[v8](gha): Bump the dependencies group across 1 directory with 5 updates by dependabot[bot] · Pull Request #3571 · cloudfoundry/cli
Bumps the dependencies group with 5 updates in the / directory:
| Package | From | To |
|---|---|---|
| actions/checkout | 4 |
5 |
| google-github-actions/auth | 2 |
3 |
| google-github-actions/setup-gcloud | 2 |
3 |
| actions/setup-go | 5 |
6 |
| aws-actions/configure-aws-credentials | 4 |
5 |
Updates actions/checkout from 4 to 5
Release notes
Sourced from actions/checkout's releases.
v5.0.0
What's Changed
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226- Prepare v5.0.0 release by
@salmanmkcin actions/checkout#2238⚠️ Minimum Compatible Runner Version
v2.327.1
Release NotesMake sure your runner is updated to this version or newer to use this release.
Full Changelog: actions/checkout@v4...v5.0.0
v4.3.0
What's Changed
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236- Prepare release v4.3.0 by
@salmanmkcin actions/checkout#2237New Contributors
@motssmade their first contribution in actions/checkout#1971@mouismailmade their first contribution in actions/checkout#1977@benwellsmade their first contribution in actions/checkout#2043@nebuk89made their first contribution in actions/checkout#2194@salmanmkcmade their first contribution in actions/checkout#2236Full Changelog: actions/checkout@v4...v4.3.0
v4.2.2
What's Changed
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946Full Changelog: actions/checkout@v4.2.1...v4.2.2
v4.2.1
What's Changed
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924New Contributors
@Jcambassmade their first contribution in actions/checkout#1919Full Changelog: actions/checkout@v4.2.0...v4.2.1
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
Changelog
V5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226V4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924v4.2.0
- Add Ref and Commit outputs by
@lucacomein actions/checkout#1180- Dependency updates by
@dependabot- actions/checkout#1777, actions/checkout#1872v4.1.7
- Bump the minor-npm-dependencies group across 1 directory with 4 updates by
@dependabotin actions/checkout#1739- Bump actions/checkout from 3 to 4 by
@dependabotin actions/checkout#1697- Check out other refs/* by commit by
@orhantoyin actions/checkout#1774- Pin actions/checkout's own workflows to a known, good, stable version. by
@jww3in actions/checkout#1776v4.1.6
- Check platform to set archive extension appropriately by
@cory-millerin actions/checkout#1732v4.1.5
- Update NPM dependencies by
@cory-millerin actions/checkout#1703- Bump github/codeql-action from 2 to 3 by
@dependabotin actions/checkout#1694- Bump actions/setup-node from 1 to 4 by
@dependabotin actions/checkout#1696- Bump actions/upload-artifact from 2 to 4 by
@dependabotin actions/checkout#1695- README: Suggest
user.emailto be41898282+github-actions[bot]@users.noreply.github.comby@cory-millerin actions/checkout#1707v4.1.4
- Disable
extensions.worktreeConfigwhen disablingsparse-checkoutby@jww3in actions/checkout#1692- Add dependabot config by
@cory-millerin actions/checkout#1688- Bump the minor-actions-dependencies group with 2 updates by
@dependabotin actions/checkout#1693- Bump word-wrap from 1.2.3 to 1.2.5 by
@dependabotin actions/checkout#1643v4.1.3
... (truncated)
Commits
08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)- See full diff in compare view
Updates google-github-actions/auth from 2 to 3
Release notes
Sourced from google-github-actions/auth's releases.
v3
Floating v3 tag
v3.0.0
What's Changed
- Bump to Node 24 and remove old parameters by
@sethvargoin google-github-actions/auth#508- Remove hacky script by
@sethvargoin google-github-actions/auth#509- Release: v3.0.0 by
@google-github-actions-botin google-github-actions/auth#510Full Changelog: google-github-actions/auth@v2...v3.0.0
v2.1.13
What's Changed
- Update deps by
@sethvargoin google-github-actions/auth#506- Release: v2.1.13 by
@google-github-actions-botin google-github-actions/auth#507Full Changelog: google-github-actions/auth@v2.1.12...v2.1.13
v2.1.12
What's Changed
- Add retries for getIDToken by
@sethvargoin google-github-actions/auth#502- Release: v2.1.12 by
@google-github-actions-botin google-github-actions/auth#503Full Changelog: google-github-actions/auth@v2.1.11...v2.1.12
v2.1.11
What's Changed
- Update troubleshooting docs for Python by
@sethvargoin google-github-actions/auth#488- Add linters by
@sethvargoin google-github-actions/auth#499- Update deps by
@sethvargoin google-github-actions/auth#500- Release: v2.1.11 by
@google-github-actions-botin google-github-actions/auth#501Full Changelog: google-github-actions/auth@v2.1.10...v2.1.11
v2.1.10
What's Changed
- Declare workflow permissions by
@sethvargoin google-github-actions/auth#482- Document that the OIDC token expires in 5min by
@sethvargoin google-github-actions/auth#483- Release: v2.1.10 by
@google-github-actions-botin google-github-actions/auth#484Full Changelog: google-github-actions/auth@v2.1.9...v2.1.10
v2.1.9
What's Changed
- Use our custom boolean parsing by
@sethvargoin google-github-actions/auth#478
... (truncated)
Commits
Updates google-github-actions/setup-gcloud from 2 to 3
Release notes
Sourced from google-github-actions/setup-gcloud's releases.
v3
Floating v3 tag
v2.2.1
What's Changed
- Update deps by
@sethvargoin google-github-actions/setup-gcloud#720- Bump to the latest actions-utils to fix the gen-readme bug by
@sethvargoin google-github-actions/setup-gcloud#721- Release: v2.2.1 by
@google-github-actions-botin google-github-actions/setup-gcloud#722Full Changelog: google-github-actions/setup-gcloud@v2...v2.2.1
v2.2.0
What's Changed
- Introduce an option to skip the tool cache by
@sethvargoin google-github-actions/setup-gcloud#718- Release: v2.2.0 by
@google-github-actions-botin google-github-actions/setup-gcloud#719Full Changelog: google-github-actions/setup-gcloud@v2.1.5...v2.2.0
v2.1.5
What's Changed
- security: bump undici from 5.28.5 to 5.29.0 in the npm_and_yarn group by
@dependabot[bot] in google-github-actions/setup-gcloud#711- Update linters by
@sethvargoin google-github-actions/setup-gcloud#715- Update deps by
@sethvargoin google-github-actions/setup-gcloud#716- Release: v2.1.5 by
@google-github-actions-botin google-github-actions/setup-gcloud#717Full Changelog: google-github-actions/setup-gcloud@v2.1.4...v2.1.5
v2.1.4
What's Changed
- Revert to pinned release workflows by
@sethvargoin google-github-actions/setup-gcloud#706- Release: v2.1.4 by
@google-github-actions-botin google-github-actions/setup-gcloud#707Full Changelog: google-github-actions/setup-gcloud@v2.1.3...v2.1.4
v2.1.3
What's Changed
- Allow manually running integration tests with workflow_dispatch by
@sethvargoin google-github-actions/setup-gcloud#702- security: bump undici from 5.28.4 to 5.28.5 in the npm_and_yarn group by
@dependabotin google-github-actions/setup-gcloud#703- Update deps by
@sethvargoin google-github-actions/setup-gcloud#704- Release: v2.1.3 by
@google-github-actions-botin google-github-actions/setup-gcloud#705Full Changelog: google-github-actions/setup-gcloud@v2...v2.1.3
v2.1.2
What's Changed
... (truncated)
Commits
Updates actions/setup-go from 5 to 6
Release notes
Sourced from actions/setup-go's releases.
v6.0.0
What's Changed
Breaking Changes
- Improve toolchain handling to ensure more reliable and consistent toolchain selection and management by
@matthewhughes934in actions/setup-go#460- Upgrade Nodejs runtime from node20 to node 24 by
@salmanmkcin actions/setup-go#624Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes
Dependency Upgrades
- Upgrade
@types/jestfrom 29.5.12 to 29.5.14 by@dependabot[bot] in actions/setup-go#589- Upgrade
@actions/tool-cachefrom 2.0.1 to 2.0.2 by@dependabot[bot] in actions/setup-go#591- Upgrade
@typescript-eslint/parserfrom 8.31.1 to 8.35.1 by@dependabot[bot] in actions/setup-go#590- Upgrade undici from 5.28.5 to 5.29.0 by
@dependabot[bot] in actions/setup-go#594- Upgrade typescript from 5.4.2 to 5.8.3 by
@dependabot[bot] in actions/setup-go#538- Upgrade eslint-plugin-jest from 28.11.0 to 29.0.1 by
@dependabot[bot] in actions/setup-go#603- Upgrade
form-datato bring in fix for critical vulnerability by@matthewhughes934in actions/setup-go#618- Upgrade actions/checkout from 4 to 5 by
@dependabot[bot] in actions/setup-go#631New Contributors
@matthewhughes934made their first contribution in actions/setup-go#618@salmanmkcmade their first contribution in actions/setup-go#624Full Changelog: actions/setup-go@v5...v6.0.0
v5.5.0
What's Changed
Bug fixes:
- Update self-hosted environment validation by
@priyagupta108in actions/setup-go#556- Add manifest validation and improve error handling by
@priyagupta108in actions/setup-go#586- Update template link by
@jsorefin actions/setup-go#527Dependency updates:
- Upgrade
@action/cachefrom 4.0.2 to 4.0.3 by@aparnajyothi-yin actions/setup-go#574- Upgrade
@actions/globfrom 0.4.0 to 0.5.0 by@dependabotin actions/setup-go#573- Upgrade ts-jest from 29.1.2 to 29.3.2 by
@dependabotin actions/setup-go#582- Upgrade eslint-plugin-jest from 27.9.0 to 28.11.0 by
@dependabotin actions/setup-go#537New Contributors
@jsorefmade their first contribution in actions/setup-go#527Full Changelog: actions/setup-go@v5...v5.5.0
v5.4.0
What's Changed
Dependency updates :
- Upgrade semver from 7.6.0 to 7.6.3 by
@dependabotin actions/setup-go#535- Upgrade eslint-config-prettier from 8.10.0 to 10.0.1 by
@dependabotin actions/setup-go#536- Upgrade
@action/cachefrom 4.0.0 to 4.0.2 by@aparnajyothi-yin actions/setup-go#568- Upgrade undici from 5.28.4 to 5.28.5 by
@dependabotin actions/setup-go#541
... (truncated)
Commits
4469467Bump actions/checkout from 4 to 5 (#631)e093d1eNode 24 upgrade (#624)1d76b95Improve toolchain handling (#460)e75c3e8Bumpform-datato bring in fix for critical vulnerability (#618)8e57b58Bump eslint-plugin-jest from 28.11.0 to 29.0.1 (#603)7c0b336Bump typescript from 5.4.2 to 5.8.3 (#538)6f26dccBump undici from 5.28.5 to 5.29.0 (#594)8d4083aBump@typescript-eslint/parserfrom 5.62.0 to 8.32.0 (#590)fa96338Bump@actions/tool-cachefrom 2.0.1 to 2.0.2 (#591)4de67c0Bump@types/jestfrom 29.5.12 to 29.5.14 (#589)- See full diff in compare view
Updates aws-actions/configure-aws-credentials from 4 to 5
Release notes
Sourced from aws-actions/configure-aws-credentials's releases.
v5.0.0
5.0.0 (2025-09-03)
⚠ BREAKING CHANGES
- Cleanup input handling. Changes invalid boolean input behavior (see #1445)
Features
- add skip OIDC option (#1458) (8c45f6b)
- Cleanup input handling. Changes invalid boolean input behavior (see #1445) (74b3e27)
- support account id allowlist (#1456) (c4be498)
v4.3.1
4.3.1 (2025-08-04)
Bug Fixes
v4.3.0
4.3.0 (2025-08-04)
NOTE: This release tag originally pointed to 59b441846ad109fa4a1549b73ef4e149c4bfb53b, but a critical bug was discovered shortly after publishing. We updated this tag to d0834ad3a60a024346910e522a81b0002bd37fea to prevent anyone using the 4.3.0 tag from encountering the bug, and we published 4.3.1 to allow workflows to auto update correctly.
Features
- dependency update and feature cleanup (#1414) (59489ba), closes #1062 #1191
- Optional environment variable output (c3b3ce6)
Bug Fixes
- docs: readme samples versioning (5b3c895)
- the wrong example region for China partition in README (37fe9a7)
- properly set proxy environment variable (cbea708)
Miscellaneous Chores
- release 4.3.0 (3f7c218)
v4.2.1
4.2.1 (2025-05-14)
Bug Fixes
... (truncated)
Changelog
Sourced from aws-actions/configure-aws-credentials's changelog.
4.3.1 (2025-08-04)
Bug Fixes
4.3.0 (2025-08-04)
Features
- depenency update and feature cleanup (#1414) (59489ba), closes #1062 #1191
- Optional environment variable output (c3b3ce6)
Bug Fixes
- docs: readme samples versioning (5b3c895)
- the wrong example region for China partition in README (37fe9a7)
- properly set proxy environment variable (cbea708)
Miscellaneous Chores
- release 4.3.0 (3f7c218)
4.2.1 (2025-05-14)
Bug Fixes
- ensure explicit inputs take precedence over environment variables (e56e6c4)
- prioritize explicit inputs over environment variables (df9c8fe)
4.2.0 (2025-05-06)
Features
- add Expiration field to Outputs (a4f3267)
- Document role-duration-seconds range (5a0cf01)
- support action inputs as environment variables (#1338) (2c168ad)
Bug Fixes
... (truncated)
Commits
a03048dchore(main): release 5.0.0 (#1451)337f510chore: Fix markdown link formatting in README.md (#1466)f001d79chore: update README with versioning (#1465)cf5f2acchore: Update distb394bddchore(deps-dev): bump@aws-sdk/credential-provider-env(#1463)b632c0bchore(deps-dev): bump memfs from 4.38.1 to 4.38.2 (#1462)978e44achore: Update distc4be498feat: support account id allowlist (#1456)c5a43c3chore: Update dist8c45f6bfeat: add skip OIDC option (#1458)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions