chore(deps): bump actions/upload-artifact from 6 to 7 in /.github/actions/scan-image#5805
Conversation
|
@dependabot rebase |
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v6...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
9758b3e to
35e4598
Compare
|
@dependabot rebase |
|
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
|
Closing in favor of a combined PR with all remaining GitHub Actions bumps. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
- actions/upload-artifact v6 → v7 - actions/download-artifact v7 → v8 - actions/cache v4 → v5 - goreleaser/goreleaser-action v6 → v7 - chainguard-images/actions v1.0.16 → v1.0.20 - chainguard-dev/actions v1.5.6 → v1.6.4 Replaces individual Dependabot PRs: #5805, #5803, #5802, #5799, #5798, #5797, #5796, #5718 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
Combined into #5825. |
* chore(deps): bump GitHub Actions dependencies - actions/upload-artifact v6 → v7 - actions/download-artifact v7 → v8 - actions/cache v4 → v5 - goreleaser/goreleaser-action v6 → v7 - chainguard-images/actions v1.0.16 → v1.0.20 - chainguard-dev/actions v1.5.6 → v1.6.4 Replaces individual Dependabot PRs: #5805, #5803, #5802, #5799, #5798, #5797, #5796, #5718 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: trigger fresh CI run * fix: bump chainguard-dev/actions to v1.6.10 v1.6.4 fails on arm64 runners due to missing AppArmor directory. Bumping to latest v1.6.10 which may resolve the issue. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: use chainguard-dev/actions v1.5.16 instead of v1.6.x v1.6.x requires AppArmor which is not available on the arm64 self-hosted runners. Staying on latest v1.5.x (v1.5.16) until the runner environment supports AppArmor. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * revert: keep chainguard-dev/actions at v1.5.6 and chainguard-images/actions at v1.0.16 The newer versions require AppArmor which is not available on the arm64 self-hosted runners. These bumps need to be handled separately with runner environment changes. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: remove duplicate SARIF uploads in alpha workflow The scan-image action already uploads SARIF with a consistent category (image-scan-<image-name>). The duplicate upload-sarif steps in alpha.yaml uploaded the same results without a category, creating a separate set of code scanning alerts that never got replaced by newer scans — causing stale CVE alerts to persist on the security page even after images were rebuilt with patched packages. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Revert "fix: remove duplicate SARIF uploads in alpha workflow" This reverts commit f194234. --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Bumps actions/upload-artifact from 6 to 7.
Release notes
Sourced from actions/upload-artifact's releases.
Commits
bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)