peaceiris
9b7aa41d20
ci: harden GitHub Actions workflows
...
Pin workflow actions to commit SHAs, set explicit permissions and timeouts, update Ubuntu runners, and include the generated action bundle.
Co-Authored-By: Codex <noreply@openai.com >
2026-05-10 01:18:21 +09:00
Paul Keen
83259d800c
feat: upgrade action runtime from Node 20 to 24 ( #684 )
2026-05-02 23:18:58 +09:00
dependabot[bot]
3a287949d3
ci: bump codecov/codecov-action from 4 to 5 ( #660 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-15 11:27:10 +09:00
dependabot[bot]
3b443076f0
ci: bump peaceiris/actions-hugo from 2.6.0 to 3.0.0 ( #653 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-05 12:39:54 +09:00
dependabot[bot]
764796d276
ci: bump actions/upload-artifact from 3 to 4 ( #654 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-05 12:39:40 +09:00
dependabot[bot]
e177dc33cb
ci: bump codecov/codecov-action from 3 to 4 ( #655 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-05 12:39:29 +09:00
dependabot[bot]
711df4ed64
ci: bump actions/dependency-review-action from 3 to 4 ( #656 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-05 12:39:13 +09:00
dependabot[bot]
9d57878417
ci: bump github/codeql-action from 2 to 3 ( #657 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-05 11:57:05 +09:00
Rui Chen
c57490a8b0
feat: bump to use node20 runtime ( #641 )
2024-02-06 23:47:20 +09:00
Andreas Deininger
aadc3a98df
ci: bump checkout to v4 ( #639 )
2023-10-05 09:17:20 +09:00
dependabot[bot]
3fa8fd6cee
ci: bump actions/setup-node from 3.5.1 to 3.6.0 ( #625 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-06 18:59:08 +09:00
dependabot[bot]
844f8735f6
ci: bump actions/dependency-review-action from 2 to 3 ( #622 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-11-14 12:02:46 +09:00
dependabot[bot]
b1822b6abe
ci: bump peaceiris/actions-hugo from 2.5.0 to 2.6.0 ( #621 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-10-24 11:25:57 +09:00
dependabot[bot]
c0150f24bb
ci: bump actions/setup-node from 3.5.0 to 3.5.1 ( #612 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-10-14 11:13:39 +09:00
dependabot[bot]
a2eba60698
ci: bump actions/setup-node from 3.4.1 to 3.5.0 ( #606 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-09-28 11:06:30 +09:00
dependabot[bot]
831547a4b2
ci: bump actions/dependency-review-action from 1 to 2 ( #593 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-30 00:12:50 +09:00
Sardorbek Imomaliev
bd5a5edf1b
ci: drop ubuntu-18.04, add ubuntu-22.04 and ubuntu-latest ( #603 )
...
add support for ubuntu 22.04, drop ubuntu-18.04
- [starting with 8 of August 2022 support for ubuntu 18.04 is deprecated](https://github.blog/changelog/2022-08-09-github-actions-the-ubuntu-18-04-actions-runner-image-is-being-deprecated-and-will-be-removed-by-12-1-22/ )
- [ubuntu 22.04 is generally available](https://github.blog/changelog/2022-08-09-github-actions-ubuntu-22-04-is-now-generally-available-on-github-hosted-runners/ )
2022-08-30 00:06:54 +09:00
dependabot[bot]
11bede66e7
ci: bump actions/setup-node from 3.1.1 to 3.4.1 ( #598 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-15 11:36:30 +09:00
dependabot[bot]
808d10a6aa
ci: bump github/codeql-action from 1 to 2 ( #581 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 14:03:21 +09:00
dependabot[bot]
25736cc1c0
ci: bump actions/setup-node from 3.1.0 to 3.1.1 ( #577 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-12 12:20:37 +09:00
dependabot[bot]
6ce18a799f
ci: bump actions/upload-artifact from 2 to 3 ( #576 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-11 21:36:56 +09:00
Shohei Ueda
4809af4bd4
ci: add actions/dependency-review-action v1
2022-04-11 00:25:28 +09:00
dependabot[bot]
3c69ee1612
ci: bump codecov/codecov-action from 2.1.0 to 3 ( #575 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-06 21:38:22 +09:00
dependabot[bot]
2f2b8d32b9
ci: bump actions/setup-node from 3.0.0 to 3.1.0 ( #574 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-04 12:35:35 +09:00
dependabot[bot]
a41bdb53bd
ci: bump actions/checkout from 2.4.0 to 3 ( #565 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-03-02 11:40:05 +09:00
dependabot[bot]
550aee6c36
ci: bump actions/setup-node from 2.5.1 to 3.0.0 ( #557 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-02-25 13:59:51 +09:00
Shohei Ueda
ba23c24d3a
ci: Remove updating npm
2022-02-25 13:54:09 +09:00
dependabot[bot]
1575f408ae
ci: bump actions/setup-node from 2.5.0 to 2.5.1 ( #552 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-29 16:01:34 +09:00
dependabot[bot]
008429aaab
ci: bump actions/setup-node from 2.4.1 to 2.5.0 ( #551 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-11-30 12:50:44 +09:00
dependabot[bot]
86a3c300c7
ci: bump actions/checkout from 2.3.5 to 2.4.0 ( #548 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-11-03 16:19:33 +09:00
dependabot[bot]
3bb386ec5a
ci: bump actions/checkout from 2.3.4 to 2.3.5 ( #546 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-10-18 11:12:24 +09:00
dependabot[bot]
cebd0015e0
ci: bump actions/setup-node from 2.4.0 to 2.4.1 ( #543 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-09-28 17:09:54 +09:00
dependabot[bot]
f93586ef6c
ci: bump codecov/codecov-action from 2.0.3 to 2.1.0 ( #542 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 2.0.3 to 2.1.0.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v2.0.3...v2.1.0 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-09-15 18:15:01 +09:00
dependabot[bot]
b911fb4dcf
ci: bump codecov/codecov-action from 2.0.2 to 2.0.3 ( #540 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-08-25 11:22:43 +09:00
dependabot[bot]
57272db01c
ci: bump actions/setup-node from 2.3.2 to 2.4.0 ( #538 )
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 2.3.2 to 2.4.0.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v2.3.2...v2.4.0 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-08-06 19:24:55 +09:00
dependabot[bot]
239a50c280
ci: bump actions/setup-node from 2.3.0 to 2.3.2 ( #537 )
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 2.3.0 to 2.3.2.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v2.3.0...v2.3.2 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-08-05 18:10:20 +09:00
dependabot[bot]
54f7007102
ci: bump codecov/codecov-action from 2.0.1 to 2.0.2 ( #533 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 2.0.1 to 2.0.2.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v2.0.1...v2.0.2 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-26 11:31:24 +09:00
dependabot[bot]
82ac7db7f2
ci: bump peaceiris/actions-label-commenter from 1.9.2 to 1.10.0 ( #532 )
...
Bumps [peaceiris/actions-label-commenter](https://github.com/peaceiris/actions-label-commenter ) from 1.9.2 to 1.10.0.
- [Release notes](https://github.com/peaceiris/actions-label-commenter/releases )
- [Changelog](https://github.com/peaceiris/actions-label-commenter/blob/main/CHANGELOG.md )
- [Commits](https://github.com/peaceiris/actions-label-commenter/compare/v1.9.2...v1.10.0 )
---
updated-dependencies:
- dependency-name: peaceiris/actions-label-commenter
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-23 12:24:47 +09:00
dependabot[bot]
781702ee9d
ci: bump actions/setup-node from 2.2.0 to 2.3.0 ( #531 )
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 2.2.0 to 2.3.0.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v2.2.0...v2.3.0 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-21 11:41:58 +09:00
dependabot[bot]
19b5ac8979
ci: bump codecov/codecov-action from 1.5.2 to 2.0.1 ( #530 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 1.5.2 to 2.0.1.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v1.5.2...v2.0.1 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-20 14:57:50 +09:00
dependabot[bot]
497618ba62
ci: bump actions/setup-node from 2.1.5 to 2.2.0 ( #529 )
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 2.1.5 to 2.2.0.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v2.1.5...v2.2.0 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-01 17:49:40 +09:00
dependabot[bot]
dead32d589
ci: bump peaceiris/actions-label-commenter from 1.9.1 to 1.9.2 ( #528 )
...
Bumps [peaceiris/actions-label-commenter](https://github.com/peaceiris/actions-label-commenter ) from 1.9.1 to 1.9.2.
- [Release notes](https://github.com/peaceiris/actions-label-commenter/releases )
- [Changelog](https://github.com/peaceiris/actions-label-commenter/blob/main/CHANGELOG.md )
- [Commits](https://github.com/peaceiris/actions-label-commenter/compare/v1.9.1...v1.9.2 )
---
updated-dependencies:
- dependency-name: peaceiris/actions-label-commenter
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-06-21 16:38:01 +09:00
dependabot[bot]
ad8a667428
ci: bump codecov/codecov-action from 1.5.0 to 1.5.2 ( #526 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 1.5.0 to 1.5.2.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v1.5.0...v1.5.2 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-06-09 11:29:30 +09:00
Shohei Ueda
5d8b0b2005
ci: Change event from published to released
2021-05-28 22:31:47 +09:00
dependabot[bot]
6a16840a86
ci: bump peaceiris/actions-hugo from 2.4.13 to 2.5.0 ( #521 )
...
Bumps [peaceiris/actions-hugo](https://github.com/peaceiris/actions-hugo ) from 2.4.13 to 2.5.0.
- [Release notes](https://github.com/peaceiris/actions-hugo/releases )
- [Changelog](https://github.com/peaceiris/actions-hugo/blob/main/CHANGELOG.md )
- [Commits](https://github.com/peaceiris/actions-hugo/compare/v2.4.13...v2.5.0 )
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-05-28 13:24:50 +09:00
dependabot[bot]
b843eaee1d
ci: bump peaceiris/actions-hugo from 2 to 2.4.13 ( #516 )
...
Bumps [peaceiris/actions-hugo](https://github.com/peaceiris/actions-hugo ) from 2 to 2.4.13.
- [Release notes](https://github.com/peaceiris/actions-hugo/releases )
- [Changelog](https://github.com/peaceiris/actions-hugo/blob/main/CHANGELOG.md )
- [Commits](https://github.com/peaceiris/actions-hugo/compare/v2...v2.4.13 )
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-05-12 11:35:46 +09:00
dependabot[bot]
f245604698
ci: bump actions/checkout from 2 to 2.3.4 ( #517 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 2 to 2.3.4.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2...v2.3.4 )
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-05-12 11:35:39 +09:00
dependabot[bot]
634c0f2891
ci: bump codecov/codecov-action from v1.4.1 to v1.5.0 ( #514 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from v1.4.1 to v1.5.0.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v1.4.1...a1ed4b322b4b38cb846afb5a0ebfa17086917d27 )
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-05-05 23:23:11 +09:00
Shohei Ueda
6b42ea1676
ci: Drop ubuntu-16.04 ( #513 )
2021-05-01 22:10:56 +09:00
dependabot[bot]
929d18cc52
ci: bump codecov/codecov-action from v1.4.0 to v1.4.1 ( #512 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from v1.4.0 to v1.4.1.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/master/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v1.4.0...967e2b38a85a62bd61be5529ada27ebc109948c2 )
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-04-21 12:12:23 +09:00