Skip to content

Commit 69bcebd

Browse files
chore(deps): update github actions (#13070)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 82d2ac6 commit 69bcebd

8 files changed

+15
-15
lines changed

.github/workflows/build-common.yml

+5-5
Original file line numberDiff line numberDiff line change
@@ -177,7 +177,7 @@ jobs:
177177
fi
178178
179179
- name: Upload agent jar
180-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
180+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
181181
with:
182182
name: opentelemetry-javaagent.jar
183183
path: javaagent/build/libs/opentelemetry-javaagent-*-SNAPSHOT.jar
@@ -188,7 +188,7 @@ jobs:
188188
mkdir sboms
189189
cp javaagent/build/spdx/*.spdx.json sboms
190190
191-
- uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
191+
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
192192
name: Upload SBOMs
193193
with:
194194
name: opentelemetry-java-instrumentation-SBOM.zip
@@ -292,15 +292,15 @@ jobs:
292292

293293
- name: Upload deadlock detector artifacts if any
294294
if: failure()
295-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
295+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
296296
with:
297297
name: deadlock-detector-test-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
298298
path: /tmp/deadlock-detector-*
299299
if-no-files-found: ignore
300300

301301
- name: Upload jvm crash dump files if any
302302
if: failure()
303-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
303+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
304304
with:
305305
name: javacore-test-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
306306
path: |
@@ -365,7 +365,7 @@ jobs:
365365

366366
- name: Upload jvm crash dump files if any
367367
if: failure()
368-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
368+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
369369
with:
370370
name: javacore-smoke-test-${{ matrix.smoke-test-suite }}-${{ matrix.os }}
371371
# we expect crash dumps either in root director or in smoke-tests

.github/workflows/codeql-daily.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ jobs:
3030
java-version-file: .java-version
3131

3232
- name: Initialize CodeQL
33-
uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
33+
uses: github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
3434
with:
3535
languages: java
3636
# using "latest" helps to keep up with the latest Kotlin support
@@ -45,7 +45,7 @@ jobs:
4545
run: ./gradlew assemble -x javadoc --no-build-cache --no-daemon
4646

4747
- name: Perform CodeQL analysis
48-
uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
48+
uses: github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
4949

5050
workflow-notification:
5151
needs:

.github/workflows/owasp-dependency-check-daily.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ jobs:
3636

3737
- name: Upload report
3838
if: always()
39-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
39+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
4040
with:
4141
path: javaagent/build/reports
4242

.github/workflows/publish-petclinic-benchmark-image.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
run: echo "TS=$(date +'%Y%m%d%H%M%S')" >> $GITHUB_ENV
3030

3131
- name: Push to GitHub packages
32-
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0
32+
uses: docker/build-push-action@67a2d409c0a876cbe6b11854e3e25193efe4e62d # v6.12.0
3333
with:
3434
push: true
3535
file: benchmark-overhead/Dockerfile-petclinic-base

.github/workflows/release.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -115,7 +115,7 @@ jobs:
115115
cp javaagent/build/spdx/*.spdx.json sboms
116116
zip opentelemetry-java-instrumentation-SBOM.zip sboms/*
117117
118-
- uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
118+
- uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
119119
name: Upload SBOMs
120120
with:
121121
name: opentelemetry-java-instrumentation-SBOM

.github/workflows/reusable-native-tests.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1919
- id: read-java
2020
run: echo "version=$(cat .java-version)" >> "$GITHUB_OUTPUT"
21-
- uses: graalvm/setup-graalvm@4a200f28cd70d1940b5e33bd00830b7dc71a7e2b # v1.2.6.1
21+
- uses: graalvm/setup-graalvm@c09e29bb115a83bd4b7c7e99bb46e2e8a1c50466 # v1.2.7.1
2222
with:
2323
version: "latest"
2424
java-version: "${{ steps.read-java.outputs.version }}"

.github/workflows/reusable-test-latest-deps.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -87,15 +87,15 @@ jobs:
8787

8888
- name: Upload deadlock detector artifacts if any
8989
if: failure()
90-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
90+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
9191
with:
9292
name: deadlock-detector-test-latest-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
9393
path: /tmp/deadlock-detector-*
9494
if-no-files-found: ignore
9595

9696
- name: Upload jvm crash dump files if any
9797
if: failure()
98-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
98+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
9999
with:
100100
name: javacore-test-latest-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
101101
path: |

.github/workflows/scorecard.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -56,14 +56,14 @@ jobs:
5656
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
5757
# format to the repository Actions tab.
5858
- name: "Upload artifact"
59-
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
59+
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
6060
with:
6161
name: SARIF file
6262
path: results.sarif
6363
retention-days: 5
6464

6565
# Upload the results to GitHub's code scanning dashboard.
6666
- name: "Upload to code-scanning"
67-
uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
67+
uses: github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
6868
with:
6969
sarif_file: results.sarif

0 commit comments

Comments
 (0)