2c411fac98
Bump github/codeql-action in the github-actions group ( #10527 )
...
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Bumps the github-actions group with 1 update: [github/codeql-action](https://github.com/github/codeql-action ).
Updates `github/codeql-action` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4.37.9...v4.38.0 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 13:50:37 -04:00
Shubham Pampattiwar
3191e38ac3
Set least-privilege GITHUB_TOKEN permissions in workflows
...
Add an explicit top-level permissions block to the GitHub Actions
workflows that were relying on the default token permissions. Each
workflow now defaults to contents: read, with additional scopes granted
only where a job needs them:
* nightly-trivy-scan keeps security-events: write at the job level to
upload SARIF results, plus contents: read for checkout.
* stale-issues gets issues: write and pull-requests: write for the
actions/stale action to label and close stale items.
Setting least-privilege permissions reduces the blast radius if a
workflow or one of its dependencies is compromised, and satisfies the
CLOMonitor token_permissions check.
Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com >
2026-09-03 10:14:23 -07:00
dependabot[bot] and GitHub
023d5ad471
Bump the github-actions group with 2 updates
...
Bumps the github-actions group with 2 updates: [helm/kind-action](https://github.com/helm/kind-action ) and [github/codeql-action](https://github.com/github/codeql-action ).
Updates `helm/kind-action` from 7a97ed793754775518f9db3a8151ee7461dc9c31 to c72b4750145dbfb1c71734c3782a4db35a1c65c0
- [Release notes](https://github.com/helm/kind-action/releases )
- [Commits](https://github.com/helm/kind-action/compare/7a97ed793754775518f9db3a8151ee7461dc9c31...c72b4750145dbfb1c71734c3782a4db35a1c65c0 )
Updates `github/codeql-action` from 4.37.7 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4.37.7...v4.37.9 )
---
updated-dependencies:
- dependency-name: helm/kind-action
dependency-version: c72b4750145dbfb1c71734c3782a4db35a1c65c0
dependency-type: direct:production
dependency-group: github-actions
- dependency-name: github/codeql-action
dependency-version: 4.37.9
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-29 19:15:03 +00:00
f902e09050
Bump github/codeql-action in the github-actions group ( #10366 )
...
Run the E2E test on kind / setup-test-matrix (push) Successful in 4s
e2e-test-kind.yaml / extract (push) Failing after 11s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 9s
Main CI / Build (push) Skipped
Bumps the github-actions group with 1 update: [github/codeql-action](https://github.com/github/codeql-action ).
Updates `github/codeql-action` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4.37.6...v4.37.7 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-24 15:43:13 -04:00
476a7ca160
Bump github/codeql-action from 4.37.3 to 4.37.6 ( #10203 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 4.37.3 to 4.37.6.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4.37.3...v4.37.6 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 16:01:37 -04:00
Xun Jiang/Bruce Jiang and GitHub
9b34594cd3
Merge pull request #10133 from velero-io/dependabot/github_actions/actions/checkout-7
...
Bump actions/checkout from 6 to 7
2026-08-04 16:44:50 +08:00
b74f8c9511
Bump github/codeql-action from 3 to 4.37.3 ( #10135 )
...
e2e-test-kind.yaml / extract (push) Failing after 11s
Run the E2E test on kind / get-go-version (push) Failing after 13s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Successful in 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Successful in 13s
Main CI / get-go-version (push) Successful in 13s
Main CI / Build (push) Failing after 21s
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v3...v4.37.3 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 13:37:25 -04:00
dependabot[bot] and GitHub
c9f784ef66
Bump actions/checkout from 6 to 7
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases )
- [Commits](https://github.com/actions/checkout/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-01 19:12:21 +00:00
dependabot[bot] and GitHub
26af4e0e9f
Bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.35.0 to 0.36.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/57a97c7e7821a5776cebc9bb87c984fa69cba8f1...ed142fd0673e97e23eac54620cfb913e5ce36c25 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-18 19:12:18 +00:00
Xun Jiang
91922103b4
Update the trivy-action version from main to specific tag to fix supply chain attack
...
https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com >
2026-03-27 16:09:53 +08:00
dependabot[bot] and GitHub
981b29b4cb
Bump actions/checkout from 5 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 19:25:51 +00:00
dependabot[bot] and GitHub
c14d564e24
Bump actions/checkout from 4 to 5
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-12 04:06:54 +00:00
Xun Jiang/Bruce Jiang and GitHub
2ae9d6fe2f
Update the nightly trivy scan targets. ( #8833 )
...
Remove the velero-restore-helper.
Add AWS, GCP, and Azure plugins.
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com >
2025-04-04 00:06:59 -04:00
qiuming and GitHub
e7a9d2e457
Merge pull request #7723 from vmware-tanzu/dependabot/github_actions/actions/checkout-4
...
Bump actions/checkout from 2 to 4
2024-04-23 14:55:13 +08:00
dependabot[bot] and GitHub
eed655dddd
Bump actions/checkout from 2 to 4
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 2 to 4.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2...v4 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-04-22 19:38:20 +00:00
dependabot[bot] and GitHub
8c7f759002
Bump github/codeql-action from 2 to 3
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 2 to 3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-04-22 19:38:14 +00:00
Xun Jiang
6a295cb0bb
Update HorizontalPodAutoscaler version in velero.io
...
Signed-off-by: Xun Jiang <blackpiglet@gmail.com >
2023-03-08 10:32:44 +08:00
Xun Jiang
0a2aed8967
Fix Dependabot alerts. Update Dockerfile. Modify Trivy daily scan.
...
Signed-off-by: Xun Jiang <blackpiglet@gmail.com >
2023-02-23 14:04:59 +08:00
Xun Jiang
b10503b351
Add Trivy nightly scan.
...
Signed-off-by: Xun Jiang <blackpiglet@gmail.com >
2023-01-05 20:06:21 +08:00