-
Notifications
You must be signed in to change notification settings - Fork 3
chore(deps): update github-actions (master) #231
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/master-github-actions
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
❌MegaLinter analysis: Error
Detailed Issues❌ REPOSITORY / trivy - 1 error
|
Code Coverage Report
|
8b120e9 to
6647d9b
Compare
b9cd97b to
7a77ced
Compare
0bae9a1 to
c796db8
Compare
1276a06 to
779b884
Compare
784ac95 to
25c109e
Compare
8479461 to
2daad47
Compare
d9a9c9e to
55553a2
Compare
66eaf4c to
e53d032
Compare
d0afa95 to
28ce8bc
Compare
7410907 to
0b5e40d
Compare
50a40a9 to
8beb795
Compare
a526f65 to
4539458
Compare
2009b35 to
9564f98
Compare
9564f98 to
771a5ef
Compare
Trivy image scan report
|
| Package | ID | Severity | Installed Version | Fixed Version |
|---|---|---|---|---|
libc6 |
CVE-2025-4802 | HIGH | 2.36-9+deb12u8 | 2.36-9+deb12u11 |
libc6 |
CVE-2025-0395 | MEDIUM | 2.36-9+deb12u8 | 2.36-9+deb12u10 |
libc6 |
CVE-2025-8058 | MEDIUM | 2.36-9+deb12u8 | 2.36-9+deb12u13 |
libexpat1 |
CVE-2023-52425 | HIGH | 2.5.0-1+deb12u1 | 2.5.0-1+deb12u2 |
libexpat1 |
CVE-2024-8176 | HIGH | 2.5.0-1+deb12u1 | 2.5.0-1+deb12u2 |
libexpat1 |
CVE-2024-50602 | MEDIUM | 2.5.0-1+deb12u1 | 2.5.0-1+deb12u2 |
libfreetype6 |
CVE-2025-27363 | HIGH | 2.12.1+dfsg-5+deb12u3 | 2.12.1+dfsg-5+deb12u4 |
libgcc-s1 |
CVE-2023-4039 | LOW | 12.2.0-14 | 12.2.0-14+deb12u1 |
libstdc++6 |
CVE-2023-4039 | LOW | 12.2.0-14 | 12.2.0-14+deb12u1 |
No Misconfigurations found
Java
28 known vulnerabilities found (CRITICAL: 1 HIGH: 12 MEDIUM: 9 LOW: 6)
Show detailed table of vulnerabilities
| Package | ID | Severity | Installed Version | Fixed Version |
|---|---|---|---|---|
ca.uhn.hapi.fhir:org.hl7.fhir.r4 |
CVE-2024-51132 | HIGH | 6.3.23 | 6.4.0 |
ca.uhn.hapi.fhir:org.hl7.fhir.r4 |
CVE-2024-52007 | HIGH | 6.3.23 | 6.4.0 |
ca.uhn.hapi.fhir:org.hl7.fhir.utilities |
CVE-2024-51132 | HIGH | 6.3.23 | 6.4.0 |
ca.uhn.hapi.fhir:org.hl7.fhir.utilities |
CVE-2024-52007 | HIGH | 6.3.23 | 6.4.0 |
ch.qos.logback:logback-core |
CVE-2024-12798 | MEDIUM | 1.5.11 | 1.5.13, 1.3.15 |
ch.qos.logback:logback-core |
CVE-2025-11226 | MEDIUM | 1.5.11 | 1.5.19, 1.3.16 |
ch.qos.logback:logback-core |
CVE-2024-12801 | LOW | 1.5.11 | 1.5.13, 1.3.15 |
commons-io:commons-io |
CVE-2024-47554 | HIGH | 2.11.0 | 2.14.0 |
org.apache.commons:commons-lang3 |
CVE-2025-48924 | MEDIUM | 3.14.0 | 3.18.0 |
org.apache.kafka:kafka-clients |
CVE-2025-27817 | MEDIUM | 3.7.1 | 3.9.1 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-24813 | CRITICAL | 10.1.31 | 11.0.3, 10.1.35, 9.0.99 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2024-50379 | HIGH | 10.1.31 | 11.0.2, 10.1.34, 9.0.98 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2024-56337 | HIGH | 10.1.31 | 11.0.2, 10.1.34, 9.0.98 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-48988 | HIGH | 10.1.31 | 11.0.8, 10.1.42, 9.0.106 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-48989 | HIGH | 10.1.31 | 11.0.10, 10.1.44, 9.0.108 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-55752 | HIGH | 10.1.31 | 11.0.11, 10.1.45, 9.0.109 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-31650 | MEDIUM | 10.1.31 | 9.0.104, 10.1.40, 11.0.6 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-49124 | MEDIUM | 10.1.31 | 11.0.8, 10.1.42, 9.0.106 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-49125 | MEDIUM | 10.1.31 | 11.0.8, 10.1.42, 9.0.106 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-31651 | LOW | 10.1.31 | 9.0.104, 10.1.40, 11.0.6 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-46701 | LOW | 10.1.31 | 9.0.105, 10.1.41, 11.0.7 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-55754 | LOW | 10.1.31 | 11.0.11, 10.1.45, 9.0.109 |
org.apache.tomcat.embed:tomcat-embed-core |
CVE-2025-61795 | LOW | 10.1.31 | 11.0.12, 10.1.47, 9.0.110 |
org.springframework.boot:spring-boot |
CVE-2025-22235 | HIGH | 3.3.5 | 3.3.11, 3.4.5 |
org.springframework:spring-context |
CVE-2025-22233 | LOW | 6.1.14 | 6.2.7, 6.1.20 |
org.springframework:spring-core |
CVE-2025-41249 | HIGH | 6.1.14 | 6.2.11 |
org.springframework:spring-web |
CVE-2025-41234 | MEDIUM | 6.1.14 | 6.2.8, 6.1.21 |
org.springframework:spring-webmvc |
CVE-2025-41242 | MEDIUM | 6.1.14 | 6.2.10 |
No Misconfigurations found
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.

This PR contains the following updates:
v4.2.2->v4.3.1v4.1.8->v4.3.0v4.4.3->v4.6.20723387->e32d7e6v2.1.6->v2.2.24v3.27.0->v3.31.4v1.10.0->v1.13.0v1.7.1->v1.7.2v1.12.7->v1.18.3v2.4.0->v2.4.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
actions/checkout (actions/checkout)
v4.3.1Compare Source
What's Changed
Full Changelog: actions/checkout@v4...v4.3.1
v4.3.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/checkout@v4...v4.3.0
actions/download-artifact (actions/download-artifact)
v4.3.0Compare Source
What's Changed
artifact-idsinput by @GrantBirki in #401New Contributors
Full Changelog: actions/download-artifact@v4.2.1...v4.3.0
v4.2.1Compare Source
What's Changed
Full Changelog: actions/download-artifact@v4.2.0...v4.2.1
v4.2.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/download-artifact@v4.1.9...v4.2.0
v4.1.9Compare Source
What's Changed
New Contributors
Full Changelog: actions/download-artifact@v4.1.8...v4.1.9
actions/upload-artifact (actions/upload-artifact)
v4.6.2Compare Source
What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v4...v4.6.2
v4.6.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4...v4.6.1
v4.6.0Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v4...v4.6.0
v4.5.0Compare Source
What's Changed
Node.jsversion in action by @hamirmahal in #578artifact-digestoutput by @bdehamer in #656New Contributors
Full Changelog: actions/upload-artifact@v4.4.3...v4.5.0
miracum/ig-build-tools (ghcr.io/miracum/ig-build-tools)
v2.2.24Compare Source
Miscellaneous Chores
67fc762(#241) (53a5483)v2.2.23Compare Source
Miscellaneous Chores
v2.2.22Compare Source
Miscellaneous Chores
v2.2.21Compare Source
Miscellaneous Chores
v2.2.20Compare Source
Miscellaneous Chores
v2.2.19Compare Source
Miscellaneous Chores
v2.2.18Compare Source
Miscellaneous Chores
20e7f72(#235) (fb3a59d)v2.2.17Compare Source
Miscellaneous Chores
v2.2.16Compare Source
Miscellaneous Chores
v2.2.15Compare Source
Bug Fixes
v2.2.14Compare Source
Bug Fixes
v2.2.13Compare Source
Miscellaneous Chores
f338d0c(#229) (53c7bb9)v2.2.12Compare Source
Miscellaneous Chores
v2.2.11Compare Source
Miscellaneous Chores
v2.2.10Compare Source
Bug Fixes
v2.2.9Compare Source
Miscellaneous Chores
85ec8e4(#224) (99ce2ed)v2.2.8Compare Source
Miscellaneous Chores
v2.2.7Compare Source
Miscellaneous Chores
v2.2.6Compare Source
Bug Fixes
Miscellaneous Chores
c06eb1d(#219) (810923d)v2.2.5Compare Source
Bug Fixes
v2.2.4Compare Source
Miscellaneous Chores
v2.2.3Compare Source
Miscellaneous Chores
ce9014e(#214) (8df1c31)v2.2.2Compare Source
Miscellaneous Chores
v2.2.1Compare Source
Miscellaneous Chores
v2.2.0Compare Source
Features
v2.1.21Compare Source
Miscellaneous Chores
v2.1.20Compare Source
Bug Fixes
v2.1.19Compare Source
Miscellaneous Chores
v2.1.18Compare Source
Miscellaneous Chores
v2.1.17Compare Source
Miscellaneous Chores
3ef64ec(#204) (f23be5e)CI/CD
v2.1.16Compare Source
Miscellaneous Chores
v2.1.15Compare Source
Miscellaneous Chores
v2.1.14Compare Source
Bug Fixes
v2.1.13Compare Source
Bug Fixes
v2.1.12Compare Source
Miscellaneous Chores
v2.1.11Compare Source
Miscellaneous Chores
860f93f(#198) (27516be)v2.1.10Compare Source
Bug Fixes
v2.1.9Compare Source
Miscellaneous Chores
v2.1.8Compare Source
Miscellaneous Chores
v2.1.7Compare Source
Miscellaneous Chores
22639ff(18913e9)a271604(994236f)cc5855a(338ac43)github/codeql-action (github/codeql-action)
v3.31.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.4 - 18 Nov 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.31.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.3 - 13 Nov 2025
See the full CHANGELOG.md for more information.
v3.31.2Compare Source
v3.31.1Compare Source
v3.31.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.0 - 24 Oct 2025
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #3222See the full CHANGELOG.md for more information.
v3.30.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.9 - 17 Oct 2025
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204See the full CHANGELOG.md for more information.
v3.30.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.8 - 10 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.7 - 06 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.6 - 02 Oct 2025
See the full CHANGELOG.md for more information.
v3.30.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.5 - 26 Sep 2025
3.30.4withupload-sarifwhich resulted in files without a.sarifextension not getting uploaded. #3160See the full CHANGELOG.md for more information.
v3.30.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.4 - 25 Sep 2025
codeql-action/initstep if different versions of the CodeQL Action are detected in the workflow file. Additionally, an error will now be thrown by the other CodeQL Action steps if they load a configuration file that was generated by a different version of thecodeql-action/initstep. #3099 and #3100tools: nightlyto theinitaction. In general, the nightly bundle is unstable and we only recommend running it when directed by GitHub staff. #3130See the full CHANGELOG.md for more information.
v3.30.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.3 - 10 Sep 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.2 - 09 Sep 2025
quality-queriesinput that was added in3.29.2as part of an internal experiment is now deprecated and will be removed in an upcoming version of the CodeQL Action. It has been superseded by a newanalysis-kindsinput, which is part of the same internal experiment. Do not use this in production as it is subject to change at any time. #3064See the full CHANGELOG.md for more information.
v3.30.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.1 - 05 Sep 2025
See the full CHANGELOG.md for more information.
v3.30.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.0 - 01 Sep 2025
See the full CHANGELOG.md for more information.
v3.29.11Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.11 - 21 Aug 2025
See the full CHANGELOG.md for more information.
v3.29.10Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.10 - 18 Aug 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.9 - 12 Aug 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.8 - 08 Aug 2025
See the full CHANGELOG.md for more information.
v3.29.7Compare Source
This is a re-release of v3.29.5 to mitigate an issue that was discovered with v3.29.6.
v3.29.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.6 - 07 Aug 2025
cleanup-levelinput to theanalyzeAction is now deprecated. The CodeQL Action has written a limited amount of intermediate results to the database since version 2.2.5, and now automatically manages cleanup. #2999See the full CHANGELOG.md for more information.
v3.29.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.5 - 29 Jul 2025
See the full CHANGELOG.md for more information.
v3.29.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.4 - 23 Jul 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.3 - 21 Jul 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.2 - 30 Jun 2025
quality-queriesinput for theinitaction is provided with an argument, separate.quality.sariffiles are produced and uploaded for each language with the results of the specified queries. Do not use this in production as it is part of an internal experiment and subject to change at any time. #2935See the full CHANGELOG.md for more information.
v3.29.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.1 - 27 Jun 2025
includequery filter fails to exclude non-included queries. #2938See the full CHANGELOG.md for more information.
v3.29.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.0 - 11 Jun 2025
See the full CHANGELOG.md for more information.
v3.28.21Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.21 - 28 July 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.20Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.20 - 21 July 2025
See the full CHANGELOG.md for more information.
v3.28.19Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.19 - 03 Jun 2025
actionslanguage, which is currently in public preview.The
actionsextractor has been included in the CodeQL CLI since v2.20.6. If your workflow has enabled theactionslanguage and you have pinnedyour
tools:property to a specific version of the CodeQL CLI earlier than v2.20.6, you will need to update to at least CodeQL v2.20.6 or disableactionsanalysis.See the full CHANGELOG.md for more information.
v3.28.18Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.18 - 16 May 2025
CODEQL_THREADSandCODEQL_RAMrunner environment variables. If set, these environmentConfiguration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.