renovate[bot]
8b8ef0f410
chore(actions): update anchore/sbom-action action (v0.23.1 → v0.24.0)
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-22 14:54:50 +00:00
3848c1cff6
chore(deps): update go deps ( #199 )
2026-03-22 16:54:28 +02:00
c2861dbffa
Revert "chore(deps): update go deps"
...
This reverts commit 4e1c1bc495 .
2026-03-22 16:50:50 +02:00
4e1c1bc495
chore(deps): update go deps
2026-03-22 16:46:33 +02:00
c9347aa598
fix(security): add missing gitleaks ignore entries for test tokens ( #197 )
...
- Added 10 fingerprints to .gitleaksignore for test tokens in historical commits
- Broadened .gitleaks.toml path allowlist to cover all *_test.go files
2026-03-22 14:24:07 +02:00
renovate[bot]
49d6923a24
chore(actions): update ivuorinen/actions action (v2026.03.11 → v2026.03.14) ( #196 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-16 08:16:54 +02:00
Copilot
e80c8bb3bf
chore(security): add gitleaks config and update ignore list for test tokens ( #195 )
2026-03-15 17:22:50 +02:00
renovate[bot]
64ee9e8dd6
chore(actions): update ivuorinen/actions action (v2026.03.10 → v2026.03.11) ( #194 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-13 20:01:37 +02:00
Copilot
db3496d802
chore: upgrade Go/deps/workflows to latest and fix gosec regressions ( #193 )
2026-03-12 19:59:12 +02:00
renovate[bot]
c9b1654b96
chore(actions): update ivuorinen/actions action (v2026.03.09 → v2026.03.10) ( #191 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-11 03:06:46 +00:00
d266beab79
ci: enforce least-privilege permissions and update workflows ( #188 )
...
* ci: add permissions: {} to CI workflow with job-level contents: read
* ci: enforce least-privilege permissions in security workflow
* ci: enforce least-privilege permissions in commitlint workflow
* ci: enforce least-privilege permissions in pr-lint workflow and update actions
* ci: enforce least-privilege permissions in stale workflow and update actions
* ci: enforce least-privilege permissions in sync-labels workflow and update actions
* ci: enforce least-privilege permissions in release workflow and update actions
* chore(actions): update ivuorinen/actions/codeql-analysis (v2026.03.06 → v2026.03.09)
* chore(deps): update testdata composite action dependencies
2026-03-10 19:08:53 +02:00
042b7a27a4
fix: install commit-msg hook for local commitlint checks ( #189 )
2026-03-10 18:08:55 +02:00
renovate[bot]
ddf674d4c9
chore(actions): update aquasecurity/trivy-action action (0.34.2 → 0.35.0) ( #187 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 03:13:06 +02:00
renovate[bot]
968fc9f98b
chore(deps): update dependency go (1.26.0 → 1.26.1) ( #186 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 03:12:35 +02:00
renovate[bot]
97ff99caea
chore(deps): update actions/dependency-review-action action (v4.8.3 → v4.9.0) ( #183 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-07 19:56:08 +02:00
renovate[bot]
fbbe021fed
chore(deps): update actions/setup-node action (v6.2.0 → v6.3.0) ( #184 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-07 18:47:30 +02:00
9845a0d777
ci: migrate CodeQL to ivuorinen/actions/codeql-analysis ( #185 )
...
* ci: migrate codeql to composable workflow
* fix: correct codeql workflow language, queries, permissions, and action ref
- Use 'javascript' instead of 'javascript-typescript' for CodeQL language
- Add queries: security-and-quality parameter
- Set root-level permissions to {}
- Add job-level permissions (actions, contents, packages, security-events)
- Pin action ref to commit hash with version comment
- Fix mangled cron schedule
2026-03-07 18:38:19 +02:00
renovate[bot]
8e1f51d1d4
chore(deps): update ivuorinen/actions action (v2026.02.28 → v2026.03.02) ( #182 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-05 23:33:28 +02:00
renovate[bot]
39ea382811
chore(deps): update aquasecurity/trivy-action action (0.34.1 → 0.34.2) ( #180 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-05 23:21:38 +02:00
renovate[bot]
2d6b874a55
chore(deps): update github/codeql-action action (v4.32.4 → v4.32.6) ( #181 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-05 22:41:53 +02:00
renovate[bot]
2c5a968b48
chore(deps): update ivuorinen/actions action (v2026.02.24 → v2026.02.28) ( #179 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-02 11:13:53 +02:00
renovate[bot]
caf3ede64b
chore(deps): update actions/setup-go action (v6.2.0 → v6.3.0) ( #178 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-01 04:43:27 +00:00
renovate[bot]
4bceee2069
chore(deps)!: update actions/upload-artifact (v6.0.0 → v7.0.0) ( #177 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-27 23:26:41 +02:00
renovate[bot]
fac4e97a9a
chore(deps)!: update goreleaser/goreleaser-action (v6.4.0 → v7.0.0) ( #173 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-27 11:56:13 +02:00
renovate[bot]
d973b9a130
chore(deps): update anchore/sbom-action action (v0.22.2 → v0.23.0) ( #176 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-27 11:18:07 +02:00
renovate[bot]
16348431b0
chore(deps): update ivuorinen/actions action (v2026.02.18 → v2026.02.24) ( #175 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-26 05:35:47 +00:00
renovate[bot]
4440354048
chore(deps): update aquasecurity/trivy-action action (0.34.0 → 0.34.1) ( #174 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-23 21:26:26 +02:00
renovate[bot]
5d8383951e
chore(deps): update github/codeql-action action (v4.32.3 → v4.32.4) ( #172 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-22 19:16:40 +02:00
renovate[bot]
8562c248df
chore(deps): update actions/dependency-review-action action (v4.8.2 → v4.8.3) ( #171 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-22 05:26:06 +00:00
renovate[bot]
e7ab7074b1
chore(deps): update ivuorinen/actions action (v2026.02.10 → v2026.02.18) ( #170 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-20 05:40:16 +00:00
renovate[bot]
f3d1f5f459
chore(deps): update pre-commit hook davidanson/markdownlint-cli2 (v0.20.0 → v0.21.0) ( #169 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-18 06:10:28 +00:00
renovate[bot]
81ced12ffe
chore(deps): update pre-commit hook rhysd/actionlint (v1.7.10 → v1.7.11) ( #168 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-16 22:49:01 +00:00
renovate[bot]
5aa33336e6
chore(deps): update github/codeql-action action (v4.32.2 → v4.32.3) ( #167 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-15 13:37:58 +00:00
renovate[bot]
139cc504f5
chore(deps): update aquasecurity/trivy-action action (0.33.1 → 0.34.0) ( #166 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-14 05:51:57 +00:00
renovate[bot]
3d9fb03a1a
chore(deps): update go (1.25.7 → 1.26.0) ( #165 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 08:49:41 +00:00
renovate[bot]
716a2e3d60
chore(deps): update ivuorinen/actions action (v2026.02.03 → v2026.02.10) ( #164 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 05:39:14 +00:00
renovate[bot]
4b32e263d7
fix(deps): update module golang.org/x/oauth2 (v0.34.0 → v0.35.0) ( #163 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-08 18:43:27 +02:00
renovate[bot]
16c6969feb
chore(deps): update github/codeql-action action (v4.32.1 → v4.32.2) ( #162 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-07 23:47:06 +02:00
renovate[bot]
b2ad49249b
chore(deps): update anchore/sbom-action action (v0.22.1 → v0.22.2) ( #160 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-06 16:36:31 +00:00
renovate[bot]
e494934804
chore(deps): update go (1.25.6 → 1.25.7) ( #161 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-06 16:01:05 +02:00
renovate[bot]
29625f8b6d
chore(deps): update ivuorinen/actions action (v2026.01.21 → v2026.02.03) ( #159 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-05 09:27:16 +02:00
renovate[bot]
e0f55d590b
chore(deps): update github/codeql-action action (v4.32.0 → v4.32.1) ( #158 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-04 01:15:40 +00:00
renovate[bot]
e7f9218ad8
chore(deps): update pre-commit hook editorconfig-checker/editorconfig-checker (v3.6.0 → v3.6.1) ( #156 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-30 21:05:34 +02:00
renovate[bot]
e9dec027b9
chore(deps): update docker/login-action action (v3.6.0 → v3.7.0) ( #157 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-30 19:32:41 +02:00
renovate[bot]
7c6532fb21
chore(deps): update anchore/sbom-action action (v0.22.0 → v0.22.1) ( #155 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-29 12:51:59 +00:00
renovate[bot]
9f145dedfe
chore(deps): update github/codeql-action action (v4.31.11 → v4.32.0) ( #154 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-28 05:49:30 +00:00
renovate[bot]
78481459f5
chore(deps): update github/codeql-action action (v4.31.10 → v4.31.11) ( #153 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-26 02:02:13 +00:00
renovate[bot]
9e25e0925f
chore(deps): update actions/checkout action (v6.0.1 → v6.0.2) ( #152 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-24 18:48:44 +02:00
renovate[bot]
9c7be8c5d4
chore(deps): update anchore/sbom-action action (v0.21.1 → v0.22.0) ( #151 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-23 09:03:38 +02:00
renovate[bot]
a75d892747
chore(deps): update ivuorinen/actions action (v2026.01.13 → v2026.01.21) ( #150 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-23 05:50:13 +00:00