Bump the github-actions group with 3 updates (#10589)

Bumps the github-actions group with 3 updates: [korthout/backport-action](https://github.com/korthout/backport-action), [github/codeql-action](https://github.com/github/codeql-action) and [jpmcb/prow-github-actions](https://github.com/jpmcb/prow-github-actions).


Updates `korthout/backport-action` from 4.6.0 to 4.6.1
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](https://github.com/korthout/backport-action/compare/2e830a1d0b8269505846ddd407a70876913ad1f8...6b65649031ac6d18ffdfd0c0820e9436f3fde22b)

Updates `github/codeql-action` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.38.0...v4.38.1)

Updates `jpmcb/prow-github-actions` from 2.0.0 to 3.0.1
- [Release notes](https://github.com/jpmcb/prow-github-actions/releases)
- [Commits](https://github.com/jpmcb/prow-github-actions/compare/c44ac3a57d67639e39e4a4988b52049ef45b80dd...187c5e3cd95a329c43448e1bdb3b1f5249232e44)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: jpmcb/prow-github-actions
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
dependabot[bot]
2026-09-28 13:56:20 +08:00
committed by GitHub
co-authored by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
parent e2003dbf0d
commit 9ff78a5065
4 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -183,7 +183,7 @@ jobs:
- name: Create backport pull requests
id: backport
# Pin to commit SHA: workflow has contents/pull-requests write.
uses: korthout/backport-action@2e830a1d0b8269505846ddd407a70876913ad1f8 # v4.6.0
uses: korthout/backport-action@6b65649031ac6d18ffdfd0c0820e9436f3fde22b # v4.6.1
with:
# Labels like `backport release-1.17` select the target branch.
label_pattern: '^backport ([^ ]+)$'
+1 -1
View File
@@ -35,6 +35,6 @@ jobs:
output: 'trivy-results.sarif'
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v4.38.0
uses: github/codeql-action/upload-sarif@v4.38.1
with:
sarif_file: 'trivy-results.sarif'
+1 -1
View File
@@ -14,7 +14,7 @@ jobs:
if: github.repository == 'velero-io/velero'
runs-on: ubuntu-latest
steps:
- uses: jpmcb/prow-github-actions@c44ac3a57d67639e39e4a4988b52049ef45b80dd # v2.0.0
- uses: jpmcb/prow-github-actions@187c5e3cd95a329c43448e1bdb3b1f5249232e44 # v3.0.1
with:
# TODO: before allowing the /lgtm command, see if we can block merging if changelog labels are missing.
prow-commands: |
+1 -1
View File
@@ -51,6 +51,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@v4.38.0
uses: github/codeql-action/upload-sarif@v4.38.1
with:
sarif_file: results.sarif