Skip to content

sec: pin github action versions#514

Merged
caarlos0 merged 1 commit into
masterfrom
pin
Nov 5, 2025
Merged

sec: pin github action versions#514
caarlos0 merged 1 commit into
masterfrom
pin

Conversation

@caarlos0

@caarlos0 caarlos0 commented Nov 5, 2025

Copy link
Copy Markdown
Member

using caarlos0/pinata

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
@caarlos0 caarlos0 self-assigned this Nov 5, 2025
@caarlos0 caarlos0 requested a review from crazy-max as a code owner November 5, 2025 13:10
@caarlos0 caarlos0 enabled auto-merge (squash) November 5, 2025 13:10
@caarlos0 caarlos0 requested a review from Copilot November 5, 2025 13:11

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enhances security by pinning GitHub Actions to specific commit SHAs instead of using mutable version tags. This follows security best practices to prevent supply chain attacks where action versions could be modified maliciously.

  • Replaces all mutable version tags (e.g., @v5) with immutable commit SHAs
  • Adds inline comments to document the version corresponding to each SHA
  • Updates actions across all workflow files: validate.yml, test.yml, and ci.yml

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
.github/workflows/validate.yml Pins actions/checkout, docker/bake-action, and docker/bake-action/subaction/list-targets to specific commit SHAs
.github/workflows/test.yml Pins actions/checkout, docker/bake-action, and codecov/codecov-action to specific commit SHAs
.github/workflows/ci.yml Pins actions/checkout, actions/setup-go, crazy-max/ghaction-import-gpg, and actions/upload-artifact to specific commit SHAs

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@coderabbitai

coderabbitai Bot commented Nov 5, 2025

Copy link
Copy Markdown

Walkthrough

Three GitHub workflow files (.github/workflows/ci.yml, .github/workflows/test.yml, and .github/workflows/validate.yml) have been updated to pin action dependencies to specific commit SHAs instead of semantic version tags. Each action reference now includes a corresponding version annotation as a comment. The changes affect workflow steps such as actions/checkout, actions/setup-go, docker/bake-action, crazy-max/ghaction-import-gpg, actions/upload-artifact, and codecov-action. No control-flow modifications, step reordering, or functional logic changes have been introduced.

Pre-merge checks

✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately and concisely describes the main change: pinning GitHub action versions in workflow files to specific commit SHAs.
Description check ✅ Passed The description is minimal but related to the changeset, referencing the tool (pinata) used to accomplish the version pinning.

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a08664b and 6680d41.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml (7 hunks)
  • .github/workflows/test.yml (1 hunks)
  • .github/workflows/validate.yml (2 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Agent
  • GitHub Check: ci (macos-latest, ~> 2.6, goreleaser-pro)
🔇 Additional comments (4)
.github/workflows/ci.yml (2)

53-53: Local action references correctly unpinned.

Lines referencing uses: ./ (local action from current repository) are appropriately not pinned, as they should reflect the current checkout state. External actions are properly pinned while local actions follow expected conventions.

Also applies to: 61-61, 96-96, 137-137, 146-146, 169-169, 175-175, 201-201, 235-235


43-43: Action version pinning applied consistently with verified SHAs.

All action references are pinned to specific commit SHAs with accurate version annotations. The SHA 08c6903cd8c0fde910a37f88322edcfb5dd907a8 correctly corresponds to v5.0.0 for actions/checkout, and identical SHAs are used across all occurrences of the same action versions. This ensures reproducible builds and supply chain security.

Also applies to: 48-48, 85-85, 90-90, 120-120, 125-125, 131-131, 159-159, 164-164, 181-181, 191-191, 196-196, 225-225, 230-230

.github/workflows/test.yml (1)

24-24: Action pins are consistent with other workflow files.

The pinned SHAs for actions/checkout and docker/bake-action match those in ci.yml and validate.yml respectively, confirming consistent application of the pinning strategy across all workflows.

Also applies to: 29-29, 35-35

.github/workflows/validate.yml (1)

26-26: Subaction and action references properly pinned with consistent SHAs.

The subaction path docker/bake-action/subaction/list-targets@SHA is correctly formatted, and both docker/bake-action references use the identical SHA for v6.9.0, maintaining consistency across the repository.

Also applies to: 30-30, 45-45


Comment @coderabbitai help to get the list of available commands and usage tips.

@caarlos0 caarlos0 merged commit aab4704 into master Nov 5, 2025
46 checks passed
@caarlos0 caarlos0 deleted the pin branch November 5, 2025 13:27
scornet256 added a commit to scornet256/gogitlabber that referenced this pull request May 18, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | action | major | `v6` → `v7` |

---

### Release Notes

<details>
<summary>goreleaser/goreleaser-action (goreleaser/goreleaser-action)</summary>

### [`v7.2.1`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.2.1)

[Compare Source](goreleaser/goreleaser-action@v7.2.0...v7.2.1)

This fully removes the usage of the old `nightly` moving tag.

**Full Changelog**: <goreleaser/goreleaser-action@v7.2.0...v7.2.1>

### [`v7.2.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.2.0)

[Compare Source](goreleaser/goreleaser-action@v7.1.0...v7.2.0)

#### What's Changed

- test: cover install across release eras by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;555](goreleaser/goreleaser-action#555)
- feat: add `version-file` input by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;556](goreleaser/goreleaser-action#556)
- feat: resolve nightly to latest vX.Y.Z-<sha>-nightly release by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;558](goreleaser/goreleaser-action#558)

**Full Changelog**: <goreleaser/goreleaser-action@v7...v7.2.0>

### [`v7.1.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.1.0)

[Compare Source](goreleaser/goreleaser-action@v7...v7.1.0)

#### What's Changed

- feat: verify release checksum and cosign signature by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;550](goreleaser/goreleaser-action#550)
- docs: document cosign verification in README by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;553](goreleaser/goreleaser-action#553)
- docs: Upgrade import GPG action version by [@&#8203;flecno](https://github.com/flecno) in [#&#8203;547](goreleaser/goreleaser-action#547)
- ci: drop docker-bake in favor of plain npm by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;551](goreleaser/goreleaser-action#551)
- ci: add release-major-tag workflow by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;552](goreleaser/goreleaser-action#552)
- ci: drop pre-cosign-v3 goreleaser versions from tests by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;554](goreleaser/goreleaser-action#554)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;543](goreleaser/goreleaser-action#543)
- ci(deps): bump the actions group with 5 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;546](goreleaser/goreleaser-action#546)
- chore(deps): bump undici from 6.23.0 to 6.24.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;545](goreleaser/goreleaser-action#545)

#### New Contributors

- [@&#8203;flecno](https://github.com/flecno) made their first contribution in [#&#8203;547](goreleaser/goreleaser-action#547)

**Full Changelog**: <goreleaser/goreleaser-action@v7...v7.1.0>

### [`v7.0.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.0.0)

[Compare Source](goreleaser/goreleaser-action@v7...v7)

#### What's Changed

- feat!: node 24, update deps, rm yarn, ESM by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;533](goreleaser/goreleaser-action#533)
- sec: pin github action versions by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;514](goreleaser/goreleaser-action#514)
- docs: Upgrade checkout GitHub Action in README.md by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;507](goreleaser/goreleaser-action#507)
- chore(deps): bump actions/checkout from 4 to 5 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;504](goreleaser/goreleaser-action#504)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;517](goreleaser/goreleaser-action#517)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;523](goreleaser/goreleaser-action#523)
- ci(deps): bump docker/bake-action from 6.9.0 to 6.10.0 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;526](goreleaser/goreleaser-action#526)
- ci(deps): bump the actions group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;532](goreleaser/goreleaser-action#532)
- ci(deps): bump actions/checkout from 6.0.1 to 6.0.2 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;534](goreleaser/goreleaser-action#534)
- chore(deps): bump the npm group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;536](goreleaser/goreleaser-action#536)
- chore(deps): bump [@&#8203;actions/http-client](https://github.com/actions/http-client) from 3.0.2 to 4.0.0 in the npm group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;537](goreleaser/goreleaser-action#537)
- ci(deps): bump docker/setup-buildx-action from 3.10.0 to 3.12.0 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;538](goreleaser/goreleaser-action#538)
- chore(deps): bump semver from 7.7.3 to 7.7.4 in the npm group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;539](goreleaser/goreleaser-action#539)

**Full Changelog**: <goreleaser/goreleaser-action@v6...v7.0.0>

### [`v7`](goreleaser/goreleaser-action@v6.4.0...v7)

[Compare Source](goreleaser/goreleaser-action@v6.4.0...v7)

### [`v6.4.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v6.4.0)

[Compare Source](goreleaser/goreleaser-action@v6.3.0...v6.4.0)

#### What's Changed

- ci: set contents read as default workflow permissions by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;494](goreleaser/goreleaser-action#494)
- fix: support .config directory for goreleaser config files  by [@&#8203;haya14busa](https://github.com/haya14busa) in [#&#8203;500](goreleaser/goreleaser-action#500)
- chore(deps): bump semver from 7.7.1 to 7.7.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;495](goreleaser/goreleaser-action#495)
- chore(deps): bump brace-expansion from 1.1.11 to 1.1.12 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;498](goreleaser/goreleaser-action#498)
- fix: do not get releases.json if version is specific by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;502](goreleaser/goreleaser-action#502)
- chore(deps): bump undici from 5.28.5 to 5.29.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;496](goreleaser/goreleaser-action#496)
- feat: retry downloading releases json by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;503](goreleaser/goreleaser-action#503)

#### New Contributors

- [@&#8203;haya14busa](https://github.com/haya14busa) made their first contribution in [#&#8203;500](goreleaser/goreleaser-action#500)

**Full Changelog**: <goreleaser/goreleaser-action@v6.3.0...v6.4.0>

### [`v6.3.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v6.3.0)

[Compare Source](goreleaser/goreleaser-action@v6.2.1...v6.3.0)

- Bump undici from 5.28.3 to 5.28.5 in [#&#8203;488](goreleaser/goreleaser-action#488)

**Full Changelog**: <goreleaser/goreleaser-action@v6.2.1...v6.3.0>

### [`v6.2.1`](https://github.com/goreleaser/goreleaser-action/releases/tag/v6.2.1)

[Compare Source](goreleaser/goreleaser-action@v6.2.0...v6.2.1)

#### What's Changed

This version of the actions adds support for GoReleaser Pro v2.7.0 versioning (which dropped the `-pro` suffix).
Older versions should work fine.

> \[!WARNING]
> This version is **required** for GoReleaser Pro v2.7.0+.
> Read more [here](https://goreleaser.com/blog/goreleaser-v2.7/).

**Full Changelog**: <goreleaser/goreleaser-action@v6.2.0...v6.2.1>

### [`v6.2.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v6.2.0)

[Compare Source](goreleaser/goreleaser-action@v6.1.0...v6.2.0)

#### What's Changed

This version of the actions adds support for GoReleaser Pro v2.7.0 versioning (which dropped the `-pro` suffix).
Older versions should work fine.

> \[!WARNING]
> This version is **required** for GoReleaser Pro v2.7.0+.
> Read more [here](https://goreleaser.com/blog/goreleaser-v2.7/).

**Full Changelog**: <goreleaser/goreleaser-action@v6.1.0...v6.2.0>

### [`v6.1.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v6.1.0)

[Compare Source](goreleaser/goreleaser-action@v6...v6.1.0)

#### What's Changed

- chore(deps): bump braces from 3.0.2 to 3.0.3 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;467](goreleaser/goreleaser-action#467)
- chore(deps): bump docker/bake-action from 4 to 5 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;468](goreleaser/goreleaser-action#468)
- chore(deps): bump semver from 7.6.2 to 7.6.3 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;470](goreleaser/goreleaser-action#470)
- chore(deps): bump [@&#8203;actions/http-client](https://github.com/actions/http-client) from 2.2.1 to 2.2.2 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;473](goreleaser/goreleaser-action#473)
- chore(deps): bump [@&#8203;actions/http-client](https://github.com/actions/http-client) from 2.2.2 to 2.2.3 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;474](goreleaser/goreleaser-action#474)
- chore(deps): bump micromatch from 4.0.5 to 4.0.8 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;475](goreleaser/goreleaser-action#475)
- chore(deps): bump [@&#8203;actions/core](https://github.com/actions/core) from 1.10.1 to 1.11.1 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;478](goreleaser/goreleaser-action#478)
- docs: bump upload-artifact version by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;479](goreleaser/goreleaser-action#479)
- chore: update generated content by [@&#8203;crazy-max](https://github.com/crazy-max) in [#&#8203;480](goreleaser/goreleaser-action#480)

#### New Contributors

- [@&#8203;dunglas](https://github.com/dunglas) made their first contribution in [#&#8203;479](goreleaser/goreleaser-action#479)

**Full Changelog**: <goreleaser/goreleaser-action@v6.0.0...v6.1.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE2NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.simoncor.net/golang/gogitlabber/pulls/2
scornet256 added a commit to scornet256/go-logger that referenced this pull request Jun 5, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | action | major | `v6` → `v7` |

---

### Release Notes

<details>
<summary>goreleaser/goreleaser-action (goreleaser/goreleaser-action)</summary>

### [`v7.2.2`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.2.2)

[Compare Source](goreleaser/goreleaser-action@v7.2.1...v7.2.2)

#### What's Changed

- ci(deps): bump the actions group with 3 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;560](goreleaser/goreleaser-action#560)
- fix: nightly resolution to select newest published release by [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;562](goreleaser/goreleaser-action#562)

#### New Contributors

- [@&#8203;Copilot](https://github.com/Copilot) made their first contribution in [#&#8203;562](goreleaser/goreleaser-action#562)

**Full Changelog**: <goreleaser/goreleaser-action@v7...v7.2.2>

### [`v7.2.1`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.2.1)

[Compare Source](goreleaser/goreleaser-action@v7.2.0...v7.2.1)

This fully removes the usage of the old `nightly` moving tag.

**Full Changelog**: <goreleaser/goreleaser-action@v7.2.0...v7.2.1>

### [`v7.2.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.2.0)

[Compare Source](goreleaser/goreleaser-action@v7.1.0...v7.2.0)

#### What's Changed

- test: cover install across release eras by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;555](goreleaser/goreleaser-action#555)
- feat: add `version-file` input by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;556](goreleaser/goreleaser-action#556)
- feat: resolve nightly to latest vX.Y.Z-<sha>-nightly release by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;558](goreleaser/goreleaser-action#558)

**Full Changelog**: <goreleaser/goreleaser-action@v7...v7.2.0>

### [`v7.1.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.1.0)

[Compare Source](goreleaser/goreleaser-action@v7...v7.1.0)

#### What's Changed

- feat: verify release checksum and cosign signature by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;550](goreleaser/goreleaser-action#550)
- docs: document cosign verification in README by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;553](goreleaser/goreleaser-action#553)
- docs: Upgrade import GPG action version by [@&#8203;flecno](https://github.com/flecno) in [#&#8203;547](goreleaser/goreleaser-action#547)
- ci: drop docker-bake in favor of plain npm by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;551](goreleaser/goreleaser-action#551)
- ci: add release-major-tag workflow by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;552](goreleaser/goreleaser-action#552)
- ci: drop pre-cosign-v3 goreleaser versions from tests by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;554](goreleaser/goreleaser-action#554)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;543](goreleaser/goreleaser-action#543)
- ci(deps): bump the actions group with 5 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;546](goreleaser/goreleaser-action#546)
- chore(deps): bump undici from 6.23.0 to 6.24.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;545](goreleaser/goreleaser-action#545)

#### New Contributors

- [@&#8203;flecno](https://github.com/flecno) made their first contribution in [#&#8203;547](goreleaser/goreleaser-action#547)

**Full Changelog**: <goreleaser/goreleaser-action@v7...v7.1.0>

### [`v7.0.0`](https://github.com/goreleaser/goreleaser-action/releases/tag/v7.0.0)

[Compare Source](goreleaser/goreleaser-action@v7...v7)

#### What's Changed

- feat!: node 24, update deps, rm yarn, ESM by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;533](goreleaser/goreleaser-action#533)
- sec: pin github action versions by [@&#8203;caarlos0](https://github.com/caarlos0) in [#&#8203;514](goreleaser/goreleaser-action#514)
- docs: Upgrade checkout GitHub Action in README.md by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;507](goreleaser/goreleaser-action#507)
- chore(deps): bump actions/checkout from 4 to 5 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;504](goreleaser/goreleaser-action#504)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;517](goreleaser/goreleaser-action#517)
- ci(deps): bump the actions group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;523](goreleaser/goreleaser-action#523)
- ci(deps): bump docker/bake-action from 6.9.0 to 6.10.0 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;526](goreleaser/goreleaser-action#526)
- ci(deps): bump the actions group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;532](goreleaser/goreleaser-action#532)
- ci(deps): bump actions/checkout from 6.0.1 to 6.0.2 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;534](goreleaser/goreleaser-action#534)
- chore(deps): bump the npm group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;536](goreleaser/goreleaser-action#536)
- chore(deps): bump [@&#8203;actions/http-client](https://github.com/actions/http-client) from 3.0.2 to 4.0.0 in the npm group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;537](goreleaser/goreleaser-action#537)
- ci(deps): bump docker/setup-buildx-action from 3.10.0 to 3.12.0 in the actions group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;538](goreleaser/goreleaser-action#538)
- chore(deps): bump semver from 7.7.3 to 7.7.4 in the npm group by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;539](goreleaser/goreleaser-action#539)

**Full Changelog**: <goreleaser/goreleaser-action@v6...v7.0.0>

### [`v7`](goreleaser/goreleaser-action@v6.4.0...v7)

[Compare Source](goreleaser/goreleaser-action@v6.4.0...v7)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.simoncor.net/golang/logger/pulls/3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants