps the all-github-actions group with 13 updates in the / directory:
9.2.211.0.0365.3.06.3.04.2.05.0.49.1.410.0.07.0.18.0.06.3.29.2.01.0.161.0.17dcc7a0cba800f454d79fff4b993e8c3555bcc0a83d37a7ff08a7ce64b4cab9669eac39b0709cdac92.2.12.6.114141.2.01.7.0Updates
sqren/backport-github-actionfrom 9.2.2 to 11.0.0Release notes
Sourced from sqren/backport-github-action's releases.
Commits
9460b71chore: release v11.0.0c0d1fb5feat: upgrade to backport@11 with smoke test suite (#177)e086778Convert to ESM, replace Jest with Vitest, align dependencies with backport6840073Replace RELEASE.md with cursor rule and skill566ba6cAdd feature-specific validation docs to RELEASE.md576c0c8Skip backport gracefully when PR is not merged7c4cc75Add RELEASE.md documenting the release and validation workflowd196c79Update backport to 10.4.0516854eBump Node 24 (#175)099cc6fBump backport to 10.2.0 (#174)Updates
actions/checkoutfrom 3 to 6Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)08c6903Prepare v5.0.0 release (#2238)Updates
actions/setup-gofrom 5.3.0 to 6.3.0Release notes
Sourced from actions/setup-go's releases.
... (truncated)
Commits
4b73464Fix golang download url to go.dev (#469)a5f9b05Update default Go module caching to use go.mod (#705)7a3fe6cBump qs from 6.14.0 to 6.14.1 (#703)b9adafdBump actions/checkout from 5 to 6 (#686)d73f6bcREADME.md: correct to actions/checkout@v6 (#683)ae252eeBump@actions/cacheto v5 (#695)bf7446aBump js-yaml from 3.14.1 to 3.14.2 (#682)02aadfeFix Node.js version in action.yml (#691)4aaadf4Example for restore-only cache in documentation (#696)4dc6199Bump semver and@types/semver(#652)Updates
actions/cachefrom 4.2.0 to 5.0.4Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
6682284Merge pull request #1738 from actions/prepare-v5.0.4e340396Update RELEASES8a67110Add licenses1865903Update dependencies & patch security vulnerabilities5656298Merge pull request #1722 from RyPeck/patch-14e380d1Fix cache key in examples.md for bun.lockb7e8d49Merge pull request #1701 from actions/Link-/fix-proxy-integration-tests984a21bAdd traffic sanity check stepacf2f1fFix resolution95a07c5Add wait for proxyUpdates
EndBug/add-and-commitfrom 9.1.4 to 10.0.0Release notes
Sourced from EndBug/add-and-commit's releases.
... (truncated)
Commits
290ea2c10.0.05190a0adocs: prepare for v109ac3878chore: npm audit fix7b015bddocs: add CodeReaper as a contributor for maintenance (#723)300836dchore(deps-dev): bump flatted from 3.3.3 to 3.4.2 (#722)f6e20edfeat!: use node version 24 (#720)6280653chore(deps-dev): bump jest from 30.2.0 to 30.3.0 (#721)1539a6achore(deps): bump@actions/corefrom 2.0.2 to 3.0.0 (#716)af611ddchore(deps): bump minimatch (#718)2df77c1chore(deps-dev): bump eslint-plugin-prettier from 5.5.4 to 5.5.5 (#712)Updates
actions/github-scriptfrom 7.0.1 to 8.0.0Release notes
Sourced from actions/github-script's releases.
Commits
ed59741Merge pull request #653 from actions/sneha-krip/readme-for-v82dc352eBold minimum Actions Runner version in README01e118cUpdate README for Node 24 runtime requirements8b222acApply suggestion from@salmanmkcadc0eeaREADME for updating actions/github-script from v7 to v820fe497Merge pull request #637 from actions/node24e7b7f22update licenses2c81ba0Update Node.js version support to 24.xf28e40cMerge pull request #610 from actions/nebuk89-patch-11ae9958Update README.mdUpdates
golangci/golangci-lint-actionfrom 6.3.2 to 9.2.0Release notes
Sourced from golangci/golangci-lint-action's releases.
... (truncated)
Commits
1e7e51ebuild(deps): bump yaml from 2.8.1 to 2.8.2 in the dependencies group (#1324)5256ff0build(deps-dev): bump the dev-dependencies group with 3 updates (#1323)13fed6fchore: update workflows7afe8ffchore: update workflows5a92899chore: move samples into fixtures (#1321)aa6fad0feat: add version-file option (#1320)a6071aabuild(deps): bump actions/checkout from 5 to 6 (#1318)6e36c84build(deps-dev): bump the dev-dependencies group with 2 updates (#1317)e7fa5acfeat: automatic module directories (#1315)f3ae99fdocs: organize options (#1314)Updates
gaurav-nelson/github-action-markdown-link-checkfrom 1.0.16 to 1.0.17Release notes
Sourced from gaurav-nelson/github-action-markdown-link-check's releases.
Commits
3c3b66fMerge pull request #205 from Okabe-Junya/bump/markdown-link-checkdd5abb6bump markdown-link-check9574206Add bug report and feature request templates with Linkspector updateUpdates
tj-actions/changed-filesfrom dcc7a0cba800f454d79fff4b993e8c3555bcc0a8 to 3d37a7ff08a7ce64b4cab9669eac39b0709cdac9Changelog
Sourced from tj-actions/changed-files's changelog.