dependabot[bot]
|
12723aad7b
|
Bump actions/setup-go from 4.1.0 to 5.0.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4.1.0 to 5.0.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](93397bea11...0c52d547c9)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-12-10 06:31:36 +00:00 |
justinsb
|
eb4d81128b
|
chore: Bump go to 1.21.5
Includes some security fixes in net/http
|
2023-12-08 20:29:23 -05:00 |
Ciprian Hacman
|
1653cf74dc
|
Update Go to v1.21.4
|
2023-11-09 07:18:46 +02:00 |
dependabot[bot]
|
28e2269fbc
|
Bump actions/checkout from 4.1.0 to 4.1.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](8ade135a41...b4ffde65f4)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-10-22 06:33:02 +00:00 |
Ciprian Hacman
|
53729a291b
|
Update Go to v1.21.3
|
2023-10-11 08:05:08 +03:00 |
Ciprian Hacman
|
0b93149a8e
|
Update Go to v1.21.2
|
2023-10-06 15:37:11 +03:00 |
dependabot[bot]
|
6564f9d8c3
|
Bump actions/checkout from 4.0.0 to 4.1.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](3df4ab11eb...8ade135a41)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-09-24 06:03:43 +00:00 |
dependabot[bot]
|
718cc245ab
|
Bump actions/checkout from 3.6.0 to 4.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.6.0 to 4.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](f43a0e5ff2...3df4ab11eb)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-09-10 06:57:32 +00:00 |
Ciprian Hacman
|
3d70853215
|
Update Go to v1.21.1
|
2023-09-09 04:54:09 +03:00 |
dependabot[bot]
|
3e02e851c5
|
Bump actions/checkout from 3.5.3 to 3.6.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.5.3 to 3.6.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](c85c95e3d7...f43a0e5ff2)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-08-27 06:41:43 +00:00 |
dependabot[bot]
|
4dcb62d1c4
|
Bump actions/setup-go from 4.0.1 to 4.1.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4.0.1 to 4.1.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](fac708d667...93397bea11)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-08-13 06:17:02 +00:00 |
Ciprian Hacman
|
98ea158e67
|
Update Go to v1.20.6
|
2023-07-11 20:19:51 +03:00 |
Ciprian Hacman
|
640afe6898
|
Update Go to v1.20.5
|
2023-06-15 19:47:03 +03:00 |
dependabot[bot]
|
e226b60591
|
Bump actions/checkout from 3.5.2 to 3.5.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.5.2 to 3.5.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](8e5e7e5ab8...c85c95e3d7)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-06-11 06:57:12 +00:00 |
dependabot[bot]
|
0c5eb4c8a8
|
Bump actions/setup-go from 4.0.0 to 4.0.1
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4.0.0 to 4.0.1.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](4d34df0c23...fac708d667)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-05-21 06:57:30 +00:00 |
Ciprian Hacman
|
ba642ec925
|
Update Go to v1.20.4
|
2023-05-08 08:00:05 +03:00 |
dependabot[bot]
|
c2c0eb8da7
|
Bump actions/checkout from 3.5.0 to 3.5.2
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.5.0 to 3.5.2.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](8f4b7f8486...8e5e7e5ab8)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-04-16 08:37:38 +00:00 |
Ole Markus With
|
a57f754c63
|
Bump golang to 1.20
|
2023-04-16 07:48:26 +02:00 |
dependabot[bot]
|
db3cfc7b58
|
Bump actions/checkout from 3.4.0 to 3.5.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.4.0 to 3.5.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](24cb908017...8f4b7f8486)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-03-26 08:08:49 +00:00 |
dependabot[bot]
|
6cd9957c83
|
Bump actions/checkout from 3.3.0 to 3.4.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.3.0 to 3.4.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](ac59398561...24cb908017)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-03-19 07:47:52 +00:00 |
dependabot[bot]
|
4f5cb6a2ad
|
Bump actions/setup-go from 3.5.0 to 4.0.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.5.0 to 4.0.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](6edd4406fa...4d34df0c23)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-03-19 06:57:48 +00:00 |
Ciprian Hacman
|
92dc38e3da
|
Update Go to v1.19.7
|
2023-03-08 05:39:36 +02:00 |
Ciprian Hacman
|
c905df5960
|
Update Go to v1.19.6
|
2023-02-16 05:59:44 +02:00 |
Ciprian Hacman
|
2d5e27cbaa
|
Update Go to v1.19.5
|
2023-01-11 10:56:25 +02:00 |
dependabot[bot]
|
dc8d6b4895
|
Bump actions/checkout from 3.2.0 to 3.3.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](755da8c3cf...ac59398561)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-01-08 06:01:10 +00:00 |
dependabot[bot]
|
ec39ec9647
|
Bump actions/setup-go from 3.4.0 to 3.5.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.4.0 to 3.5.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](d0a58c1c4d...6edd4406fa)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-12-18 06:48:25 +00:00 |
dependabot[bot]
|
cbd67cddb6
|
Bump actions/checkout from 3.1.0 to 3.2.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.1.0 to 3.2.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](93ea575cb5...755da8c3cf)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-12-18 06:03:52 +00:00 |
Ciprian Hacman
|
f8464e24a7
|
Update Go to v1.19.4
|
2022-12-13 06:07:32 +02:00 |
dependabot[bot]
|
52c689a29d
|
Bump actions/setup-go from 3.3.1 to 3.4.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.3.1 to 3.4.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](c4a742cab1...d0a58c1c4d)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-12-04 06:01:14 +00:00 |
Ciprian Hacman
|
01ecd15a05
|
Update Go to v1.19.3
|
2022-11-15 05:05:01 +02:00 |
dependabot[bot]
|
f4b766db50
|
Bump actions/setup-go from 3.3.0 to 3.3.1
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.3.0 to 3.3.1.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](268d8c0ca0...c4a742cab1)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-10-23 06:16:25 +00:00 |
dependabot[bot]
|
c98f96e412
|
Bump actions/checkout from 3.0.2 to 3.1.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.0.2 to 3.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](2541b1294d...93ea575cb5)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-10-09 07:08:30 +00:00 |
dependabot[bot]
|
b84cece1a7
|
Bump actions/setup-go from 3.2.1 to 3.3.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.2.1 to 3.3.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](84cbf80943...268d8c0ca0)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-08-28 06:19:36 +00:00 |
Ciprian Hacman
|
6b8b45355d
|
Update Go to v1.19.0
|
2022-08-17 06:56:48 +03:00 |
Ciprian Hacman
|
d686975489
|
Switch to latest MacOS version for CI
|
2022-07-21 20:22:11 +03:00 |
dependabot[bot]
|
8555fbdc9e
|
Bump actions/setup-go from 3.2.0 to 3.2.1
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.2.0 to 3.2.1.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](b22fbbc292...84cbf80943)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-07-19 03:20:46 +00:00 |
Kubernetes Prow Robot
|
cb6bd4d9e7
|
Merge pull request #13995 from hakman/update_github_workflows
Update GitHub workflows
|
2022-07-18 20:20:06 -07:00 |
Ciprian Hacman
|
451256f966
|
Use hashes for actions versions
|
2022-07-18 08:09:54 +03:00 |
Ciprian Hacman
|
7d69bb0976
|
Update Go to v1.18.4
|
2022-07-18 07:53:50 +03:00 |
dependabot[bot]
|
b50bd8b59d
|
Bump actions/setup-go from 3.1.0 to 3.2.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.1.0 to 3.2.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](fcdc43634a...b22fbbc292)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-05-29 06:13:12 +00:00 |
dependabot[bot]
|
f682cea494
|
Bump actions/setup-go from 3.0.0 to 3.1.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3.0.0 to 3.1.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](f6164bd8c8...fcdc43634a)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-05-15 06:12:41 +00:00 |
Ciprian Hacman
|
03cb37aed2
|
Update Go to v1.18.1
|
2022-04-22 21:20:06 +03:00 |
Ciprian Hacman
|
2ca4a9bee3
|
Use golang 1.18.0 explicitly
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
|
2022-03-29 07:22:16 +03:00 |
Ole Markus With
|
59631a1fff
|
Use golang 1.18 for building
|
2022-03-28 20:24:09 +02:00 |
Ciprian Hacman
|
641ef62230
|
Apply suggestions from code review
|
2022-03-28 17:05:02 +03:00 |
dependabot[bot]
|
a90c265a6f
|
Bump actions/setup-go from 2.2.0 to 3
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 2.2.0 to 3.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](bfdd3570ce...f6164bd8c8)
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-03-28 13:29:58 +00:00 |
naveensrinivasan
|
b832368bf7
|
Pin actions to a full length commit SHA
- Pinned actions by SHA https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
>Pin actions to a full length commit SHA
>Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload.
https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
Also, dependabot supports upgrading based on SHA.
Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
|
2022-03-27 18:05:05 +00:00 |
naveensrinivasan
|
f48e39c2a1
|
Pinned action by SHA and included the URL for verification
|
2022-03-27 18:02:41 +00:00 |
Ciprian Hacman
|
dfe088eb3e
|
Update Go to v1.17.5
|
2021-12-13 12:48:11 +02:00 |
Ciprian Hacman
|
8cd0633e70
|
Update Go to v1.17.4
|
2021-12-06 05:38:25 +02:00 |