Bump the github-actions-version-updates group across 1 directory with 4 updates
Type: Pull Request
State: Open
Association: Unknown
Comments: 2
(about 1 month ago)
(about 1 month ago)
dependencies github_actions
Bumps the github-actions-version-updates group with 4 updates in the /.github/workflows directory: oven-sh/setup-bun, oxsecurity/megalinter, github/codeql-action and docker/setup-buildx-action.
Updates oven-sh/setup-bun from 2.0.2 to 2.1.0
Release notes
Sourced from oven-sh/setup-bun's releases.
v2.1.0
oven-sh/setup-bunis the github action for setting up Bun.What's Changed
- chore: add settings for vscode by
@okineadevin oven-sh/setup-bun#120- feat: support for multiple registries by
@xhyromin oven-sh/setup-bun#109- feat: read engines from package json by
@xhyromin oven-sh/setup-bun#132- ci: disable tests with version selectors by
@xhyromin oven-sh/setup-bun#133- chore(ci): Pin GitHub Actions to SHA-1s by
@dgilmanuniin oven-sh/setup-bun#140- feat: Check for existing bun before downloading by
@erikaxelin oven-sh/setup-bun#138- docs: restore missing
no-cacheinput by@bashonlyin oven-sh/setup-bun#149- release: v2.1.0 by
@xhyromin oven-sh/setup-bun#151New Contributors
@dgilmanunimade their first contribution in oven-sh/setup-bun#140@erikaxelmade their first contribution in oven-sh/setup-bun#138@bashonlymade their first contribution in oven-sh/setup-bun#149Full Changelog: https://github.com/oven-sh/setup-bun/compare/v2...v2.1.0
Commits
b7a1c7crelease: v2.1.0 (#151)ad1208bdocs: restore missingno-cacheinput (#149)bc6f04c[autofix.ci] apply automated fixes1dbab06feat: Check for existing bun before downloading (#138)6356405chore(ci): Pin GitHub Actions to SHA-1s (#140)22457c8docs: remove unnecessary note237a6a7[autofix.ci] apply automated fixes53e6487ci(format): use bun68643eaci: disable tests with version selectors (#133)56169abfeat: read engines from package json (#132)- Additional commits viewable in compare view
Updates oxsecurity/megalinter from 9.2.0 to 9.3.0
Release notes
Sourced from oxsecurity/megalinter's releases.
v9.3.0
What's Changed
Core
- Add enum name support in MegaLinter config Json schema for better autocompletion in editors
- Update base image to python:3.13-alpine3.23
New linters
- Add codespell
- Add kingfisher by
@bdovaz- Add rumdl by
@bdovazLinters enhancements
- Change checkmake Docker image reference by
@bdovazReporters
- Handle multiple MegaLinter runs on the same repo using custom value sent in variable MEGALINTER_MULTIRUN_KEY
- Allow to override url to CI build in Git based reporters using REPORTERS_ACTION_RUN_URL variable
- Fix sections display in Gitlab console logs
Doc
- Classify all JSON schema config variables by category and section
CI
- Free disk space on GitHub actions runner when releasing a new flavor
- Add missing Dockerfile patterns to Renovate Dockerfile manager
- Remove gitpod custom image, workflow, and makefile targets
Linter versions upgrades (54)
- actionlint from 1.7.9 to 1.7.10
- ansible-lint from 25.11.1 to 25.12.2
- bash-exec from 5.2.37 to 5.3.3
- black from 25.11.0 to 25.12.0
- cfn-lint from 1.41.0 to 1.43.1
- checkov from 3.2.495 to 3.2.497
- clang-format from 20.1.8 to 21.1.2
- clippy from 0.1.91 to 0.1.92
- clj-kondo from 2025.10.23 to 2025.12.23
- code-analyzer-apex from 5.6.1 to 5.7.1
- code-analyzer-aura from 5.6.1 to 5.7.1
- code-analyzer-lwc from 5.6.1 to 5.7.1
- cppcheck from 2.14.2 to 2.18.3
- csharpier from 1.2.1 to 1.2.5
- cspell from 9.3.2 to 9.4.0
- dartanalyzer from 3.8.3 to 3.10.7
- dotnet-format from 9.0.111 to 9.0.112
- git_diff from 2.49.1 to 2.52.0
- golangci-lint from 2.6.2 to 2.7.2
- grype from 0.104.1 to 0.104.3
- helm from 3.18.4 to 3.19.0
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[Unreleased] (beta, main branch content)
Note: Can be used with
oxsecurity/megalinter@betain your GitHub Action mega-linter.yml file, or withoxsecurity/megalinter:betadocker image
Core
- Add support for SSH remote origins when building custom flavors (fixes: #6511)
New linters
Disabled linters
Deprecated linters
Removed linters
Media
Linters enhancements
Fixes
Reporters
Doc
Flavors
CI
mega-linter-runner
Linter versions upgrades (N)
- code-analyzer-apex from 5.7.1 to 5.8.0 on 2026-01-05
- code-analyzer-aura from 5.7.1 to 5.8.0 on 2026-01-05
- code-analyzer-lwc from 5.7.1 to 5.8.0 on 2026-01-05
- cfn-lint from 1.43.1 to 1.43.2 on 2026-01-05
- rumdl from 0.0.208 to 0.0.210 on 2026-01-05
[v9.3.0] - 2026-01-04
- Core
- Add enum name support in MegaLinter config Json schema for better autocompletion in editors
- Update base image to python:3.13-alpine3.23
... (truncated)
Commits
42bb470Release MegaLinter v9.3.0fe74938changelogedb083a[automation] Auto-update linters version, help and documentation (#6889)824240cJSON Schema fix (#6888)9af8d5bchore(deps): update dependency npm-package-json-lint to v9.1.0 (#6883)781c95c[automation] Auto-update linters version, help and documentation (#6885)101b802JSON Schema (#6887)3ab7a93chore(deps): update dependency friendsofphp/php-cs-fixer to v3.92.4 (#6886)12f7c03chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.9.21 (#6882)91a9dfbchore(deps): update dependency sfdx-hardis to v6.20.0 (#6884)- Additional commits viewable in compare view
Updates github/codeql-action from 4.31.8 to 4.31.9
Release notes
Sourced from github/codeql-action's releases.
v4.31.9
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.9 - 16 Dec 2025
No user facing changes.
See the full CHANGELOG.md for more information.
Changelog
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.31.9 - 16 Dec 2025
No user facing changes.
4.31.8 - 11 Dec 2025
- Update default CodeQL bundle version to 2.23.8. #3354
4.31.7 - 05 Dec 2025
- Update default CodeQL bundle version to 2.23.7. #3343
4.31.6 - 01 Dec 2025
No user facing changes.
4.31.5 - 24 Nov 2025
- Update default CodeQL bundle version to 2.23.6. #3321
4.31.4 - 18 Nov 2025
No user facing changes.
4.31.3 - 13 Nov 2025
- CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
- Update default CodeQL bundle version to 2.23.5. #3288
4.31.2 - 30 Oct 2025
No user facing changes.
4.31.1 - 30 Oct 2025
- The
add-snippetsinput has been removed from theanalyzeaction. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.4.31.0 - 24 Oct 2025
- Bump minimum CodeQL bundle version to 2.17.6. #3223
- When SARIF files are uploaded by the
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #3222
... (truncated)
Commits
5d4e8d1Merge pull request #3371 from github/update-v4.31.9-998798e341dc115fUpdate changelog for v4.31.9998798eMerge pull request #3352 from github/nickrolfe/jar-min-ff-cleanup5eb7519Merge pull request #3358 from github/henrymercer/database-upload-telemetryd29eddbExtract version number to constante962687Merge branch 'main' into henrymercer/database-upload-telemetry19c7f96RenameisOverlayBaseae5de9aUsegetErrorMessagein log too0cb8633Preferperformance.now()c07cc0dMerge pull request #3351 from github/henrymercer/ghec-dr-determine-tools-vers...- Additional commits viewable in compare view
Updates docker/setup-buildx-action from 3.11.1 to 3.12.0
Release notes
Sourced from docker/setup-buildx-action's releases.
v3.12.0
- Deprecate
installinput by@crazy-maxin docker/setup-buildx-action#455- Bump
@docker/actions-toolkitfrom 0.62.1 to 0.63.0 in docker/setup-buildx-action#434- Bump brace-expansion from 1.1.11 to 1.1.12 in docker/setup-buildx-action#436
- Bump form-data from 2.5.1 to 2.5.5 in docker/setup-buildx-action#432
- Bump undici from 5.28.4 to 5.29.0 in docker/setup-buildx-action#435
Full Changelog: https://github.com/docker/setup-buildx-action/compare/v3.11.1...v3.12.0
Commits
8d2750cMerge pull request #455 from crazy-max/install-deprecatede81846bdeprecate install input65d18f8Merge pull request #454 from docker/dependabot/github_actions/actions/checkout-6000d75dbuild(deps): bump actions/checkout from 5 to 61583c0fMerge pull request #443 from nicolasleger/patch-1ed158e7doc: bump actions/checkout from 4 to 54cc794fMerge pull request #441 from docker/dependabot/github_actions/actions/checkout-54dfc3d6build(deps): bump actions/checkout from 4 to 5af1b253Merge pull request #440 from crazy-max/k3s-build3c6ab92ci: k3s test with latest buildx- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
Package Dependencies
docker/setup-buildx-action
actions
3.11.1 → 3.12.0
Minor
Technical Details
| ID: | 12564744 |
| UUID: | 3784346554 |
| Node ID: | PR_kwDOBM-Q_c67rhmN |
| Host: | GitHub |
| Repository: | secureCodeBox/secureCodeBox |