Sourced from step-security/harden-runner's releases.
v2.11.1
What's Changed
- cache: add support for GitHub Actions cache v2 by
@h0x0er
in step-security/harden-runner#529Full Changelog: https://github.com/step-security/harden-runner/compare/v2...v2.11.1
c6295a6
Merge pull request #530
from step-security/rc-193e118b1
Improve error handlingb38e918
Merge pull request #529
from h0x0er/jatin/cache-fix0664d30
cache: added support for cache v2b131ca5
Merge pull request #524
from step-security/fix/security/GHSA-968p-4wvh-cqc82dc9579
Address vulnerabilitiesf054d81
Update README (#522)8a09271
Update Readme (#520)6ec6af7
Update readme (#518)539365b
Merge pull request #516
from vorburger/patch-1Sourced from actions/dependency-review-action's releases.
v4.6.0
What's Changed
- Updating multiple dependency versions by
@Ahmed3lmallah
in actions/dependency-review-action#870- Grouping minor and patch dependabot updates to lessen the number of PRs by
@Ahmed3lmallah
in actions/dependency-review-action#876- Bump actions/stale from 9.0.0 to 9.1.0 by
@dependabot
in actions/dependency-review-action#878- Bump undici from 5.28.4 to 5.28.5 by
@dependabot
in actions/dependency-review-action#877- DR Action should link to the proxima stamp when appropriate in error messages by
@AshelyTC
in actions/dependency-review-action#891- Allow deny package removal by
@ellenfieldn
in actions/dependency-review-action#888- Fix typos by
@omahs
in actions/dependency-review-action#893- Bump esbuild from 0.19.5 to 0.25.0 by
@dependabot
in actions/dependency-review-action#900- Bump octokit and related dependencies by
@RomanIakovlev
in actions/dependency-review-action#904- Bump
@babel/helpers
from 7.23.2 to 7.26.10 by@dependabot
in actions/dependency-review-action#905- Bump
@octokit/plugin-paginate-rest
from 9.1.5 to 9.2.2 by@dependabot
in actions/dependency-review-action#899- Update transitive dependency spdx-license-ids by
@ailox
in actions/dependency-review-action#855- To not print OpenSSF Scorecard section if no dependencies scanned by
@fabasoad
in actions/dependency-review-action#884- Improve usage of this action in dependency-review.yml by
@fabasoad
in actions/dependency-review-action#883- Clarify comment-summary-in-pr behaviour by
@Pantelis-Santorinios
in actions/dependency-review-action#902- Prepare 4.6.0 Release candidate by
@brrygrdn
in actions/dependency-review-action#910New Contributors
@AshelyTC
made their first contribution in actions/dependency-review-action#891@ellenfieldn
made their first contribution in actions/dependency-review-action#888@omahs
made their first contribution in actions/dependency-review-action#893@RomanIakovlev
made their first contribution in actions/dependency-review-action#904@ailox
made their first contribution in actions/dependency-review-action#855@fabasoad
made their first contribution in actions/dependency-review-action#884@Pantelis-Santorinios
made their first contribution in actions/dependency-review-action#902@brrygrdn
made their first contribution in actions/dependency-review-action#910Full Changelog: https://github.com/actions/dependency-review-action/compare/v4.5.0...v4.6.0
ce3cf95
Merge pull request #910
from actions/brrygrdn/4.6.0-release-candidate479b697
Prepare 4.6.0aee9590
Merge pull request #902
from Pantelis-Santorinios/patch-1080ada6
Merge pull request #883
from fabasoad/fix/ci430e5f0
Merge pull request #884
from fabasoad/fix/86351699b6
Merge pull request #855
from ailox/ailox/fix/invalid-new-licensesac9b193
Merge pull request #899
from actions/dependabot/npm_and_yarn/octokit/plugin-p...d630451
Pin @octokit/types
version for compatibilityc8dafca
Add dist for @octokit/plugin-paginate-rest
version
bumpbc858b5
Bump @octokit/plugin-paginate-rest
from 9.1.5 to
9.2.2Sourced from actions/create-github-app-token's releases.
v2.0.2
2.0.2 (2025-04-03)
Bug Fixes
v2.0.1
2.0.1 (2025-04-03)
Bug Fixes
v2.0.0
2.0.0 (2025-04-03)
BREAKING CHANGES
- Removed deprecated inputs (
app_id
,private_key
,skip_token_revoke
) and madeapp-id
andprivate-key
required in the action configuration.
3ff1caa
build(release): 2.0.2 [skip ci]eaef294
fix: improve log messages for token creation (#226)86e2496
build(release): 2.0.1 [skip ci]2411bfc
fix(deps): bump the production-dependencies group across 1 directory
with 2 u...f17d09a
build(deps-dev): bump the development-dependencies group with 3 updates
(#225)e250d17
ci(update-permission-inputs): add permissions (#230)ed258b4
Rename workflow5c652ca
Update update-inputs.yml60ee75d
ci(update-inputs): create initial version (#229)064492a
build(release): 2.0.0 [skip ci]Sourced from github/codeql-action's releases.
v3.28.15
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.15 - 07 Apr 2025
- Fix bug where the action would fail if it tried to produce a debug artifact with more than 65535 files. #2842
See the full CHANGELOG.md for more information.
v3.28.14
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.14 - 07 Apr 2025
- Update default CodeQL bundle version to 2.21.0. #2838
See the full CHANGELOG.md for more information.
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
3.28.15 - 07 Apr 2025
- Fix bug where the action would fail if it tried to produce a debug artifact with more than 65535 files. #2842
3.28.14 - 07 Apr 2025
- Update default CodeQL bundle version to 2.21.0. #2838
3.28.13 - 24 Mar 2025
No user facing changes.
3.28.12 - 19 Mar 2025
- Dependency caching should now cache more dependencies for Java
build-mode: none
extractions. This should speed up workflows and avoid inconsistent alerts in some cases.- Update default CodeQL bundle version to 2.20.7. #2810
3.28.11 - 07 Mar 2025
- Update default CodeQL bundle version to 2.20.6. #2793
3.28.10 - 21 Feb 2025
- Update default CodeQL bundle version to 2.20.5. #2772
- Address an issue where the CodeQL Bundle would occasionally fail to decompress on macOS. #2768
3.28.9 - 07 Feb 2025
- Update default CodeQL bundle version to 2.20.4. #2753
3.28.8 - 29 Jan 2025
- Enable support for Kotlin 2.1.10 when running with CodeQL CLI v2.20.3. #2744
3.28.7 - 29 Jan 2025
No user facing changes.
3.28.6 - 27 Jan 2025
- Re-enable debug artifact upload for CLI versions 2.20.3 or greater. #2726
... (truncated)
45775bd
Merge pull request #2854
from github/update-v3.28.15-a35ae8c38dd78aab
Update CHANGELOG.md with bug fix detailse40af59
Update changelog for v3.28.15a35ae8c
Merge pull request #2843
from github/cklin/diff-informed-compatbb59df6
Merge pull request #2842
from github/henrymercer/zip644b508f5
Merge pull request #2845
from github/mergeback/v3.28.14-to-main-fc7e4a0fca00afb
Update checked-in dependencies2969c78
Update changelog and version after v3.28.14fc7e4a0
Merge pull request #2844
from github/update-v3.28.14-362ef4ce2be0175c
Update changelog for v3.28.14