Christoph Wille
|
3a809d7b53
|
Update Scorecard actions versions and apply Zizmor offline findings (#3365)
* Update scorecard.yml actions versions
* Zizmor offline analysis findings
|
6 months ago |
Christoph Wille
|
6215747563
|
Principle of least privilege for workflow tokens (#3360)
|
7 months ago |
Christoph Wille
|
e315e929dd
|
CycloneDX: fix --output path setting
|
1 year ago |
dependabot[bot]
|
5a6f9b88a5
|
Bump actions/upload-artifact from 3 to 4 (#3146)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 3 to 4.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v3...v4)
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2 years ago |
Siegfried Pammer
|
d2bf239e40
|
Revert "Bump actions/upload-artifact from 3 to 4 (#3140)" (#3144)
This reverts commit 82ce3da4c9 .
|
2 years ago |
dependabot[bot]
|
82ce3da4c9
|
Bump actions/upload-artifact from 3 to 4 (#3140)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 3 to 4.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v3...v4)
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2 years ago |
dependabot[bot]
|
25e3ca48db
|
Bump actions/checkout from 3 to 4 (#3077)
Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v3...v4)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
2 years ago |
dependabot[bot]
|
0c7b24e964
|
Bump actions/upload-artifact from 2 to 3 (#2738)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 2 to 3.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v2...v3)
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
3 years ago |
dependabot[bot]
|
ea21e2b8e2
|
Bump actions/checkout from 2 to 3 (#2740)
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...v3)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
3 years ago |
Christoph Wille
|
de350f19dd
|
Switch action to Windows machine
|
3 years ago |
Christoph Wille
|
f5269769be
|
CycloneDX BOM generation
|
3 years ago |