Commit Graph

2366 Commits

Author SHA1 Message Date
dependabot[bot] ead0cab60e
Bump redis from `bd41d55` to `4724941` in /test/IntegrationTests/docker (#4134)
Bumps redis from `bd41d55` to `4724941`.

---
updated-dependencies:
- dependency-name: redis
  dependency-version: 7.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-08 16:49:39 +02:00
dependabot[bot] d641fa1bfa
Bump github/codeql-action from 3.28.13 to 3.28.15 (#4131)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.28.13 to 3.28.15.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](1b549b9259...45775bd823)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 3.28.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-08 09:41:28 +02:00
dependabot[bot] ab1626b5e0
Bump rabbitmq from 4.0.7 to 4.0.8 in /test/IntegrationTests/docker (#4128)
Bumps rabbitmq from 4.0.7 to 4.0.8.

---
updated-dependencies:
- dependency-name: rabbitmq
  dependency-version: 4.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-08 09:35:24 +02:00
Piotr Kiełkowicz c267593d7e
CodeQL - narrow permissions (#4130) 2025-04-08 07:46:23 +02:00
Piotr Kiełkowicz a181350c1f
CodeQL - Adjust permissions (#4129) 2025-04-08 07:36:20 +02:00
Piotr Kiełkowicz e6d31d1067
OpenSSF Scorecard - SAST / CodeQL (#4126) 2025-04-08 07:14:25 +02:00
Piotr Kiełkowicz 9c5f51c467
OpenSSF Scorecard - Set token-permissions to content-read (#4125) 2025-04-03 13:16:17 +02:00
Piotr Kiełkowicz b07874afc4
OpenSSF Scorecard - pin docker images to exact digest - ASP.NET Framework (#4124) 2025-04-03 12:06:34 +02:00
Piotr Kiełkowicz de5f0267bb
Security scans/best practices - badges in readme (#4123) 2025-04-03 06:34:01 +02:00
Piotr Kiełkowicz 0215924bb1
OpenSSF Scorecard - pin docker images to exact digest (#4122) 2025-04-02 15:26:12 +02:00
dependabot[bot] 6818044707
Bump mysql from `9b9d0aa` to `0596fa2` in /test/IntegrationTests/docker (#4120)
Bumps mysql from `9b9d0aa` to `0596fa2`.

---
updated-dependencies:
- dependency-name: mysql
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-01 19:06:20 +00:00
dependabot[bot] 91bb26ff7e
Bump centos/centos from `a9ebde7` to `509bc60` in /docker (#4121)
Bumps centos/centos from `a9ebde7` to `509bc60`.

---
updated-dependencies:
- dependency-name: centos/centos
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-01 20:11:46 +02:00
dependabot[bot] f10805bcfe
Bump github/codeql-action from 3.28.12 to 3.28.13 (#4118)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.28.12 to 3.28.13.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](5f8171a638...1b549b9259)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-01 13:21:12 +00:00
dependabot[bot] 3a24f60132
Bump lycheeverse/lychee-action from 2.3.0 to 2.4.0 (#4119)
* Bump lycheeverse/lychee-action from 2.3.0 to 2.4.0

Bumps [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/lycheeverse/lychee-action/releases)
- [Commits](f613c4a64e...1d97d84f0b)

---
updated-dependencies:
- dependency-name: lycheeverse/lychee-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix link

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-04-01 14:41:09 +02:00
OpenTelemetry Bot b4c33857de
Add ossf-scorecard scanning workflow (#4117)
* Add ossf-scorecard scanning workflow

* Add end of file newline

---------

Co-authored-by: otelbot <197425009+otelbot@users.noreply.github.com>
2025-04-01 06:37:35 +02:00
dependabot[bot] d83287c634
Bump mongo from 8.0.5 to 8.0.6 in /test/IntegrationTests/docker (#4114)
Bumps mongo from 8.0.5 to 8.0.6.

---
updated-dependencies:
- dependency-name: mongo
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 22:40:22 +02:00
dependabot[bot] 796283fbf9
Bump centos/centos from `e0946ab` to `a9ebde7` in /docker (#4115)
Bumps centos/centos from `e0946ab` to `a9ebde7`.

---
updated-dependencies:
- dependency-name: centos/centos
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 12:43:03 +00:00
Mateusz Łach fa73c9f138
[nuget-tests] remove external service usage (#4113) 2025-03-25 13:39:35 +01:00
dependabot[bot] e7659c522e
Bump fossas/fossa-action from 1.5.0 to 1.6.0 (#4112)
Bumps [fossas/fossa-action](https://github.com/fossas/fossa-action) from 1.5.0 to 1.6.0.
- [Release notes](https://github.com/fossas/fossa-action/releases)
- [Commits](93a52ecf7c...c0a7d013f8)

---
updated-dependencies:
- dependency-name: fossas/fossa-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-21 13:09:33 +00:00
dependabot[bot] faeaf8e7a5
Bump actions/upload-artifact from 4.6.1 to 4.6.2 (#4110)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.1 to 4.6.2.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](4cec3d8aa0...ea165f8d65)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-03-21 11:35:09 +01:00
dependabot[bot] bba225e444
Bump actions/cache from 4.2.2 to 4.2.3 (#4109)
Bumps [actions/cache](https://github.com/actions/cache) from 4.2.2 to 4.2.3.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](d4323d4df1...5a3ec84eff)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-03-21 10:39:09 +01:00
dependabot[bot] 0536bc693c
Bump centos/centos from `5da7cec` to `e0946ab` in /docker (#4111)
Bumps centos/centos from `5da7cec` to `e0946ab`.

---
updated-dependencies:
- dependency-name: centos/centos
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-21 10:02:24 +01:00
dependabot[bot] 2d74d58bec
Bump actions/download-artifact from 4.1.9 to 4.2.1 (#4108)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.1.9 to 4.2.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](cc20338598...95815c38cf)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-21 09:39:12 +01:00
Mateusz Łach 6818d32f43
[integration-tests] remove usage of external services (#4107) 2025-03-20 18:38:12 +01:00
Paulo Janotti dc65d0adbe
Make AspNetCoreBootstrapper all FrameworkReference assets private (#4103)
* Make AspNetCoreBootstrapper all FrameworkReference assets private

Related to #3911

* Fix doc link
2025-03-20 03:32:07 +00:00
dependabot[bot] e311bc9341
Bump postgres from `81f32a8` to `c522082` in /test/IntegrationTests/docker (#4096)
Bump postgres in /test/IntegrationTests/docker

Bumps postgres from `81f32a8` to `c522082`.

---
updated-dependencies:
- dependency-name: postgres
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 15:15:53 -07:00
Mateusz Łach 98a27861ae
[flaky-test] rabbitmq6 test app - wait for model to close (#4098) 2025-03-19 19:16:52 +01:00
dependabot[bot] e81f5e1e1d
Bump actions/setup-go from 5.3.0 to 5.4.0 (#4101)
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](f111f3307d...0aaccfd150)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 17:19:59 +01:00
dependabot[bot] a7fbc14d7c
Bump .NET SDK to 9.0.202 (#4099)
* Bump dotnet/sdk in /docker

Bumps dotnet/sdk from 9.0.201-bookworm-slim to 9.0.202-bookworm-slim.

---
updated-dependencies:
- dependency-name: dotnet/sdk
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump .NET SDK to 9.0.202

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-03-19 17:03:58 +01:00
dependabot[bot] 241910ec1f
Bump redis from `6aafb7f` to `5250fed` in /test/IntegrationTests/docker (#4097)
Bumps redis from `6aafb7f` to `5250fed`.

---
updated-dependencies:
- dependency-name: redis
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 15:35:42 +01:00
dependabot[bot] 79fb80d533
Bump centos/centos from `b511d51` to `5da7cec` in /docker (#4094)
Bumps centos/centos from `b511d51` to `5da7cec`.

---
updated-dependencies:
- dependency-name: centos/centos
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 06:25:36 +01:00
dependabot[bot] 9944bfe255
Bump actions/setup-dotnet from 4.3.0 to 4.3.1 (#4093)
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 4.3.0 to 4.3.1.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](3951f0dfe7...67a3573c9a)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-17 09:33:03 -07:00
dependabot[bot] 7e773954e9
Bump mongo from `36f9c73` to `7bd28e5` in /test/IntegrationTests/docker (#4092)
Bumps mongo from `36f9c73` to `7bd28e5`.

---
updated-dependencies:
- dependency-name: mongo
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-17 12:54:48 +00:00
dependabot[bot] 0bf7d0cbf2
Bump mysql from `1466826` to `9b9d0aa` in /test/IntegrationTests/docker (#4091)
Bumps mysql from `1466826` to `9b9d0aa`.

---
updated-dependencies:
- dependency-name: mysql
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-14 14:55:55 +01:00
dependabot[bot] 8bad67f2d0
Bump mongo from `f6164e4` to `36f9c73` in /test/IntegrationTests/docker (#4090)
Bumps mongo from `f6164e4` to `36f9c73`.

---
updated-dependencies:
- dependency-name: mongo
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-13 14:45:19 +01:00
Piotr Kiełkowicz b89cc58112
Suppress false positive NU1903 on CI/local builds (#4089) 2025-03-13 11:00:31 +01:00
dependabot[bot] d9b39cefff
Bump .NET SDK to 9.0.201/8.0.407 (#4088)
* Bump dotnet/sdk in /docker

Bumps dotnet/sdk from 9.0.200-bookworm-slim to 9.0.201-bookworm-slim.

---
updated-dependencies:
- dependency-name: dotnet/sdk
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump .NET SDK to 9.0.201/8.0.407

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-03-12 16:11:15 +00:00
dependabot[bot] 5e170cffed
Bump streetsidesoftware/cspell-action from 6.10.0 to 6.10.1 (#4086)
* Bump streetsidesoftware/cspell-action from 6.10.0 to 6.10.1

Bumps [streetsidesoftware/cspell-action](https://github.com/streetsidesoftware/cspell-action) from 6.10.0 to 6.10.1.
- [Release notes](https://github.com/streetsidesoftware/cspell-action/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell-action/blob/main/CHANGELOG.md)
- [Commits](ef95dc49d6...8485bb4b68)

---
updated-dependencies:
- dependency-name: streetsidesoftware/cspell-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Fix self-reference

* Bump Centos SHA256

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
2025-03-11 13:04:39 +01:00
Adrian Cole d41d86a9d4
allow wget in otel-dotnet-auto-install.sh (#4076)
* allow wget in otel-dotnet-auto-install.sh

Signed-off-by: Adrian Cole <adrian.cole@elastic.co>

* Update CHANGELOG.md

Co-authored-by: Robert Pająk <pellared@hotmail.com>

---------

Signed-off-by: Adrian Cole <adrian.cole@elastic.co>
Co-authored-by: Piotr Kiełkowicz <pkiekowicz@splunk.com>
Co-authored-by: Robert Pająk <pellared@hotmail.com>
2025-03-11 06:47:04 +01:00
Piotr Kiełkowicz 7cac0462b6
Post 1.11.0 release (#4083) 2025-03-06 12:54:43 +00:00
Piotr Kiełkowicz 38bed4e0d3
Release 1.11.0 (#4081) 2025-03-06 12:21:53 +01:00
Piotr Kiełkowicz 1f2760dae9
Bump OTel to 1.11.2 + transitive dependencies + internal dependencies (#4077)
* Bump OTel packages to 1.11.2

* Update transitive packages

* Bump internal packages

* CHANGELOG with security fix
2025-03-06 11:08:15 +01:00
dependabot[bot] 92e83194e4
Bump dotnet/sdk from `53b1a50` to `53b1a50` in /docker (#4079)
Bumps dotnet/sdk from `53b1a50` to `53b1a50`.

---
updated-dependencies:
- dependency-name: dotnet/sdk
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-06 08:39:56 +01:00
dependabot[bot] 0085707552
Bump centos/centos from `f9ac469` to `10cd56b` in /docker (#4078)
Bumps centos/centos from `f9ac469` to `10cd56b`.

---
updated-dependencies:
- dependency-name: centos/centos
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-06 08:39:32 +01:00
dependabot[bot] c317c72ea2
Bump postgres from `1c47b71` to `81f32a8` in /test/IntegrationTests/docker (#4074)
Bump postgres in /test/IntegrationTests/docker

Bumps postgres from `1c47b71` to `81f32a8`.

---
updated-dependencies:
- dependency-name: postgres
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-03 19:15:26 +01:00
dependabot[bot] 5138a506c6
Bump azure-storage/azurite from 3.33.0 to 3.34.0 in /test/IntegrationTests/docker (#4073)
Bump azure-storage/azurite in /test/IntegrationTests/docker

Bumps azure-storage/azurite from 3.33.0 to 3.34.0.

---
updated-dependencies:
- dependency-name: azure-storage/azurite
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-03 19:14:09 +01:00
dependabot[bot] 4dab15b02e
Bump mongo from `961312c` to `f6164e4` in /test/IntegrationTests/docker (#4070)
Bumps mongo from `961312c` to `f6164e4`.

---
updated-dependencies:
- dependency-name: mongo
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-03 07:21:54 +01:00
dependabot[bot] 2abc24aac2
Bump actions/cache from 4.2.1 to 4.2.2 (#4071)
Bumps [actions/cache](https://github.com/actions/cache) from 4.2.1 to 4.2.2.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](0c907a75c2...d4323d4df1)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-03 07:21:14 +01:00
dependabot[bot] df82f2a616
Bump rabbitmq from 4.0.6 to 4.0.7 in /test/IntegrationTests/docker (#4067)
Bumps rabbitmq from 4.0.6 to 4.0.7.

---
updated-dependencies:
- dependency-name: rabbitmq
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-28 07:00:37 +01:00
dependabot[bot] 6fc49fa6d4
Bump actions/download-artifact from 4.1.8 to 4.1.9 (#4064)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.1.8 to 4.1.9.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](fa0a91b85d...cc20338598)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-26 18:50:04 +01:00