Skip to content

Commit 3e2cada

Browse files
chore(deps): update github actions
1 parent 8b34de5 commit 3e2cada

18 files changed

+41
-41
lines changed

.github/workflows/auto-update-otel-sdk.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ jobs:
7272
java-version-file: .java-version
7373

7474
- name: Setup Gradle
75-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
75+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
7676

7777
- name: Update license report
7878
run: ./gradlew generateLicenseReport

.github/workflows/build-common.yml

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
java-version-file: .java-version
3939

4040
- name: Setup Gradle
41-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
41+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
4242
with:
4343
cache-read-only: ${{ inputs.cache-read-only }}
4444
# gradle enterprise is used for the build cache
@@ -54,7 +54,7 @@ jobs:
5454
steps:
5555
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
5656

57-
- uses: gradle/actions/wrapper-validation@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
57+
- uses: gradle/actions/wrapper-validation@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
5858

5959
license-check:
6060
runs-on: ubuntu-latest
@@ -71,7 +71,7 @@ jobs:
7171
java-version-file: .java-version
7272

7373
- name: Setup Gradle
74-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
74+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
7575
with:
7676
cache-read-only: ${{ inputs.cache-read-only }}
7777
# gradle enterprise is used for the build cache
@@ -145,7 +145,7 @@ jobs:
145145
sed -i "s/org.gradle.jvmargs=/org.gradle.jvmargs=-Xmx3g /" gradle.properties
146146
147147
- name: Setup Gradle
148-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
148+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
149149
with:
150150
cache-read-only: ${{ inputs.cache-read-only }}
151151
# gradle enterprise is used for the build cache
@@ -172,7 +172,7 @@ jobs:
172172
fi
173173
174174
- name: Upload agent jar
175-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
175+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
176176
with:
177177
name: opentelemetry-javaagent.jar
178178
path: javaagent/build/libs/opentelemetry-javaagent-*-SNAPSHOT.jar
@@ -183,7 +183,7 @@ jobs:
183183
mkdir sboms
184184
cp javaagent/build/spdx/*.spdx.json sboms
185185
186-
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
186+
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
187187
name: Upload SBOMs
188188
with:
189189
name: opentelemetry-java-instrumentation-SBOM.zip
@@ -235,7 +235,7 @@ jobs:
235235

236236
# vaadin 14 tests fail with node 18
237237
- name: Set up Node
238-
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
238+
uses: actions/setup-node@1e60f620b9541d16bece96c5465dc8ee9832be0b # v4.0.3
239239
with:
240240
node-version: 16
241241

@@ -250,7 +250,7 @@ jobs:
250250
run: .github/scripts/deadlock-detector.sh
251251

252252
- name: Setup Gradle
253-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
253+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
254254
with:
255255
# only push cache for one matrix option since github action cache space is limited
256256
cache-read-only: ${{ inputs.cache-read-only || matrix.test-java-version != 11 || matrix.vm != 'hotspot' }}
@@ -292,15 +292,15 @@ jobs:
292292

293293
- name: Upload deadlock detector artifacts if any
294294
if: failure()
295-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
295+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
296296
with:
297297
name: deadlock-detector-test-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
298298
path: /tmp/deadlock-detector-*
299299
if-no-files-found: ignore
300300

301301
- name: Upload jvm crash dump files if any
302302
if: failure()
303-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
303+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
304304
with:
305305
name: javacore-test-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
306306
path: |
@@ -349,7 +349,7 @@ jobs:
349349
java-version-file: .java-version
350350

351351
- name: Set up Gradle cache
352-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
352+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
353353
with:
354354
# only push cache for one matrix option per OS since github action cache space is limited
355355
cache-read-only: ${{ inputs.cache-read-only || matrix.smoke-test-suite != 'tomcat' }}
@@ -369,7 +369,7 @@ jobs:
369369

370370
- name: Upload jvm crash dump files if any
371371
if: failure()
372-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
372+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
373373
with:
374374
name: javacore-smoke-test-${{ matrix.smoke-test-suite }}-${{ matrix.os }}
375375
# we expect crash dumps either in root director or in smoke-tests
@@ -402,7 +402,7 @@ jobs:
402402
java-version-file: .java-version
403403

404404
- name: Setup Gradle
405-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
405+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
406406
with:
407407
cache-read-only: ${{ inputs.cache-read-only }}
408408

@@ -425,7 +425,7 @@ jobs:
425425
java-version-file: .java-version
426426

427427
- name: Set up Gradle cache
428-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
428+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
429429
with:
430430
cache-read-only: ${{ inputs.cache-read-only }}
431431

.github/workflows/build.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ jobs:
7373
java-version-file: .java-version
7474

7575
- name: Setup Gradle
76-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
76+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
7777
with:
7878
# gradle enterprise is used for the build cache
7979
gradle-home-cache-excludes: caches/build-cache-1

.github/workflows/codeql-daily.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,22 +30,22 @@ jobs:
3030
java-version-file: .java-version
3131

3232
- name: Initialize CodeQL
33-
uses: github/codeql-action/init@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
33+
uses: github/codeql-action/init@2d790406f505036ef40ecba973cc774a50395aac # v3.25.13
3434
with:
3535
languages: java
3636
# using "latest" helps to keep up with the latest Kotlin support
3737
# see https://github.com/github/codeql-action/issues/1555#issuecomment-1452228433
3838
tools: latest
3939

4040
- name: Setup Gradle
41-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
41+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
4242

4343
- name: Build
4444
# skipping build cache is needed so that all modules will be analyzed
4545
run: ./gradlew assemble -x javadoc --no-build-cache --no-daemon
4646

4747
- name: Perform CodeQL analysis
48-
uses: github/codeql-action/analyze@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
48+
uses: github/codeql-action/analyze@2d790406f505036ef40ecba973cc774a50395aac # v3.25.13
4949

5050
workflow-notification:
5151
needs:

.github/workflows/overhead-benchmark-daily.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
rsync -avv gh-pages/benchmark-overhead/results/ benchmark-overhead/results/
2525
2626
- name: Setup Gradle
27-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
27+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
2828

2929
- name: Run tests
3030
working-directory: benchmark-overhead

.github/workflows/owasp-dependency-check-daily.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,15 +28,15 @@ jobs:
2828
run: |
2929
sed -i "s/org.gradle.jvmargs=/org.gradle.jvmargs=-Xmx3g /" gradle.properties
3030
31-
- uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
31+
- uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
3232

3333
- run: ./gradlew :javaagent:dependencyCheckAnalyze
3434
env:
3535
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
3636

3737
- name: Upload report
3838
if: always()
39-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
39+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
4040
with:
4141
path: javaagent/build/reports
4242

.github/workflows/pr-smoke-test-early-jdk8-images.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
java-version-file: .java-version
2626

2727
- name: Setup Gradle
28-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
28+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
2929
with:
3030
cache-read-only: true
3131
# gradle enterprise is used for the build cache

.github/workflows/pr-smoke-test-fake-backend-images.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
java-version-file: .java-version
2626

2727
- name: Setup Gradle
28-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
28+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
2929
with:
3030
cache-read-only: true
3131
# gradle enterprise is used for the build cache
@@ -52,7 +52,7 @@ jobs:
5252
java-version-file: .java-version
5353

5454
- name: Setup Gradle
55-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
55+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
5656
with:
5757
cache-read-only: true
5858

.github/workflows/pr-smoke-test-servlet-images.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ jobs:
4343
java-version-file: .java-version
4444

4545
- name: Set up Gradle cache
46-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
46+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
4747
with:
4848
cache-read-only: true
4949

.github/workflows/publish-smoke-test-early-jdk8-images.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
3636

3737
- name: Setup Gradle
38-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
38+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
3939

4040
- name: Build Docker image
4141
run: ./gradlew :smoke-tests:images:early-jdk8:dockerPush -PextraTag=${{ env.TAG }}

.github/workflows/publish-smoke-test-fake-backend-images.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
3636

3737
- name: Setup Gradle
38-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
38+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
3939

4040
- name: Build Docker image
4141
run: ./gradlew :smoke-tests:images:fake-backend:jib -Djib.httpTimeout=120000 -Djib.console=plain -PextraTag=${{ env.TAG }}
@@ -68,7 +68,7 @@ jobs:
6868
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
6969

7070
- name: Setup Gradle
71-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
71+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
7272

7373
- name: Build Docker image
7474
run: ./gradlew :smoke-tests:images:fake-backend:dockerPush -PextraTag=${{ env.TAG }}

.github/workflows/publish-smoke-test-servlet-images.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ jobs:
6767
password: ${{ secrets.GITHUB_TOKEN }}
6868

6969
- name: Set up Gradle cache
70-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
70+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
7171
with:
7272
# only push cache for one matrix option per OS since github action cache space is limited
7373
cache-read-only: ${{ matrix.smoke-test-suite != 'tomcat' }}

.github/workflows/release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
java-version-file: .java-version
8787

8888
- name: Setup Gradle
89-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
89+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
9090

9191
- name: Build and publish artifacts
9292
env:
@@ -114,7 +114,7 @@ jobs:
114114
cp javaagent/build/spdx/*.spdx.json sboms
115115
zip opentelemetry-java-instrumentation-SBOM.zip sboms/*
116116
117-
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
117+
- uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
118118
name: Upload SBOMs
119119
with:
120120
name: opentelemetry-java-instrumentation-SBOM

.github/workflows/reusable-muzzle.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
java-version-file: .java-version
3535

3636
- name: Setup Gradle
37-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
37+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
3838
with:
3939
cache-read-only: ${{ inputs.cache-read-only }}
4040

.github/workflows/reusable-smoke-test-images.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ jobs:
6161
run: echo "TAG=$(date '+%Y%m%d').$GITHUB_RUN_ID" >> $GITHUB_ENV
6262

6363
- name: Set up Gradle cache
64-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
64+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
6565
with:
6666
cache-read-only: ${{ inputs.cache-read-only }}
6767

.github/workflows/reusable-test-indy.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646
4747
# vaadin 14 tests fail with node 18
4848
- name: Set up Node
49-
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
49+
uses: actions/setup-node@1e60f620b9541d16bece96c5465dc8ee9832be0b # v4.0.3
5050
with:
5151
node-version: 16
5252

@@ -58,7 +58,7 @@ jobs:
5858
key: ${{ runner.os }}-test-latest-cache-pnpm-modules
5959

6060
- name: Setup Gradle
61-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
61+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
6262
with:
6363
cache-read-only: ${{ inputs.cache-read-only }}
6464
# gradle enterprise is used for the build cache

.github/workflows/reusable-test-latest-deps.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
run: .github/scripts/deadlock-detector.sh
5656

5757
- name: Setup Gradle
58-
uses: gradle/actions/setup-gradle@dbbdc275be76ac10734476cc723d82dfe7ec6eda # v3.4.2
58+
uses: gradle/actions/setup-gradle@d9c87d481d55275bb5441eef3fe0e46805f9ef70 # v3.5.0
5959
with:
6060
cache-read-only: ${{ inputs.cache-read-only }}
6161
# gradle enterprise is used for the build cache
@@ -90,15 +90,15 @@ jobs:
9090

9191
- name: Upload deadlock detector artifacts if any
9292
if: failure()
93-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
93+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
9494
with:
9595
name: deadlock-detector-test-latest-${{ matrix.test-java-version }}-${{ matrix.vm }}-${{ matrix.test-partition }}
9696
path: /tmp/deadlock-detector-*
9797
if-no-files-found: ignore
9898

9999
- name: Upload jvm crash dump files if any
100100
if: failure()
101-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
101+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
102102
with:
103103
name: javacore-test-latest-${{ matrix.test-java-version }}-${{ matrix.test-partition }}
104104
path: |

.github/workflows/scorecard.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -56,14 +56,14 @@ jobs:
5656
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
5757
# format to the repository Actions tab.
5858
- name: "Upload artifact"
59-
uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
59+
uses: actions/upload-artifact@0b2256b8c012f0828dc542b3febcab082c67f72b # v4.3.4
6060
with:
6161
name: SARIF file
6262
path: results.sarif
6363
retention-days: 5
6464

6565
# Upload the results to GitHub's code scanning dashboard.
6666
- name: "Upload to code-scanning"
67-
uses: github/codeql-action/upload-sarif@b611370bb5703a7efb587f9d136a52ea24c5c38c # v3.25.11
67+
uses: github/codeql-action/upload-sarif@2d790406f505036ef40ecba973cc774a50395aac # v3.25.13
6868
with:
6969
sarif_file: results.sarif

0 commit comments

Comments
 (0)