Skip to content

Commit

Permalink
update dependencies in workflow pipelines
Browse files Browse the repository at this point in the history
  • Loading branch information
jgadsden authored Jan 16, 2025
2 parents 14074e8 + 7c879e3 commit 4b7f55a
Show file tree
Hide file tree
Showing 6 changed files with 39 additions and 39 deletions.
8 changes: 4 additions & 4 deletions .github/workflows/housekeeping.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ jobs:
output: 'trivy-results.sarif'

- name: Upload scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3.27.0
uses: github/codeql-action/upload-sarif@v3.28.1
with:
sarif_file: 'trivy-results.sarif'

Expand All @@ -94,7 +94,7 @@ jobs:
ref: main

- name: Initialize CodeQL
uses: github/codeql-action/init@v3.27.0
uses: github/codeql-action/init@v3.28.1
with:
languages: 'javascript'
config-file: ./.github/codeql/codeql-config.yml
Expand All @@ -103,10 +103,10 @@ jobs:
# Prefix the list here with "+" to use these queries and those in the config file.

- name: CodeQL autobuild
uses: github/codeql-action/autobuild@v3.27.0
uses: github/codeql-action/autobuild@v3.28.1

- name: Perform vulnerability analysis
uses: github/codeql-action/analyze@v3.27.0
uses: github/codeql-action/analyze@v3.28.1

link_checker:
name: Link checker
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/pull_request.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -135,7 +135,7 @@ jobs:
uses: actions/[email protected]

- name: Initialize CodeQL
uses: github/codeql-action/init@v3.27.0
uses: github/codeql-action/init@v3.28.1
with:
languages: 'javascript'
config-file: ./.github/codeql/codeql-config.yml
Expand All @@ -144,10 +144,10 @@ jobs:
# Prefix the list here with "+" to use these queries and those in the config file.

- name: CodeQL autobuild
uses: github/codeql-action/autobuild@v3.27.0
uses: github/codeql-action/autobuild@v3.28.1

- name: Perform vulnerability analysis
uses: github/codeql-action/analyze@v3.27.0
uses: github/codeql-action/analyze@v3.28.1

e2e_smokes:
name: Local site e2e smokes
Expand Down Expand Up @@ -184,7 +184,7 @@ jobs:
npm run test:e2e-pr-smokes
- name: Upload e2e videos
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: e2e_vids.zip
path: td.vue/tests/e2e/videos
Expand Down Expand Up @@ -224,7 +224,7 @@ jobs:
npm run test:e2e-pr
- name: Upload e2e videos
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: e2e_vids.zip
path: td.vue/tests/e2e/videos
Expand Down Expand Up @@ -296,7 +296,7 @@ jobs:
- name: Build for amd64
id: docker_build
uses: docker/build-push-action@v6.10.0
uses: docker/build-push-action@v6.11.0
with:
context: ./
file: ./Dockerfile
Expand All @@ -309,7 +309,7 @@ jobs:
load: true

- name: Upload docker local image
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: ${{ env.IMAGE_NAME }}
path: /tmp/${{ env.IMAGE_NAME }}.tar
Expand Down
32 changes: 16 additions & 16 deletions .github/workflows/push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ jobs:
run: npm run make-sbom

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-server
path: './td.server/sbom.*'
Expand Down Expand Up @@ -143,7 +143,7 @@ jobs:
uses: actions/[email protected]

- name: Initialize CodeQL
uses: github/codeql-action/init@v3.27.0
uses: github/codeql-action/init@v3.28.1
with:
languages: 'javascript'
config-file: ./.github/codeql/codeql-config.yml
Expand All @@ -152,10 +152,10 @@ jobs:
# Prefix the list here with "+" to use these queries and those in the config file.

- name: CodeQL autobuild
uses: github/codeql-action/autobuild@v3.27.0
uses: github/codeql-action/autobuild@v3.28.1

- name: Perform vulnerability analysis
uses: github/codeql-action/analyze@v3.27.0
uses: github/codeql-action/analyze@v3.28.1

build_docker_image:
name: Build latest docker
Expand All @@ -168,7 +168,7 @@ jobs:
uses: actions/[email protected]

- name: Set up QEMU
uses: docker/setup-qemu-action@v3.2.0
uses: docker/setup-qemu-action@v3.3.0

- name: Set up Docker Buildx
id: buildx
Expand All @@ -194,7 +194,7 @@ jobs:
# platform manifests not (yet) supported, so split out architectures
- name: Build for amd64 and push latest
id: docker_build_amd64
uses: docker/build-push-action@v6.10.0
uses: docker/build-push-action@v6.11.0
with:
context: ./
file: ./Dockerfile
Expand All @@ -208,7 +208,7 @@ jobs:

- name: Build for arm64 and push latest-arm64
id: docker_build_arm64
uses: docker/build-push-action@v6.10.0
uses: docker/build-push-action@v6.11.0
with:
context: ./
file: ./Dockerfile
Expand All @@ -226,7 +226,7 @@ jobs:
IMAGE_ID: ${{ steps.docker_build_amd64.outputs.imageid }}

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-container-image-app
path: './boms/*'
Expand Down Expand Up @@ -340,7 +340,7 @@ jobs:
run: npm run test:e2e-ci-smokes

- name: Upload e2e videos
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: e2e_vids.zip
path: td.vue/tests/e2e/videos
Expand Down Expand Up @@ -392,7 +392,7 @@ jobs:
run: npm run test:e2e-ci

- name: Upload e2e videos
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: e2e_vids.zip
path: td.vue/tests/e2e/videos
Expand Down Expand Up @@ -453,7 +453,7 @@ jobs:
output: 'trivy-results.sarif'

- name: Upload scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3.27.0
uses: github/codeql-action/upload-sarif@v3.28.1
with:
sarif_file: 'trivy-results.sarif'

Expand Down Expand Up @@ -490,7 +490,7 @@ jobs:
run: npm run build:desktop -- --windows --publish never

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-windows-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -532,7 +532,7 @@ jobs:
run: npm run build:desktop -- --mac --publish never

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-macos-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -579,7 +579,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-linux-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -626,7 +626,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-linux-snap-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -666,7 +666,7 @@ jobs:
cp raw/sboms-desktop-linux-snap-site/bom.xml sboms/threat-dragon-desktop-linux-snap-site-bom.xml
cp raw/sboms-container-image-app/* sboms/threat-dragon-container-image/app/
- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms
path: 'sboms/'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-snap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-linux-snap-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-windows.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ jobs:
run: npm run build:desktop -- --windows --publish always

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-windows-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down
20 changes: 10 additions & 10 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ jobs:
run: npm run make-sbom

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-server
path: './td.server/sbom.*'
Expand Down Expand Up @@ -164,7 +164,7 @@ jobs:
run: npm run build:desktop -- --windows --publish always

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-windows-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -227,7 +227,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-macos-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -277,7 +277,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-linux-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand Down Expand Up @@ -333,7 +333,7 @@ jobs:
run: find . -name "*.log" -exec cat '{}' \; -print

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-desktop-linux-snap-site
path: './td.vue/dist-desktop/bundled/.sbom/*'
Expand All @@ -350,7 +350,7 @@ jobs:
uses: actions/[email protected]

- name: Set up QEMU
uses: docker/setup-qemu-action@v3.2.0
uses: docker/setup-qemu-action@v3.3.0

- name: Set up Docker Buildx
id: buildx
Expand All @@ -376,7 +376,7 @@ jobs:
# platform manifests not (yet) supported, so split out architectures
- name: Build for amd64 and push to Docker Hub
id: docker_build_amd64
uses: docker/build-push-action@v6.10.0
uses: docker/build-push-action@v6.11.0
with:
context: ./
file: ./Dockerfile
Expand All @@ -390,7 +390,7 @@ jobs:

- name: Build for arm64 and push to Docker Hub
id: docker_build_arm64
uses: docker/build-push-action@v6.10.0
uses: docker/build-push-action@v6.11.0
with:
context: ./
file: ./Dockerfile
Expand All @@ -408,7 +408,7 @@ jobs:
IMAGE_ID: ${{ steps.docker_build_amd64.outputs.imageid }}

- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms-container-image-app
path: './boms/*'
Expand Down Expand Up @@ -456,7 +456,7 @@ jobs:
cp raw/sboms-desktop-linux-snap-site/bom.xml sboms/threat-dragon-desktop-linux-snap-site-bom.xml
cp raw/sboms-container-image-app/* sboms/threat-dragon-container-image/app/
- name: Save SBOM artifact
uses: actions/upload-artifact@v4.5.0
uses: actions/upload-artifact@v4.6.0
with:
name: sboms
path: 'sboms/'
Expand Down

0 comments on commit 4b7f55a

Please sign in to comment.