diff --git a/.github/workflows/arc-publish-chart.yaml b/.github/workflows/arc-publish-chart.yaml index 5d1983a2..b2f53695 100644 --- a/.github/workflows/arc-publish-chart.yaml +++ b/.github/workflows/arc-publish-chart.yaml @@ -58,7 +58,7 @@ jobs: run: helm template --values charts/.ci/values-kube-score.yaml charts/* | ./kube-score score - --ignore-test pod-networkpolicy --ignore-test deployment-has-poddisruptionbudget --ignore-test deployment-has-host-podantiaffinity --ignore-test container-security-context --ignore-test pod-probes --ignore-test container-image-tag --enable-optional-test container-security-context-privileged --enable-optional-test container-security-context-readonlyrootfilesystem # python is a requirement for the chart-testing action below (supports yamllint among other tests) - - uses: actions/setup-python@v6 + - uses: actions/setup-python@v7 with: python-version: "3.11" @@ -79,7 +79,7 @@ jobs: - name: Create kind cluster if: steps.list-changed.outputs.changed == 'true' - uses: helm/kind-action@ef37e7f390d99f746eb8b610417061a60e82a6cc + uses: helm/kind-action@06c1ae10762d3b9c1644e7fe69596ae519e015a2 # We need cert-manager already installed in the cluster because we assume the CRDs exist - name: Install cert-manager @@ -145,7 +145,7 @@ jobs: - name: Get Token id: get_workflow_token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.ACTIONS_ACCESS_APP_ID }} application_private_key: ${{ secrets.ACTIONS_ACCESS_PK }} diff --git a/.github/workflows/arc-publish.yaml b/.github/workflows/arc-publish.yaml index ef3f869a..e00f6b03 100644 --- a/.github/workflows/arc-publish.yaml +++ b/.github/workflows/arc-publish.yaml @@ -41,7 +41,7 @@ jobs: - name: Checkout uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" @@ -71,7 +71,7 @@ jobs: - name: Get Token id: get_workflow_token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.ACTIONS_ACCESS_APP_ID }} application_private_key: ${{ secrets.ACTIONS_ACCESS_PK }} diff --git a/.github/workflows/arc-release-runners.yaml b/.github/workflows/arc-release-runners.yaml index 2916e3a5..89a914dd 100644 --- a/.github/workflows/arc-release-runners.yaml +++ b/.github/workflows/arc-release-runners.yaml @@ -41,7 +41,7 @@ jobs: - name: Get Token id: get_workflow_token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.ACTIONS_ACCESS_APP_ID }} application_private_key: ${{ secrets.ACTIONS_ACCESS_PK }} diff --git a/.github/workflows/arc-validate-chart.yaml b/.github/workflows/arc-validate-chart.yaml index e9ea3ba0..a2f2d87f 100644 --- a/.github/workflows/arc-validate-chart.yaml +++ b/.github/workflows/arc-validate-chart.yaml @@ -50,7 +50,7 @@ jobs: version: ${{ env.HELM_VERSION }} # python is a requirement for the chart-testing action below (supports yamllint among other tests) - - uses: actions/setup-python@v6 + - uses: actions/setup-python@v7 with: python-version: "3.11" @@ -70,7 +70,7 @@ jobs: ct lint --config charts/.ci/ct-config.yaml - name: Create kind cluster - uses: helm/kind-action@ef37e7f390d99f746eb8b610417061a60e82a6cc + uses: helm/kind-action@06c1ae10762d3b9c1644e7fe69596ae519e015a2 if: steps.list-changed.outputs.changed == 'true' # We need cert-manager already installed in the cluster because we assume the CRDs exist diff --git a/.github/workflows/gha-e2e-tests.yaml b/.github/workflows/gha-e2e-tests.yaml index 781b659e..1b664da7 100644 --- a/.github/workflows/gha-e2e-tests.yaml +++ b/.github/workflows/gha-e2e-tests.yaml @@ -38,7 +38,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -62,7 +62,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -85,7 +85,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -108,7 +108,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -131,7 +131,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -154,7 +154,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -177,7 +177,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -200,7 +200,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -223,7 +223,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -246,7 +246,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -269,7 +269,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -292,7 +292,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -315,7 +315,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -338,7 +338,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -361,7 +361,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -384,7 +384,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -407,7 +407,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} @@ -430,7 +430,7 @@ jobs: - name: Get configure token id: config-token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.E2E_TESTS_ACCESS_APP_ID }} application_private_key: ${{ secrets.E2E_TESTS_ACCESS_PK }} diff --git a/.github/workflows/gha-publish-chart.yaml b/.github/workflows/gha-publish-chart.yaml index 8bcb4076..85eab5c7 100644 --- a/.github/workflows/gha-publish-chart.yaml +++ b/.github/workflows/gha-publish-chart.yaml @@ -82,10 +82,10 @@ jobs: echo "repository_owner=$(echo ${{ github.repository_owner }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_OUTPUT - name: Set up QEMU - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a - name: Set up Docker Buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e with: # Pinning v0.9.1 for Buildx and BuildKit v0.10.6 # BuildKit v0.11 which has a bug causing intermittent @@ -94,7 +94,7 @@ jobs: driver-opts: image=moby/buildkit:v0.10.6 - name: Login to GitHub Container Registry - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f with: registry: ghcr.io username: ${{ github.actor }} diff --git a/.github/workflows/gha-validate-chart.yaml b/.github/workflows/gha-validate-chart.yaml index 8e6ed541..cc7a4719 100644 --- a/.github/workflows/gha-validate-chart.yaml +++ b/.github/workflows/gha-validate-chart.yaml @@ -46,7 +46,7 @@ jobs: version: ${{ env.HELM_VERSION }} # python is a requirement for the chart-testing action below (supports yamllint among other tests) - - uses: actions/setup-python@v6 + - uses: actions/setup-python@v7 with: python-version: "3.11" @@ -84,7 +84,7 @@ jobs: version: ${{ env.HELM_VERSION }} # python is a requirement for the chart-testing action below (supports yamllint among other tests) - - uses: actions/setup-python@v6 + - uses: actions/setup-python@v7 with: python-version: "3.11" @@ -115,7 +115,7 @@ jobs: run: | helm unittest ./charts/gha-runner-scale-set-experimental/ - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" cache: false diff --git a/.github/workflows/global-publish-canary.yaml b/.github/workflows/global-publish-canary.yaml index 0a177565..4cddcfa5 100644 --- a/.github/workflows/global-publish-canary.yaml +++ b/.github/workflows/global-publish-canary.yaml @@ -59,7 +59,7 @@ jobs: - name: Get Token id: get_workflow_token - uses: peter-murray/workflow-application-token-action@cb731e00cb6754f584507134ff389dfb3dc42bbc + uses: peter-murray/workflow-application-token-action@dad2b81e50ce3edeb5f3b7ffbd79f731368bd668 with: application_id: ${{ secrets.ACTIONS_ACCESS_APP_ID }} application_private_key: ${{ secrets.ACTIONS_ACCESS_PK }} @@ -93,7 +93,7 @@ jobs: uses: actions/checkout@v7 - name: Login to GitHub Container Registry - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f with: registry: ghcr.io username: ${{ github.actor }} @@ -110,10 +110,10 @@ jobs: echo "repository_owner=$(echo ${{ github.repository_owner }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_OUTPUT - name: Set up QEMU - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a - name: Set up Docker Buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e with: version: latest diff --git a/.github/workflows/global-run-codeql.yaml b/.github/workflows/global-run-codeql.yaml index 451f174b..2bee8491 100644 --- a/.github/workflows/global-run-codeql.yaml +++ b/.github/workflows/global-run-codeql.yaml @@ -28,7 +28,7 @@ jobs: uses: actions/checkout@v7 - name: Install Go - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version-file: go.mod diff --git a/.github/workflows/global-run-stale.yaml b/.github/workflows/global-run-stale.yaml index 1d30b0d4..ace5afa7 100644 --- a/.github/workflows/global-run-stale.yaml +++ b/.github/workflows/global-run-stale.yaml @@ -14,7 +14,7 @@ jobs: issues: write # for actions/stale to close stale issues pull-requests: write # for actions/stale to close stale PRs steps: - - uses: actions/stale@v10 + - uses: actions/stale@v11 with: stale-issue-message: 'This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.' # turn off stale for both issues and PRs diff --git a/.github/workflows/go.yaml b/.github/workflows/go.yaml index 402b6c2a..155c4a75 100644 --- a/.github/workflows/go.yaml +++ b/.github/workflows/go.yaml @@ -30,7 +30,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" cache: false @@ -43,7 +43,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" cache: false @@ -57,7 +57,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" cache: false @@ -70,7 +70,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" cache: false @@ -83,7 +83,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: "go.mod" - run: make manifests