From 36c183fc3807ec066ee0299aa63d7d31a3bc7855 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 7 Nov 2023 11:07:27 +0000 Subject: [PATCH] chore(deps): bump actions/checkout from 3 to 4 Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v3...v4) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/pr_and_main.yml | 8 ++++---- .github/workflows/publish.yml | 4 ++-- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/pr_and_main.yml b/.github/workflows/pr_and_main.yml index 8bbb2f3..c56319d 100644 --- a/.github/workflows/pr_and_main.yml +++ b/.github/workflows/pr_and_main.yml @@ -11,7 +11,7 @@ jobs: snyk_scan_deps_licences: runs-on: ubuntu-latest steps: - - uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Run Snyk to check for deps vulnerabilities uses: snyk/actions/gradle-jdk17@b98d498629f1c368650224d6d212bf7dfa89e4bf # v0.4.0 with: @@ -22,7 +22,7 @@ jobs: snyk_scan_code: runs-on: ubuntu-latest steps: - - uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Run Snyk to check for code vulnerabilities uses: snyk/actions/gradle-jdk17@b98d498629f1c368650224d6d212bf7dfa89e4bf # v0.4.0 with: @@ -37,7 +37,7 @@ jobs: - snyk_scan_deps_licences - snyk_scan_code steps: - - uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Generate SBOM # check SBOM can be generated but nothing is done with it uses: snyk/actions/gradle-jdk17@b98d498629f1c368650224d6d212bf7dfa89e4bf # v0.4.0 with: @@ -50,7 +50,7 @@ jobs: runs-on: ubuntu-latest if: github.event_name == 'push' && github.ref == 'refs/heads/main' steps: - - uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Enable Snyk online monitoring to check for vulnerabilities uses: snyk/actions/gradle-jdk17@b98d498629f1c368650224d6d212bf7dfa89e4bf # v0.4.0 with: diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d32490c..109508a 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -9,7 +9,7 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - uses: actions/setup-java@v3 with: java-version: '8' @@ -26,7 +26,7 @@ jobs: publish_sbom: runs-on: ubuntu-latest steps: - - uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b + - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Generate SBOM uses: snyk/actions/gradle-jdk17@b98d498629f1c368650224d6d212bf7dfa89e4bf # v0.4.0 with: