Compare commits

..
Author SHA1 Message Date
Tõnis Tiigi 03b4d6cac0 Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
prevent workflow command injection in metadata logs
2026-09-10 18:13:15 -07:00
CrazyMax dcc3c70566 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-09-10 10:11:25 +02:00
CrazyMax 2145b7d858 prevent workflow command injection in metadata logs
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-09-10 10:11:24 +02:00
CrazyMax 104b27ceb2 Merge pull request #1616 from docker/dependabot/github_actions/codeql-actions-f1ba23a83b
chore(deps): Bump the codeql-actions group with 2 updates
2026-09-09 15:39:13 +02:00
CrazyMax 9b2a2073c3 Merge pull request #1615 from docker/dependabot/npm_and_yarn/js-yaml-4.3.2
chore(deps): Bump js-yaml from 4.3.1 to 4.3.2
2026-09-09 15:38:48 +02:00
dependabot[bot] 5f00bd7ece chore(deps): Bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.6 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...cdf488f595d80d6e07e03d4674febd5ab45fa938)

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...cdf488f595d80d6e07e03d4674febd5ab45fa938)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 11:54:23 +00:00
dependabot[bot] aeeb70cc49 chore(deps): Bump js-yaml from 4.3.1 to 4.3.2
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 10:53:55 +00:00
CrazyMax 27c552b342 Merge pull request #1614 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.98.0
chore(deps): Bump @docker/actions-toolkit from 0.92.0 to 0.98.0
2026-09-09 12:52:05 +02:00
github-actions[bot] 35a05cc103 [dependabot skip] chore: update generated content 2026-09-09 09:13:01 +00:00
dependabot[bot] 4e660f2e30 chore(deps): Bump @docker/actions-toolkit from 0.92.0 to 0.98.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.98.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.92.0...v0.98.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.98.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:12:13 +00:00
CrazyMax bb0f4e3f0e Merge pull request #1592 from docker/dependabot/npm_and_yarn/brace-expansion-1.1.18
chore(deps): Bump brace-expansion from 1.1.13 to 1.1.18
2026-09-09 11:10:10 +02:00
github-actions[bot] 213f379438 [dependabot skip] chore: update generated content 2026-09-09 09:08:06 +00:00
dependabot[bot] 9faad81e8c chore(deps): Bump brace-expansion from 1.1.13 to 1.1.18
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.13 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:07:16 +00:00
CrazyMax d1b4d6a4ee Merge pull request #1605 from docker/dependabot/npm_and_yarn/js-yaml-4.3.1
chore(deps): Bump js-yaml from 4.3.0 to 4.3.1
2026-09-09 11:04:47 +02:00
CrazyMax 12f4b5e353 Merge pull request #1613 from docker/dependabot/npm_and_yarn/csv-parse-7.0.2
chore(deps): Bump csv-parse from 7.0.0 to 7.0.2
2026-09-09 11:04:24 +02:00
CrazyMax 5d2ba96cd6 Merge pull request #1611 from docker/dependabot/npm_and_yarn/nanoid-3.3.18
chore(deps): Bump nanoid from 3.3.16 to 3.3.18
2026-09-09 11:03:24 +02:00
github-actions[bot] c4f5168a02 [dependabot skip] chore: update generated content 2026-09-09 09:02:52 +00:00
dependabot[bot] b2993c26f2 chore(deps): Bump csv-parse from 7.0.0 to 7.0.2
Bumps [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse) from 7.0.0 to 7.0.2.
- [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md)
- [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.2/packages/csv-parse)

---
updated-dependencies:
- dependency-name: csv-parse
  dependency-version: 7.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:01:54 +00:00
dependabot[bot] da299cd21b chore(deps): Bump nanoid from 3.3.16 to 3.3.18
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.16 to 3.3.18.
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md)
- [Commits](https://github.com/ai/nanoid/compare/3.3.16...3.3.18)

---
updated-dependencies:
- dependency-name: nanoid
  dependency-version: 3.3.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:01:30 +00:00
dependabot[bot] 5ea3152e64 chore(deps): Bump js-yaml from 4.3.0 to 4.3.1
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-28 00:41:10 +00:00
6 changed files with 152 additions and 152 deletions
+2 -2
View File
@@ -35,12 +35,12 @@ jobs:
node-version: ${{ env.NODE_VERSION }}
-
name: Initialize CodeQL
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: javascript-typescript
build-mode: none
-
name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
category: "/language:javascript-typescript"
Generated Vendored
+136 -136
View File
File diff suppressed because one or more lines are too long
Generated Vendored
+3 -3
View File
File diff suppressed because one or more lines are too long
Generated Vendored
+1 -1
View File
@@ -3289,7 +3289,7 @@ USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm packages may be included in this product:
- brace-expansion@1.1.13
- brace-expansion@1.1.18
- brace-expansion@2.0.2
These packages each contain the following license:
+1 -1
View File
@@ -137,7 +137,7 @@ actionsToolkit.run(
if (metadata) {
await core.group(`Metadata`, async () => {
const metadatadt = JSON.stringify(metadata, null, 2);
core.info(metadatadt);
GitHub.printUntrusted(metadatadt);
core.setOutput('metadata', metadatadt);
});
}
+9 -9
View File
@@ -2436,12 +2436,12 @@ __metadata:
linkType: hard
"brace-expansion@npm:^1.1.7":
version: 1.1.13
resolution: "brace-expansion@npm:1.1.13"
version: 1.1.18
resolution: "brace-expansion@npm:1.1.18"
dependencies:
balanced-match: "npm:^1.0.0"
concat-map: "npm:0.0.1"
checksum: 10/b5f4329fdbe9d2e25fa250c8f866ebd054ba946179426e99b86dcccddabdb1d481f0e40ee5430032e62a7d0a6c2837605ace6783d015aa1d65d85ca72154d936
checksum: 10/b55a3c03239b8d2127c7cbb3408c9ad3a556a8c303bf3064df78bfb7c093160fc8f6e0a32e42a850a78eba12f29ccf6ef997690b9acf945d242c56c61c4aa977
languageName: node
linkType: hard
@@ -4002,13 +4002,13 @@ __metadata:
linkType: hard
"js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1":
version: 4.3.0
resolution: "js-yaml@npm:4.3.0"
version: 4.3.2
resolution: "js-yaml@npm:4.3.2"
dependencies:
argparse: "npm:^2.0.1"
bin:
js-yaml: bin/js-yaml.js
checksum: 10/2bcec3a8118d7f744badeb04e14366578d234a736f353d41fe35d2305e4ce2409a8e041d277f07cd6bbc8aaa12128d650a68ce43247072519bede20962d2126f
checksum: 10/05c44b9c73e4901d92703b155e76518df64bf01ac62e4c036b47de4b391e19b72e32656e8954d51b436307f08cc9d0c0d4ec617d061cf2f65fffee9f3114bee7
languageName: node
linkType: hard
@@ -4543,11 +4543,11 @@ __metadata:
linkType: hard
"nanoid@npm:^3.3.16":
version: 3.3.16
resolution: "nanoid@npm:3.3.16"
version: 3.3.18
resolution: "nanoid@npm:3.3.18"
bin:
nanoid: bin/nanoid.cjs
checksum: 10/8004af92b5541af1dbd23b69845b5026f777d5b7ef07163cea1837aae86e052ced8b383cecbf8a4f1b5e77ae207df96dc45e16b9e0fa3c4b761d085f1e42851b
checksum: 10/1b3b4fdac831b92b56d1dbe8b1e63a372432faf86ea383134e3b53141ef8108a60b7f84343b5cefecac9550bb74edf8164da93ea07d1c4f757039bc75d8a5d9e
languageName: node
linkType: hard