Skip to content

Commit 2dcf58d

Browse files
chore(deps): update github actions
1 parent 4426825 commit 2dcf58d

18 files changed

+39
-39
lines changed

.github/workflows/auto-update-otel-sdk.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ jobs:
7272
java-version-file: .java-version
7373

7474
- name: Setup Gradle
75-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
75+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
7676

7777
- name: Update license report
7878
run: ./gradlew generateLicenseReport

.github/workflows/build-common.yml

+13-13
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
java-version-file: .java-version
3939

4040
- name: Setup Gradle
41-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
41+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
4242
with:
4343
cache-read-only: ${{ inputs.cache-read-only }}
4444
# gradle enterprise is used for the build cache
@@ -54,7 +54,7 @@ jobs:
5454
steps:
5555
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
5656

57-
- uses: gradle/actions/wrapper-validation@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
57+
- uses: gradle/actions/wrapper-validation@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
5858

5959
license-check:
6060
runs-on: ubuntu-latest
@@ -71,7 +71,7 @@ jobs:
7171
java-version-file: .java-version
7272

7373
- name: Setup Gradle
74-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
74+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
7575
with:
7676
cache-read-only: ${{ inputs.cache-read-only }}
7777
# gradle enterprise is used for the build cache
@@ -144,7 +144,7 @@ jobs:
144144
sed -i "s/org.gradle.jvmargs=/org.gradle.jvmargs=-Xmx3g /" gradle.properties
145145
146146
- name: Setup Gradle
147-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
147+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
148148
with:
149149
cache-read-only: ${{ inputs.cache-read-only }}
150150
# gradle enterprise is used for the build cache
@@ -171,7 +171,7 @@ jobs:
171171
fi
172172
173173
- name: Upload agent jar
174-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
174+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
175175
with:
176176
name: opentelemetry-javaagent.jar
177177
path: javaagent/build/libs/opentelemetry-javaagent-*-SNAPSHOT.jar
@@ -182,7 +182,7 @@ jobs:
182182
mkdir sboms
183183
cp javaagent/build/spdx/*.spdx.json sboms
184184
185-
- uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
185+
- uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
186186
name: Upload SBOMs
187187
with:
188188
name: opentelemetry-java-instrumentation-SBOM.zip
@@ -249,7 +249,7 @@ jobs:
249249
run: .github/scripts/deadlock-detector.sh
250250

251251
- name: Setup Gradle
252-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
252+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
253253
with:
254254
# only push cache for one matrix option since github action cache space is limited
255255
cache-read-only: ${{ inputs.cache-read-only || matrix.test-java-version != 11 || matrix.vm != 'hotspot' }}
@@ -291,15 +291,15 @@ jobs:
291291

292292
- name: Upload deadlock detector artifacts if any
293293
if: failure()
294-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
294+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
295295
with:
296296
name: deadlock-detector-test-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
297297
path: /tmp/deadlock-detector-*
298298
if-no-files-found: ignore
299299

300300
- name: Upload jvm crash dump files if any
301301
if: failure()
302-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
302+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
303303
with:
304304
name: javacore-test-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
305305
path: |
@@ -348,7 +348,7 @@ jobs:
348348
java-version-file: .java-version
349349

350350
- name: Set up Gradle cache
351-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
351+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
352352
with:
353353
# only push cache for one matrix option per OS since github action cache space is limited
354354
cache-read-only: ${{ inputs.cache-read-only || matrix.smoke-test-suite != 'tomcat' }}
@@ -368,7 +368,7 @@ jobs:
368368

369369
- name: Upload jvm crash dump files if any
370370
if: failure()
371-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
371+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
372372
with:
373373
name: javacore-smoke-test-${{ matrix.smoke-test-suite }}-${{ matrix.os }}
374374
# we expect crash dumps either in root director or in smoke-tests
@@ -401,7 +401,7 @@ jobs:
401401
java-version-file: .java-version
402402

403403
- name: Setup Gradle
404-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
404+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
405405
with:
406406
cache-read-only: ${{ inputs.cache-read-only }}
407407

@@ -424,7 +424,7 @@ jobs:
424424
java-version-file: .java-version
425425

426426
- name: Set up Gradle cache
427-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
427+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
428428
with:
429429
cache-read-only: ${{ inputs.cache-read-only }}
430430

.github/workflows/build.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ jobs:
7373
java-version-file: .java-version
7474

7575
- name: Setup Gradle
76-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
76+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
7777
with:
7878
# gradle enterprise is used for the build cache
7979
gradle-home-cache-excludes: caches/build-cache-1

.github/workflows/codeql-daily.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -30,22 +30,22 @@ jobs:
3030
java-version-file: .java-version
3131

3232
- name: Initialize CodeQL
33-
uses: github/codeql-action/init@2c779ab0d087cd7fe7b826087247c2c81f27bfa6 # v3.26.5
33+
uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
3434
with:
3535
languages: java
3636
# using "latest" helps to keep up with the latest Kotlin support
3737
# see https://github.com/github/codeql-action/issues/1555#issuecomment-1452228433
3838
tools: latest
3939

4040
- name: Setup Gradle
41-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
41+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
4242

4343
- name: Build
4444
# skipping build cache is needed so that all modules will be analyzed
4545
run: ./gradlew assemble -x javadoc --no-build-cache --no-daemon
4646

4747
- name: Perform CodeQL analysis
48-
uses: github/codeql-action/analyze@2c779ab0d087cd7fe7b826087247c2c81f27bfa6 # v3.26.5
48+
uses: github/codeql-action/analyze@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
4949

5050
workflow-notification:
5151
needs:

.github/workflows/overhead-benchmark-daily.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
rsync -avv gh-pages/benchmark-overhead/results/ benchmark-overhead/results/
2525
2626
- name: Setup Gradle
27-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
27+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
2828

2929
- name: Run tests
3030
working-directory: benchmark-overhead

.github/workflows/owasp-dependency-check-daily.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -28,15 +28,15 @@ jobs:
2828
run: |
2929
sed -i "s/org.gradle.jvmargs=/org.gradle.jvmargs=-Xmx3g /" gradle.properties
3030
31-
- uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
31+
- uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
3232

3333
- run: ./gradlew :javaagent:dependencyCheckAnalyze
3434
env:
3535
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
3636

3737
- name: Upload report
3838
if: always()
39-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
39+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
4040
with:
4141
path: javaagent/build/reports
4242

.github/workflows/pr-smoke-test-early-jdk8-images.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
java-version-file: .java-version
2626

2727
- name: Setup Gradle
28-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
28+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
2929
with:
3030
cache-read-only: true
3131
# gradle enterprise is used for the build cache

.github/workflows/pr-smoke-test-fake-backend-images.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
java-version-file: .java-version
2626

2727
- name: Setup Gradle
28-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
28+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
2929
with:
3030
cache-read-only: true
3131
# gradle enterprise is used for the build cache
@@ -52,7 +52,7 @@ jobs:
5252
java-version-file: .java-version
5353

5454
- name: Setup Gradle
55-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
55+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
5656
with:
5757
cache-read-only: true
5858

.github/workflows/pr-smoke-test-servlet-images.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ jobs:
4343
java-version-file: .java-version
4444

4545
- name: Set up Gradle cache
46-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
46+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
4747
with:
4848
cache-read-only: true
4949

.github/workflows/publish-smoke-test-early-jdk8-images.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
3636

3737
- name: Setup Gradle
38-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
38+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
3939

4040
- name: Build Docker image
4141
run: ./gradlew :smoke-tests:images:early-jdk8:dockerPush -PextraTag=${{ env.TAG }}

.github/workflows/publish-smoke-test-fake-backend-images.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
3636

3737
- name: Setup Gradle
38-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
38+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
3939

4040
- name: Build Docker image
4141
run: ./gradlew :smoke-tests:images:fake-backend:jib -Djib.httpTimeout=120000 -Djib.console=plain -PextraTag=${{ env.TAG }}
@@ -68,7 +68,7 @@ jobs:
6868
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
6969

7070
- name: Setup Gradle
71-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
71+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
7272

7373
- name: Build Docker image
7474
run: ./gradlew :smoke-tests:images:fake-backend:dockerPush -PextraTag=${{ env.TAG }}

.github/workflows/publish-smoke-test-servlet-images.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ jobs:
6767
password: ${{ secrets.GITHUB_TOKEN }}
6868

6969
- name: Set up Gradle cache
70-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
70+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
7171
with:
7272
# only push cache for one matrix option per OS since github action cache space is limited
7373
cache-read-only: ${{ matrix.smoke-test-suite != 'tomcat' }}

.github/workflows/release.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
java-version-file: .java-version
8787

8888
- name: Setup Gradle
89-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
89+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
9090

9191
- name: Build and publish artifacts
9292
env:
@@ -114,7 +114,7 @@ jobs:
114114
cp javaagent/build/spdx/*.spdx.json sboms
115115
zip opentelemetry-java-instrumentation-SBOM.zip sboms/*
116116
117-
- uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
117+
- uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
118118
name: Upload SBOMs
119119
with:
120120
name: opentelemetry-java-instrumentation-SBOM

.github/workflows/reusable-muzzle.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
java-version-file: .java-version
3535

3636
- name: Setup Gradle
37-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
37+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
3838
with:
3939
cache-read-only: ${{ inputs.cache-read-only }}
4040

.github/workflows/reusable-smoke-test-images.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ jobs:
6161
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
6262

6363
- name: Set up Gradle cache
64-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
64+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
6565
with:
6666
cache-read-only: ${{ inputs.cache-read-only }}
6767

.github/workflows/reusable-test-indy.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ jobs:
5858
key: ${{ runner.os }}-test-latest-cache-pnpm-modules
5959

6060
- name: Setup Gradle
61-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
61+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
6262
with:
6363
cache-read-only: ${{ inputs.cache-read-only }}
6464
# gradle enterprise is used for the build cache

.github/workflows/reusable-test-latest-deps.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
run: .github/scripts/deadlock-detector.sh
5656

5757
- name: Setup Gradle
58-
uses: gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
58+
uses: gradle/actions/setup-gradle@16bf8bc8fe830fa669c3c9f914d3eb147c629707 # v4.0.1
5959
with:
6060
cache-read-only: ${{ inputs.cache-read-only }}
6161
# gradle enterprise is used for the build cache
@@ -90,15 +90,15 @@ jobs:
9090

9191
- name: Upload deadlock detector artifacts if any
9292
if: failure()
93-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
93+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
9494
with:
9595
name: deadlock-detector-test-latest-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
9696
path: /tmp/deadlock-detector-*
9797
if-no-files-found: ignore
9898

9999
- name: Upload jvm crash dump files if any
100100
if: failure()
101-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
101+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
102102
with:
103103
name: javacore-test-latest-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
104104
path: |

.github/workflows/scorecard.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -56,14 +56,14 @@ jobs:
5656
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
5757
# format to the repository Actions tab.
5858
- name: "Upload artifact"
59-
uses: actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a # v4.3.6
59+
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
6060
with:
6161
name: SARIF file
6262
path: results.sarif
6363
retention-days: 5
6464

6565
# Upload the results to GitHub's code scanning dashboard.
6666
- name: "Upload to code-scanning"
67-
uses: github/codeql-action/upload-sarif@2c779ab0d087cd7fe7b826087247c2c81f27bfa6 # v3.26.5
67+
uses: github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
6868
with:
6969
sarif_file: results.sarif

0 commit comments

Comments
 (0)