From 3bb95a5ca6cda1f5fce801c1c15b0e4db9cc163a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 14:09:46 +0000 Subject: [PATCH] build(deps): bump the github-action-updates group across 1 directory with 6 updates Bumps the github-action-updates group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [oxsecurity/megalinter/flavors/c_cpp](https://github.com/oxsecurity/megalinter) | `10.0.0` | `10.1.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.9` | `4.38.2` | | [reviewdog/action-suggester](https://github.com/reviewdog/action-suggester) | `1.24.3` | `1.26.1` | | [sonarsource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `8.2.1` | `8.2.2` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.9` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.9` | `4.38.2` | Updates `oxsecurity/megalinter/flavors/c_cpp` from 10.0.0 to 10.1.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](https://github.com/oxsecurity/megalinter/compare/15e5b45552097e318c93de385779ce3b1084052c...9949bad031045f366be2467e00e8371a7328a2e2) Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `reviewdog/action-suggester` from 1.24.3 to 1.26.1 - [Release notes](https://github.com/reviewdog/action-suggester/releases) - [Commits](https://github.com/reviewdog/action-suggester/compare/2558ba17e65a9039e73764a73009fc05fef28a46...c387862ad6765a9729f2b40ee4d8b5769f2145c7) Updates `sonarsource/sonarqube-scan-action` from 8.2.1 to 8.2.2 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/22918119ff8e1ca75a623e15c8296b6ea4fbe28f...ba9859eae8dd6bd29e412f25ddbbef3d032000f4) Updates `github/codeql-action/init` from 4.37.9 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-updates - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-updates - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-updates - dependency-name: oxsecurity/megalinter/flavors/c_cpp dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-updates - dependency-name: reviewdog/action-suggester dependency-version: 1.26.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-updates - dependency-name: sonarsource/sonarqube-scan-action dependency-version: 8.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-action-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/linting-formatting.yml | 6 +++--- .github/workflows/security.yml | 2 +- .github/workflows/static-analysis.yml | 6 +++--- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/linting-formatting.yml b/.github/workflows/linting-formatting.yml index a50a9f70..bb38a5a8 100644 --- a/.github/workflows/linting-formatting.yml +++ b/.github/workflows/linting-formatting.yml @@ -26,13 +26,13 @@ jobs: with: fetch-depth: 0 persist-credentials: false - - uses: oxsecurity/megalinter/flavors/c_cpp@15e5b45552097e318c93de385779ce3b1084052c # v10.0.0 + - uses: oxsecurity/megalinter/flavors/c_cpp@9949bad031045f366be2467e00e8371a7328a2e2 # v10.1.0 env: APPLY_FIXES: all VALIDATE_ALL_CODEBASE: true GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: git diff - - uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 if: ${{ success() || failure() }} with: sarif_file: megalinter-reports/megalinter-report.sarif @@ -42,6 +42,6 @@ jobs: name: linter path: | megalinter-reports - - uses: reviewdog/action-suggester@2558ba17e65a9039e73764a73009fc05fef28a46 # v1.24.3 + - uses: reviewdog/action-suggester@c387862ad6765a9729f2b40ee4d8b5769f2145c7 # v1.26.1 with: tool_name: MegaLinter diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 7fd0747b..cc55e3dc 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -31,6 +31,6 @@ jobs: results_format: sarif repo_token: ${{ secrets.SCORECARD_READ_TOKEN }} publish_results: true - - uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: sarif_file: scorecards.sarif diff --git a/.github/workflows/static-analysis.yml b/.github/workflows/static-analysis.yml index 23423aa5..4c69a0f0 100644 --- a/.github/workflows/static-analysis.yml +++ b/.github/workflows/static-analysis.yml @@ -61,7 +61,7 @@ jobs: cp .build/Coverage/compile_commands.json compile_commands.json cp .build/Coverage/sonarqube.xml sonarqube.xml - - uses: sonarsource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 + - uses: sonarsource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8.2.2 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} @@ -75,7 +75,7 @@ jobs: with: persist-credentials: false - - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: cpp @@ -88,4 +88,4 @@ jobs: configure-preset: "Host" build-preset: "Host-Debug" - - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2