Skip to content

Update all dependencies - #42

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Aug 5, 2024 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/checkout action major v5 → v7 age confidence
actions/download-artifact action major v5 → v8 age confidence
actions/setup-java action major v5 → v6 age confidence
actions/upload-artifact action major v4 → v7 age confidence
github/codeql-action action major v3 → v4 age confidence
gradle (source) minor 9.1.0 → 9.8.0 age confidence
gradle/actions action major v4.4.3 → v6.4.0 age confidence
mikepenz/action-junit-report action major v5 → v6 age confidence
net.researchgate.release plugin minor 3.1.0 → 3.2.0 age confidence
org.testcontainers:junit-jupiter (source) dependencies patch 1.21.3 → 1.21.4 age confidence
org.testcontainers:testcontainers (source) dependencies major 1.21.3 → 2.0.5 age confidence
org.assertj:assertj-core (source) dependencies patch 3.27.5 → 3.27.7 age confidence
org.junit.jupiter:junit-jupiter (source) dependencies major 5.13.4 → 6.1.3 age confidence
org.junit:junit-bom (source) dependencies major 5.13.4 → 6.1.3 age confidence

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

  • Block checking out fork PR for pull_request_target and workflow_run by @​aiqiaoy in #​2454
  • Various dependency updates

v6.1.0

Compare Source

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

Compare Source

v6.0.2

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

actions/download-artifact (actions/download-artifact)

v8.0.1

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

Compare Source

v8 - What's new

[!IMPORTANT]
actions/download-artifact@​v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT]
Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @​actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v7.0.0

Compare Source

v7 - What's new

[!IMPORTANT]
actions/download-artifact@​v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

New Contributors

Full Changelog: actions/download-artifact@v6.0.0...v7.0.0

v6.0.0

Compare Source

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

New Contributors

Full Changelog: actions/download-artifact@v5...v6.0.0

actions/setup-java (actions/setup-java)

v6.0.1

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v6.0.0...v6.0.1

v6.0.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v5.7.0...v6.0.0

actions/upload-artifact (actions/upload-artifact)

v7.0.1

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

Compare Source

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

Compare Source

v6 - What's new

[!IMPORTANT]
actions/upload-artifact@​v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

Compare Source

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

New Contributors

Full Changelog: actions/upload-artifact@v4...v5.0.0

github/codeql-action (github/codeql-action)

v4.38.2

Compare Source

v4.38.1

Compare Source

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #​4146

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v4.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v4.37.4

Compare Source

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #​4037
  • Update default CodeQL bundle version to 2.26.2. #​4051

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

v4.36.2

Compare Source

  • Cache CodeQL CLI version information across Actions steps. #​3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #​3937
  • Update default CodeQL bundle version to 2.25.6. #​3948

v4.36.1

Compare Source

No user facing changes.

[v4.36.0](https://redirect.github.com/github/codeql-action/releases/

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 618333c to fc5907b Compare August 14, 2024 14:43
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 11f8c5d to 12a1088 Compare September 13, 2024 05:00
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from fc87ab4 to 90a8995 Compare September 25, 2024 11:09
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 7d76f2f to 4b0d4da Compare October 4, 2024 15:02
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 33702eb to f3981f7 Compare October 23, 2024 01:28
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 9e595c9 to a2342fa Compare November 12, 2024 20:57
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 4d43261 to 2fa95ad Compare November 20, 2024 23:22
@renovate renovate Bot changed the title chore(deps): update all dependencies fix(deps): update all dependencies Dec 10, 2024
@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from b37e4b9 to 7d3bd5f Compare December 20, 2024 17:33
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from d4fc2cc to 449a9f4 Compare January 4, 2025 13:46
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from f501ad7 to 9bc57e0 Compare January 24, 2025 13:46
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 8bea77c to ccb32ed Compare February 21, 2025 19:10
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 2df1c75 to a066c1e Compare June 11, 2025 23:15
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 7ff8d10 to 8873464 Compare June 24, 2025 13:46
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from ab2c7c7 to b22191d Compare July 4, 2025 15:40
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 26c4c5c to 3a1147e Compare August 11, 2025 14:59
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 01cf560 to b99a4f7 Compare September 19, 2025 01:04
@renovate renovate Bot changed the title fix(deps): update all dependencies fix(deps): update all dependencies - autoclosed Sep 22, 2025
@renovate renovate Bot closed this Sep 22, 2025
@renovate
renovate Bot deleted the renovate/all branch September 22, 2025 16:46
@renovate renovate Bot changed the title fix(deps): update all dependencies - autoclosed fix(deps): update all dependencies Sep 29, 2025
@renovate renovate Bot reopened this Sep 29, 2025
@renovate renovate Bot changed the title fix(deps): update all dependencies fix(deps): update dependency org.assertj:assertj-core to v3.27.6 Sep 29, 2025
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 950c03f to d5f75a2 Compare September 29, 2025 15:04
@renovate renovate Bot changed the title fix(deps): update dependency org.assertj:assertj-core to v3.27.6 fix(deps): update all dependencies Sep 29, 2025
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 88e91d3 to 0fbc945 Compare October 1, 2025 21:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants