grafana / grafana/security-github-actions
Dependency Dashboard
- Dominant language
- JavaScript
- Stars
- 8
- Forks
- 14
- Avg merge
- 4h 35m
- Merged PRs (30d)
- 6
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
## Config Migration Needed
- [ ] Select this checkbox to let Renovate create an automated Config Migration PR.
## Repository Problems
Renovate tried to run on this repository, but found these problems.
- ⚠️ WARN: Package lookup failures
## Pending Status Checks
The following updates await pending status checks. To force their creation now, click on a checkbox below.
- [ ] chore(deps): update trufflesecurity/trufflehog docker tag to v3.97.5
- [ ] chore(deps): update grafana/shared-workflows/create-github-app-token action to v1.0
---
> [!WARNING]
> Renovate failed to look up the following dependencies: `Failed to look up github-tags package aquasecurity/trivy-action: no-result`, `Failed to look up github-releases package aquasecurity/trivy: no-result`.
>
> Files affected: `trivy/action.yml`
---
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [chore(deps): update snyk/actions digest to 12140f4](../pull/174)
- [ ] [chore(deps): update actions/upload-artifact action to v4.6.2](../pull/178)
- [ ] [chore(deps): update astral-sh/setup-uv action to v6.8.0](../pull/179)
- [ ] [chore(deps): update semgrep/semgrep docker tag to v1.177.0](../pull/207)
- [ ] [chore(deps): update actions/github-script action to v9](../pull/195)
- [ ] [chore(deps): update astral-sh/setup-uv action to v10](../pull/211)
- [ ] [chore(deps): update github artifact actions (major)](../pull/197) (`actions/download-artifact`, `actions/upload-artifact`)
- [ ] [chore(deps): update grafana/shared-workflows/get-vault-secrets action to v2.0.2](../pull/198)
- [ ] [chore(deps): update mshick/add-pr-comment action to v3](../pull/215)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## Vulnerabilities
Renovate has not found any CVEs on [osv.dev](https://osv.dev).
## Detected Dependencies
github-actions (7)
.github/workflows/org-required-trufflehog.yml
.github/workflows/periodic-zizmor.yaml (5)
- `actions/checkout v7@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `grafana/shared-workflows create-github-app-token/v0.3.1@46f48da11e78ebdba7a8747ae456b11062fac83e` → [Updates: `create-github-app-token/v1.0`]
- `actions/checkout v7@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `astral-sh/setup-uv v6.7.0@b75a909f75acd358c2196fb9a5f1299a9a8868a4` → [Updates: `v6.8.0`, `v10.1.0`]
- `actions/github-script v7@f28e40c7f34bde8b3046d885e986cb6290c5673b` → [Updates: `v9`].github/workflows/reusable-trufflehog.yml (5)
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `mshick/add-pr-comment v2.8.2@b8f338c590a895d50bcbfa6c5859251edc8952fc` → [Updates: `v3.12.0`]
- `actions/upload-artifact v4.4.0@50769540e7f4bd5e21e526ee35c689e35e0d6874` → [Updates: `v4.6.2`, `v7.0.1`]
- `grafana/shared-workflows get-vault-secrets/v1.3.1@f1614b210386ac420af6807a997ac7f6d96e477a` → [Updates: `get-vault-secrets/v2.0.2`]
- `actions/download-artifact v4@d3f86a106a0bac45b974a628896c90dbdf5c8093` → [Updates: `v8`].github/workflows/self-zizmor.yaml (1)
- `actions/checkout v7@3d3c42e5aac5ba805825da76410c181273ba90b1`
.github/workflows/semgrep.yaml (3)
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `semgrep/semgrep 1.171.0@sha256:bdf7013b2c3634a487671158da77c554f531742326b543a9464d2adf6c433ac8` → [Updates: `1.177.0`].github/workflows/snyk_monitor.yml (2)
- `actions/checkout v7@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `snyk/actions master@e2221410bff24446ba09102212d8bc75a567237d` → [Updates: `master`]trivy/action.yml (7)
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `aquasecurity/trivy-action 0.33.1@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8`
- `actions/checkout v7.0.1@3d3c42e5aac5ba805825da76410c181273ba90b1`
- `aquasecurity/trivy-action 0.33.1@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8`
- `aquasecurity/trivy v0.69.3`
- `aquasecurity/trivy v0.69.3`
pre-commit (1)
.pre-commit-config.yaml (1)
- `grafana/security-github-actions main`
regex (3)
.github/workflows/reusable-trufflehog.yml (1)
- `trufflesecurity/trufflehog v3.97.4` → [Updates: `v3.97.5`]
.github/workflows/reusable-trufflehog.yml (1)
- `trufflesecurity/trufflehog v3.97.4` → [Updates: `v3.97.5`]
pre-commit/trufflehog.sh (1)
- `trufflesecurity/trufflehog 3.97.4@sha256:562bc231afa9de3d04de44cfe624252b08207de1fc3cebc5e7ed92bed7f279e4` → [Updates: `3.97.5`]
---
## Need help?
You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.