Skip to content

deps: Update dependencies for github (major)#960

Open
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/major-dependencies-for-github
Open

deps: Update dependencies for github (major)#960
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/major-dependencies-for-github

Conversation

@renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Mar 24, 2025

This PR contains the following updates:

Package Type Update Change
actions/checkout action major v4.3.0v6.0.2
actions/setup-go action major v5.5.0v6.3.0
actions/upload-artifact action major v4.6.2v7.0.0
github/codeql-action action major v3.30.9v4.32.5
google-github-actions/auth action major v2.1.13v3.0.0
google-github-actions/get-secretmanager-secrets action major v2.2.5v3.0.0

Release Notes

actions/checkout (actions/checkout)

v6.0.2

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

v5.0.1

Compare Source

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

Compare Source

What's Changed
⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

Compare Source

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

actions/setup-go (actions/setup-go)

v6.3.0

Compare Source

What's Changed

Full Changelog: actions/setup-go@v6...v6.3.0

v6.2.0

Compare Source

What's Changed
Enhancements
Dependency updates
New Contributors

Full Changelog: actions/setup-go@v6...v6.2.0

v6.1.0

Compare Source

What's Changed

Enhancements
Dependency updates

New Contributors

Full Changelog: actions/setup-go@v6...v6.1.0

v6.0.0

Compare Source

What's Changed
Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades
New Contributors

Full Changelog: actions/setup-go@v5...v6.0.0

v5.6.0

Compare Source

What's Changed

Full Changelog: actions/setup-go@v5...v5.6.0

actions/upload-artifact (actions/upload-artifact)

v7.0.0

Compare Source

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

Compare Source

v5.0.0

Compare Source

github/codeql-action (github/codeql-action)

v4.32.5

Compare Source

v4.32.4

Compare Source

  • Update default CodeQL bundle version to 2.24.2. #​3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #​3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #​3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #​3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #​3484

v4.32.3

Compare Source

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #​3466

v4.32.2

Compare Source

v4.32.1

Compare Source

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #​3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #​3421

v4.32.0

Compare Source

v4.31.11

Compare Source

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #​3409
  • Improved error handling throughout the CodeQL Action. #​3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #​3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #​3403

v4.31.10

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.10 - 12 Jan 2026
  • Update default CodeQL bundle version to 2.23.9. #​3393

See the full CHANGELOG.md for more information.

v4.31.9

Compare Source

v4.31.8

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.8 - 11 Dec 2025
  • Update default CodeQL bundle version to 2.23.8. #​3354

See the full CHANGELOG.md for more information.

v4.31.7

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.7 - 05 Dec 2025
  • Update default CodeQL bundle version to 2.23.7. #​3343

See the full CHANGELOG.md for more information.

v4.31.6

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.6 - 01 Dec 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v4.31.5

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.5 - 24 Nov 2025
  • Update default CodeQL bundle version to 2.23.6. #​3321

See the full CHANGELOG.md for more information.

v4.31.4

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.4 - 18 Nov 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v4.31.3

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.3 - 13 Nov 2025
  • CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
  • Update default CodeQL bundle version to 2.23.5. #​3288

See the full CHANGELOG.md for more information.

v4.31.2

Compare Source

v4.31.1

Compare Source

v4.31.0

Compare Source

v4.30.9

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.30.9 - 17 Oct 2025
  • Update default CodeQL bundle version to 2.23.3. #​3205
  • Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #​3204

See the full CHANGELOG.md for more information.

v4.30.8

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.30.8 - 10 Oct 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v4.30.7

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.30.7 - 06 Oct 2025

  • [v4+ only] The CodeQL Action now runs on Node.js v24. #​3169

See the full CHANGELOG.md for more information.

v3.32.5

Compare Source

  • Repositories owned by an organization can now set up the github-codeql-disable-overlay custom repository property to disable improved incremental analysis for CodeQL. First, create a custom repository property with the name github-codeql-disable-overlay and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to true to disable improved incremental analysis. For more information, see Managing custom properties for repositories in your organization. This feature is not yet available on GitHub Enterprise Server. #​3507
  • Added an experimental change so that when improved incremental analysis fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. #​3487
  • The minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. #​3515
  • Reduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. #​3516
  • Added an experimental change which lowers the minimum disk space requirement for improved incremental analysis, enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. #​3498
  • Added an experimental change which allows the start-proxy action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. #​3512
  • The previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. #​3503, #​3504

v3.32.4

Compare Source

  • Update default CodeQL bundle version to 2.24.2. #​3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #​3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #​3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #​3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #​3484

v3.32.3

Compare Source

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #​3466

v3.32.2

Compare Source

v3.32.1

Compare Source

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #​3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #​3421

v3.32.0

Compare Source

v3.31.11

Compare Source

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #​3409
  • Improved error handling throughout the CodeQL Action. #​3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #​3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #​3403

v3.31.10

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.10 - 12 Jan 2026
  • Update default CodeQL bundle version to 2.23.9. #​3393

See the full CHANGELOG.md for more information.

v3.31.9

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.9 - 16 Dec 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.31.8

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.8 - 11 Dec 2025
  • Update default CodeQL bundle version to 2.23.8. #​3354

See the full CHANGELOG.md for more information.

v3.31.7

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.7 - 05 Dec 2025
  • Update default CodeQL bundle version to 2.23.7. #​3343

See the full CHANGELOG.md for more information.

v3.31.6

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.6 - 01 Dec 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.31.5

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #​3321

See the full CHANGELOG.md for more information.

v3.31.4

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.4 - 18 Nov 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.31.3

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.3 - 13 Nov 2025

  • CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
  • Update default CodeQL bundle version to 2.23.5. #​3288

See the full CHANGELOG.md for more information.

v3.31.2

Compare Source

v3.31.1

Compare Source

v3.31.0

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.0 - 24 Oct 2025
  • Bump minimum CodeQL bundle version to 2.17.6. #​3223
  • When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #​3222

See the full CHANGELOG.md for more information.

google-github-actions/auth (google-github-actions/auth)

v3.0.0

Compare Source

What's Changed

Full Changelog: google-github-actions/auth@v2...v3.0.0

google-github-actions/get-secretmanager-secrets (google-github-actions/get-secretmanager-secrets)

v3.0.0

Compare Source

What's Changed

Full Changelog: google-github-actions/get-secretmanager-secrets@v2...v3.0.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested a review from a team as a code owner March 24, 2025 15:42
@renovate-bot renovate-bot changed the title deps: Update golangci/golangci-lint-action action to v7 deps: Update golangci/golangci-lint-action action to v8 May 4, 2025
@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from bf7db21 to 7a3b74f Compare May 4, 2025 21:00
@kgala2
Copy link
Contributor

kgala2 commented May 20, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 7a3b74f to f386bd6 Compare May 20, 2025 17:32
@dpebot
Copy link
Collaborator

dpebot commented May 20, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from f386bd6 to 76db7d6 Compare May 20, 2025 21:02
@dpebot
Copy link
Collaborator

dpebot commented May 20, 2025

/gcbrun

@hessjcg
Copy link
Collaborator

hessjcg commented May 20, 2025

I don't think we can do this major version upgrade of golangci lint right now. We would need to significantly rewrite our lint rules.

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 76db7d6 to b08241a Compare July 28, 2025 16:13
@dpebot
Copy link
Collaborator

dpebot commented Jul 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from b08241a to 03c39c2 Compare August 11, 2025 16:02
@renovate-bot renovate-bot changed the title deps: Update golangci/golangci-lint-action action to v8 deps: Update dependencies for github (major) Aug 11, 2025
@dpebot
Copy link
Collaborator

dpebot commented Aug 11, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 03c39c2 to a0fa1e8 Compare August 12, 2025 22:44
@dpebot
Copy link
Collaborator

dpebot commented Aug 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from a0fa1e8 to 77b90a0 Compare August 12, 2025 23:31
@dpebot
Copy link
Collaborator

dpebot commented Aug 12, 2025

/gcbrun

@renovate-bot renovate-bot changed the title deps: Update dependencies for github (major) deps: Update actions/checkout action to v5 Aug 12, 2025
@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 77b90a0 to 4a1afe8 Compare August 12, 2025 23:54
@dpebot
Copy link
Collaborator

dpebot commented Aug 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 4a1afe8 to e0998d2 Compare August 12, 2025 23:55
@dpebot
Copy link
Collaborator

dpebot commented Aug 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from e0998d2 to 6344d1e Compare August 31, 2025 12:27
@renovate-bot renovate-bot changed the title deps: Update actions/checkout action to v5 deps: Update dependencies for github (major) Aug 31, 2025
@dpebot
Copy link
Collaborator

dpebot commented Aug 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 6344d1e to 42805fb Compare September 3, 2025 05:43
@dpebot
Copy link
Collaborator

dpebot commented Sep 3, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 42805fb to af6741f Compare September 4, 2025 06:03
@dpebot
Copy link
Collaborator

dpebot commented Dec 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 70d1d2d to b89e131 Compare December 17, 2025 03:00
@dpebot
Copy link
Collaborator

dpebot commented Dec 17, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from b89e131 to b706f10 Compare December 31, 2025 12:13
@dpebot
Copy link
Collaborator

dpebot commented Dec 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from b706f10 to bb0c23e Compare January 12, 2026 14:49
@dpebot
Copy link
Collaborator

dpebot commented Jan 12, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from bb0c23e to fa2c7d2 Compare January 13, 2026 03:11
@dpebot
Copy link
Collaborator

dpebot commented Jan 13, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from fa2c7d2 to ab1dced Compare January 22, 2026 18:49
@dpebot
Copy link
Collaborator

dpebot commented Jan 22, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from ab1dced to a6e5aad Compare January 23, 2026 15:05
@dpebot
Copy link
Collaborator

dpebot commented Jan 23, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from a6e5aad to 4520944 Compare January 26, 2026 20:08
@dpebot
Copy link
Collaborator

dpebot commented Jan 26, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 4520944 to 2282bf9 Compare February 2, 2026 16:46
@dpebot
Copy link
Collaborator

dpebot commented Feb 2, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 2282bf9 to 8426acd Compare February 5, 2026 19:43
@dpebot
Copy link
Collaborator

dpebot commented Feb 5, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 8426acd to f2974e3 Compare February 13, 2026 15:40
@dpebot
Copy link
Collaborator

dpebot commented Feb 13, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from f2974e3 to 2b99e92 Compare February 20, 2026 17:07
@dpebot
Copy link
Collaborator

dpebot commented Feb 20, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 2b99e92 to 659484b Compare February 26, 2026 04:03
@dpebot
Copy link
Collaborator

dpebot commented Feb 26, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from 659484b to e1ba8bb Compare February 26, 2026 19:04
@dpebot
Copy link
Collaborator

dpebot commented Feb 26, 2026

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/major-dependencies-for-github branch from e1ba8bb to 643c9b2 Compare March 2, 2026 16:09
@dpebot
Copy link
Collaborator

dpebot commented Mar 2, 2026

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants