dependabot[bot]
|
a73e3bdb6b
|
chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-06-04 03:38:09 +00:00 |
|
CrazyMax
|
b522ed9b9b
|
Merge pull request #453 from crazy-max/yarn-update
update yarn to 4.15.0
|
2026-05-28 18:41:14 +02:00 |
|
CrazyMax
|
3807abb13c
|
update yarn to 4.15.0
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
|
2026-05-28 15:11:47 +02:00 |
|
CrazyMax
|
b48e756491
|
Merge pull request #451 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.91.0
chore(deps): Bump @docker/actions-toolkit from 0.90.0 to 0.91.0
|
2026-05-28 10:40:54 +02:00 |
|
github-actions[bot]
|
16246e91d6
|
chore: update generated content
|
2026-05-28 08:18:46 +00:00 |
|
dependabot[bot]
|
78970d44df
|
chore(deps): Bump @docker/actions-toolkit from 0.90.0 to 0.91.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.90.0 to 0.91.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.90.0...v0.91.0)
---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
dependency-version: 0.91.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-28 08:17:51 +00:00 |
|
CrazyMax
|
8d9e8e938e
|
Merge pull request #452 from docker/dependabot/npm_and_yarn/tmp-0.2.7
chore(deps): Bump tmp from 0.2.5 to 0.2.7
|
2026-05-28 10:15:26 +02:00 |
|
CrazyMax
|
ed9d2dc915
|
Merge pull request #450 from docker/sec-cli/ignore-scripts-fix-20260527-192659
ci: add ignore-scripts to Node package manager config (20260527-192659)
|
2026-05-28 09:49:39 +02:00 |
|
github-actions[bot]
|
73284d0e36
|
chore: update generated content
|
2026-05-28 03:12:49 +00:00 |
|
dependabot[bot]
|
1358ed6549
|
chore(deps): Bump tmp from 0.2.5 to 0.2.7
Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.7)
---
updated-dependencies:
- dependency-name: tmp
dependency-version: 0.2.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-28 03:11:53 +00:00 |
|
securityeng-bot[bot]
|
d9caed87ad
|
ci: enforce ignore-scripts policy for Node package managers
|
2026-05-27 20:05:24 +00:00 |
|
CrazyMax
|
d8437235bd
|
Merge pull request #449 from docker/dependabot/github_actions/subaction/matrix/actions/github-script-9.0.0
chore(deps): Bump actions/github-script from 8.0.0 to 9.0.0 in /subaction/matrix
|
2026-05-26 20:11:10 +02:00 |
|
dependabot[bot]
|
6f2e2568d5
|
chore(deps): Bump actions/github-script in /subaction/matrix
Bumps [actions/github-script](https://github.com/actions/github-script) from 8.0.0 to 9.0.0.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f7108da1b3)
---
updated-dependencies:
- dependency-name: actions/github-script
dependency-version: 9.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-26 17:14:51 +00:00 |
|
Tõnis Tiigi
|
4e2003362d
|
Merge pull request #444 from crazy-max/dependabot-subdir
dependabot: scan matrix subaction
|
2026-05-26 10:12:12 -07:00 |
|
CrazyMax
|
319deeae86
|
Merge pull request #447 from docker/dependabot/github_actions/github/codeql-action-4.36.0
chore(deps): Bump github/codeql-action from 4.35.5 to 4.36.0
|
2026-05-26 09:47:18 +02:00 |
|
CrazyMax
|
7b33a5efc5
|
Merge pull request #446 from docker/dependabot/github_actions/docker/setup-buildx-action-4.1.0
chore(deps): Bump docker/setup-buildx-action from 4.0.0 to 4.1.0
|
2026-05-26 09:46:58 +02:00 |
|
CrazyMax
|
7155ebf2d8
|
Merge pull request #445 from docker/dependabot/github_actions/docker/metadata-action-6.1.0
chore(deps): Bump docker/metadata-action from 6.0.0 to 6.1.0
|
2026-05-26 09:46:38 +02:00 |
|
CrazyMax
|
a3634cba36
|
Merge pull request #448 from docker/dependabot/github_actions/docker/bake-action-7.2.0
chore(deps): Bump docker/bake-action from 7.1.0 to 7.2.0
|
2026-05-26 09:30:53 +02:00 |
|
dependabot[bot]
|
ef67877e47
|
chore(deps): Bump docker/bake-action from 7.1.0 to 7.2.0
Bumps [docker/bake-action](https://github.com/docker/bake-action) from 7.1.0 to 7.2.0.
- [Release notes](https://github.com/docker/bake-action/releases)
- [Commits](https://github.com/docker/bake-action/compare/a66e1c87e2eca0503c343edf1d208c716d54b8a8...6614cfa25eff9a0b2b2697efb0b6159e7680d584)
---
updated-dependencies:
- dependency-name: docker/bake-action
dependency-version: 7.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-26 05:05:18 +00:00 |
|
dependabot[bot]
|
51998f2e23
|
chore(deps): Bump github/codeql-action from 4.35.5 to 4.36.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.5 to 4.36.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/9e0d7b8d25671d64c341c19c0152d693099fb5ba...7211b7c8077ea37d8641b6271f6a365a22a5fbfa)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-26 05:05:08 +00:00 |
|
dependabot[bot]
|
c3213e2454
|
chore(deps): Bump docker/setup-buildx-action from 4.0.0 to 4.1.0
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5)
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-26 05:03:41 +00:00 |
|
dependabot[bot]
|
cfa1977d2c
|
chore(deps): Bump docker/metadata-action from 6.0.0 to 6.1.0
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 6.0.0 to 6.1.0.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](https://github.com/docker/metadata-action/compare/030e881283bb7a6894de51c315a6bfe6a94e05cf...80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9)
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-26 05:03:27 +00:00 |
|
CrazyMax
|
67998fd5c4
|
dependabot: scan matrix subaction
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
|
2026-05-23 02:05:24 +02:00 |
|
CrazyMax
|
6614cfa25e
|
Merge pull request #425 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.88.0
chore(deps): Bump @docker/actions-toolkit from 0.87.0 to 0.90.0
v7
v7.2.0
|
2026-05-21 15:32:33 +02:00 |
|
github-actions[bot]
|
0a925a2f44
|
chore: update generated content
|
2026-05-21 13:29:22 +00:00 |
|
dependabot[bot]
|
b9ca7428b9
|
chore(deps): Bump @docker/actions-toolkit from 0.87.0 to 0.90.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.87.0 to 0.90.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.87.0...v0.90.0)
---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
dependency-version: 0.88.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-21 13:28:23 +00:00 |
|
CrazyMax
|
48e6359a4a
|
Merge pull request #429 from docker/dependabot/npm_and_yarn/fast-xml-parser-5.7.1
chore(deps): Bump fast-xml-parser from 5.5.9 to 5.8.0
|
2026-05-21 15:26:23 +02:00 |
|
github-actions[bot]
|
d1523f495a
|
chore: update generated content
|
2026-05-21 13:24:20 +00:00 |
|
dependabot[bot]
|
a73f293b0b
|
chore(deps): Bump fast-xml-parser from 5.5.9 to 5.8.0
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.5.9 to 5.8.0.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.9...v5.8.0)
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.7.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-21 13:23:23 +00:00 |
|
CrazyMax
|
bc584acc2a
|
Merge pull request #430 from docker/dependabot/npm_and_yarn/actions/core-3.0.1
chore(deps): Bump @actions/core from 3.0.0 to 3.0.1
|
2026-05-21 15:20:46 +02:00 |
|
github-actions[bot]
|
23050a11b3
|
chore: update generated content
|
2026-05-21 13:18:58 +00:00 |
|
dependabot[bot]
|
7ae1cf6599
|
chore(deps): Bump @actions/core from 3.0.0 to 3.0.1
Bumps [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) from 3.0.0 to 3.0.1.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core)
---
updated-dependencies:
- dependency-name: "@actions/core"
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-21 13:18:03 +00:00 |
|
CrazyMax
|
e7934f8394
|
Merge pull request #432 from docker/dependabot/npm_and_yarn/postcss-8.5.10
chore(deps): Bump postcss from 8.5.6 to 8.5.10
|
2026-05-21 15:15:59 +02:00 |
|
CrazyMax
|
2180af9b2d
|
Merge pull request #436 from docker/dependabot/npm_and_yarn/fast-xml-builder-1.2.0
chore(deps): Bump fast-xml-builder from 1.1.4 to 1.2.0
|
2026-05-21 15:14:59 +02:00 |
|
CrazyMax
|
67520b7fff
|
Merge pull request #439 from docker/dependabot/github_actions/actions/create-github-app-token-3.2.0
chore(deps): Bump actions/create-github-app-token from 3.1.1 to 3.2.0
|
2026-05-21 15:14:32 +02:00 |
|
dependabot[bot]
|
bab4dca6e5
|
chore(deps): Bump actions/create-github-app-token from 3.1.1 to 3.2.0
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 3.1.1 to 3.2.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/create-github-app-token/compare/1b10c78c7865c340bc4f6099eb2f838309f1e8c3...bcd2ba49218906704ab6c1aa796996da409d3eb1)
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 3.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-21 13:12:05 +00:00 |
|
CrazyMax
|
30365c9513
|
Merge pull request #437 from docker/dependabot/github_actions/crazy-max-dot-github-6667ecc476
chore(deps): Bump the crazy-max-dot-github group with 2 updates
|
2026-05-21 15:08:45 +02:00 |
|
CrazyMax
|
d27056814b
|
Merge pull request #443 from crazy-max/zizmor-fixes
ci: restrict update-dist GitHub App token scope
|
2026-05-21 14:57:12 +02:00 |
|
CrazyMax
|
55c6f41962
|
ci: restrict update-dist GitHub App token scope
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
|
2026-05-21 14:19:42 +02:00 |
|
CrazyMax
|
96578ad44f
|
Merge pull request #440 from docker/dependabot/npm_and_yarn/tar-7.5.15
chore(deps): Bump tar from 6.2.1 to 7.5.15
|
2026-05-21 14:14:17 +02:00 |
|
CrazyMax
|
394c7845c8
|
Merge pull request #441 from docker/dependabot/github_actions/github/codeql-action-4.35.5
chore(deps): Bump github/codeql-action from 4.35.2 to 4.35.5
|
2026-05-21 14:01:36 +02:00 |
|
CrazyMax
|
008fe0dad3
|
Merge pull request #442 from docker/dependabot/github_actions/codecov/codecov-action-6.0.1
chore(deps): Bump codecov/codecov-action from 6.0.0 to 6.0.1
|
2026-05-21 14:00:59 +02:00 |
|
dependabot[bot]
|
25a07aec84
|
chore(deps): Bump codecov/codecov-action from 6.0.0 to 6.0.1
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.0 to 6.0.1.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codecov/codecov-action/compare/57e3a136b779b570ffcdbf80b3bdc90e7fab3de2...e79a6962e0d4c0c17b229090214935d2e33f8354)
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-version: 6.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-20 05:06:59 +00:00 |
|
dependabot[bot]
|
b0fda6d54b
|
chore(deps): Bump github/codeql-action from 4.35.2 to 4.35.5
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.2 to 4.35.5.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/95e58e9a2cdfd71adc6e0353d5c52f41a045d225...9e0d7b8d25671d64c341c19c0152d693099fb5ba)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-19 09:49:21 +00:00 |
|
dependabot[bot]
|
db33cb2356
|
chore(deps): Bump tar from 6.2.1 to 7.5.15
Bumps [tar](https://github.com/isaacs/node-tar) from 6.2.1 to 7.5.15.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v6.2.1...v7.5.15)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.15
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-15 00:38:44 +00:00 |
|
dependabot[bot]
|
263f1e5eaf
|
chore(deps): Bump the crazy-max-dot-github group with 2 updates
Bumps the crazy-max-dot-github group with 2 updates: [crazy-max/.github/.github/workflows/pr-assign-author.yml](https://github.com/crazy-max/.github) and [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github).
Updates `crazy-max/.github/.github/workflows/pr-assign-author.yml` from 1.7.1 to 1.8.0
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](https://github.com/crazy-max/.github/compare/64a0bfaf6e6bb1c448d6e4c42b11034ee7094f16...9ba6e6f9450baf3b1237f8035c1fdc45932510bd)
Updates `crazy-max/.github/.github/workflows/zizmor.yml` from 1.7.1 to 1.8.0
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](https://github.com/crazy-max/.github/compare/64a0bfaf6e6bb1c448d6e4c42b11034ee7094f16...9ba6e6f9450baf3b1237f8035c1fdc45932510bd)
---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/workflows/pr-assign-author.yml
dependency-version: 1.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
dependency-version: 1.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: crazy-max-dot-github
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-12 05:32:54 +00:00 |
|
github-actions[bot]
|
54ce3f462d
|
chore: update generated content
|
2026-05-08 18:44:06 +00:00 |
|
dependabot[bot]
|
73ba2255c7
|
chore(deps): Bump fast-xml-builder from 1.1.4 to 1.2.0
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder) from 1.1.4 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-builder/compare/v1.1.4...v1.2.0)
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-05-08 18:42:57 +00:00 |
|
CrazyMax
|
4574eacfed
|
Merge pull request #433 from docker/dependabot/github_actions/crazy-max-dot-github-a3893cf95f
chore(deps): Bump the crazy-max-dot-github group with 2 updates
|
2026-04-27 09:36:23 +02:00 |
|
dependabot[bot]
|
29fd3dbeee
|
chore(deps): Bump the crazy-max-dot-github group with 2 updates
Bumps the crazy-max-dot-github group with 2 updates: [crazy-max/.github/.github/workflows/pr-assign-author.yml](https://github.com/crazy-max/.github) and [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github).
Updates `crazy-max/.github/.github/workflows/pr-assign-author.yml` from 1.7.0 to 1.7.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](https://github.com/crazy-max/.github/compare/4a17dbaa9ce13920fc5bb8824eb89c16301e5ab2...64a0bfaf6e6bb1c448d6e4c42b11034ee7094f16)
Updates `crazy-max/.github/.github/workflows/zizmor.yml` from 1.7.0 to 1.7.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](https://github.com/crazy-max/.github/compare/4a17dbaa9ce13920fc5bb8824eb89c16301e5ab2...64a0bfaf6e6bb1c448d6e4c42b11034ee7094f16)
---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/workflows/pr-assign-author.yml
dependency-version: 1.7.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
dependency-version: 1.7.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: crazy-max-dot-github
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2026-04-24 23:42:36 +00:00 |
|