-
Notifications
You must be signed in to change notification settings - Fork 197
Commit 95ee1bc
authored
Update workflows (#898)
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://github.com/actions/checkout) | action |
minor | `v3.1.0` -> `v3.2.0` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action) |
action | minor | `v2.0.6` -> `v2.1.2` |
|
[pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish)
| action | patch | `v1.6.1` -> `v1.6.4` |
---
### Release Notes
<details>
<summary>actions/checkout</summary>
###
[`v3.2.0`](https://github.com/actions/checkout/releases/tag/v3.2.0)
[Compare
Source](https://github.com/actions/checkout/compare/v3.1.0...v3.2.0)
#### What's Changed
- Add GitHub Action to perform release by
[@​rentziass](https://github.com/rentziass) in
[https://github.com/actions/checkout/pull/942](https://github.com/actions/checkout/pull/942)
- Fix status badge by
[@​ScottBrenner](https://github.com/ScottBrenner) in
[https://github.com/actions/checkout/pull/967](https://github.com/actions/checkout/pull/967)
- Replace datadog/squid with ubuntu/squid Docker image by
[@​cory-miller](https://github.com/cory-miller) in
[https://github.com/actions/checkout/pull/1002](https://github.com/actions/checkout/pull/1002)
- Wrap pipeline commands for submoduleForeach in quotes by
[@​jokreliable](https://github.com/jokreliable) in
[https://github.com/actions/checkout/pull/964](https://github.com/actions/checkout/pull/964)
- Update [@​actions/io](https://github.com/actions/io) to 1.1.2
by [@​cory-miller](https://github.com/cory-miller) in
[https://github.com/actions/checkout/pull/1029](https://github.com/actions/checkout/pull/1029)
- Upgrading version to 3.2.0 by
[@​vmjoseph](https://github.com/vmjoseph) in
[https://github.com/actions/checkout/pull/1039](https://github.com/actions/checkout/pull/1039)
#### New Contributors
- [@​ScottBrenner](https://github.com/ScottBrenner) made their
first contribution in
[https://github.com/actions/checkout/pull/967](https://github.com/actions/checkout/pull/967)
- [@​cory-miller](https://github.com/cory-miller) made their
first contribution in
[https://github.com/actions/checkout/pull/1002](https://github.com/actions/checkout/pull/1002)
- [@​jokreliable](https://github.com/jokreliable) made their
first contribution in
[https://github.com/actions/checkout/pull/964](https://github.com/actions/checkout/pull/964)
- [@​vmjoseph](https://github.com/vmjoseph) made their first
contribution in
[https://github.com/actions/checkout/pull/1039](https://github.com/actions/checkout/pull/1039)
**Full Changelog**:
actions/checkout@v3...v3.2.0
</details>
<details>
<summary>ossf/scorecard-action</summary>
###
[`v2.1.2`](https://github.com/ossf/scorecard-action/releases/tag/v2.1.2)
[Compare
Source](https://github.com/ossf/scorecard-action/compare/v2.1.1...v2.1.2)
#### What's Changed
##### Fixes
- 🌱 Bump scorecard dependency to v4.10.2 to remove a CODEOWNERS printf
statement. by
[@​spencerschrock](https://github.com/spencerschrock) in
[https://github.com/ossf/scorecard-action/pull/1054](https://github.com/ossf/scorecard-action/pull/1054)
**Full Changelog**:
ossf/scorecard-action@v2.1.1...v2.1.2
###
[`v2.1.1`](https://github.com/ossf/scorecard-action/releases/tag/v2.1.1)
[Compare
Source](https://github.com/ossf/scorecard-action/compare/v2.1.0...v2.1.1)
#### Scorecard version
This release use [Scorecard's
v4.10.1](https://github.com/ossf/scorecard/releases/tag/v4.10.1)
**Full Changelog**:
ossf/scorecard-action@v2.1.0...v2.1.1
###
[`v2.1.0`](https://github.com/ossf/scorecard-action/releases/tag/v2.1.0)
[Compare
Source](https://github.com/ossf/scorecard-action/compare/v2.0.6...v2.1.0)
#### What's Changed
##### Scorecard version
This release uses [scorecard
v4.10.0](https://github.com/ossf/scorecard/releases/tag/v4.10.0).
##### Improvements
- Docker build workflow by
[@​naveensrinivasan](https://github.com/naveensrinivasan) in
[https://github.com/ossf/scorecard-action/pull/981](https://github.com/ossf/scorecard-action/pull/981)
- Use root user in distroless to support GitHub Actions by
[@​spencerschrock](https://github.com/spencerschrock) in
[https://github.com/ossf/scorecard-action/pull/994](https://github.com/ossf/scorecard-action/pull/994)
- Disable pull_request_target by
[@​laurentsimon](https://github.com/laurentsimon) in
[https://github.com/ossf/scorecard-action/pull/1031](https://github.com/ossf/scorecard-action/pull/1031)
##### Documentation
- Add PAT section explaining risks by
[@​olivekl](https://github.com/olivekl) in
[https://github.com/ossf/scorecard-action/pull/1024](https://github.com/ossf/scorecard-action/pull/1024)
- Make the badge text easier to copy by
[@​rajbos](https://github.com/rajbos) in
[https://github.com/ossf/scorecard-action/pull/1026](https://github.com/ossf/scorecard-action/pull/1026)
#### New Contributors
- [@​joycebrum](https://github.com/joycebrum) made their first
contribution in
[https://github.com/ossf/scorecard-action/pull/984](https://github.com/ossf/scorecard-action/pull/984)
- [@​rajbos](https://github.com/rajbos) made their first
contribution in
[https://github.com/ossf/scorecard-action/pull/1026](https://github.com/ossf/scorecard-action/pull/1026)
**Full Changelog**:
ossf/scorecard-action@v2.0.6...v2.1.0
</details>
<details>
<summary>pypa/gh-action-pypi-publish</summary>
###
[`v1.6.4`](https://github.com/pypa/gh-action-pypi-publish/releases/tag/v1.6.4)
[Compare
Source](https://github.com/pypa/gh-action-pypi-publish/compare/v1.6.3...v1.6.4)
#### oh, boi! again?
This is the last one tonight, promise! It fixes this embarrassing bug
that was actually caught by the CI but got overlooked due to the lack of
sleep.
TL;DR GH passed `$HOME` from the external env into the container and
that tricked the Python's `site` module to think that the home directory
is elsewhere, adding non-existent paths to the env vars. See
[#​115](https://github.com/pypa/gh-action-pypi-publish/issues/115).
**Full Diff**:
pypa/gh-action-pypi-publish@v1.6.3...v1.6.4
###
[`v1.6.3`](https://github.com/pypa/gh-action-pypi-publish/releases/tag/v1.6.3)
[Compare
Source](https://github.com/pypa/gh-action-pypi-publish/compare/v1.6.2...v1.6.3)
### Another Release!? Why?
In
[https://github.com/pypa/gh-action-pypi-publish/issues/112#issuecomment-1340133013](https://github.com/pypa/gh-action-pypi-publish/issues/112#issuecomment-1340133013),
it was discovered that passing a `$PATH` variable even breaks the
shebang. So this version adds more safeguards to make sure it keeps
working with a fully broken `$PATH`.
**Full Diff**:
pypa/gh-action-pypi-publish@v1.6.2...v1.6.3
###
[`v1.6.2`](https://github.com/pypa/gh-action-pypi-publish/releases/tag/v1.6.2)
[Compare
Source](https://github.com/pypa/gh-action-pypi-publish/compare/v1.6.1...v1.6.2)
#### What's Fixed
- Made the `$PATH` and `$PYTHONPATH` environment variables resilient to
broken values passed from the host runner environment, which previously
allowed the users to accidentally break the container's internal runtime
as reported in
[https://github.com/pypa/gh-action-pypi-publish/issues/112](https://github.com/pypa/gh-action-pypi-publish/issues/112)
#### Internal Maintenance Improvements
- Added a devpi-based smoke-test GitHub Actions CI/CD workflow by
[@​sesdaile-varmour](https://github.com/sesdaile-varmour) in
[https://github.com/pypa/gh-action-pypi-publish/pull/111](https://github.com/pypa/gh-action-pypi-publish/pull/111)
#### New Contributors
- [@​sesdaile-varmour](https://github.com/sesdaile-varmour) made
their first contribution in
[https://github.com/pypa/gh-action-pypi-publish/pull/111](https://github.com/pypa/gh-action-pypi-publish/pull/111)
**Full Diff**:
pypa/gh-action-pypi-publish@v1.6.1...v1.6.2
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "before 6am on monday" in timezone
Australia/Sydney, Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://app.renovatebot.com/dashboard#github/google/osv.dev).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4yNC4wIiwidXBkYXRlZEluVmVyIjoiMzQuNzMuMyJ9-->1 parent ebff43b commit 95ee1bcCopy full SHA for 95ee1bc
2 files changed
+3
-3
lines changed.github/workflows/publish-to-pypi.yaml
Copy file name to clipboardexpand all lines: .github/workflows/publish-to-pypi.yaml+1-1
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
46 |
| - | |
| 46 | + | |
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
|
.github/workflows/scorecards.yml
Copy file name to clipboardexpand all lines: .github/workflows/scorecards.yml+2-2
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
|
0 commit comments