From 560544734bf85ef0da900830f09665fa0d18a75f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 2 May 2026 17:06:50 +0000 Subject: [PATCH] Bump the version-updates group with 8 updates Bumps the version-updates group with 8 updates: | Package | From | To | | --- | --- | --- | | [fish-shop/workflows/.github/workflows/codeql-analysis.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [fish-shop/workflows/.github/workflows/dependency-review.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [fish-shop/workflows/.github/workflows/gitleaks.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [fish-shop/workflows/.github/workflows/markdown-links.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [fish-shop/workflows/.github/workflows/openssf-scorecard.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [fish-shop/workflows/.github/workflows/release-tags.yml](https://github.com/fish-shop/workflows) | `1.14.4` | `1.14.5` | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.0` | `2.19.1` | | [fish-shop/install-fish-shell](https://github.com/fish-shop/install-fish-shell) | `2.1.11` | `2.1.12` | Updates `fish-shop/workflows/.github/workflows/codeql-analysis.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `fish-shop/workflows/.github/workflows/dependency-review.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `fish-shop/workflows/.github/workflows/gitleaks.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `fish-shop/workflows/.github/workflows/markdown-links.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `fish-shop/workflows/.github/workflows/openssf-scorecard.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `fish-shop/workflows/.github/workflows/release-tags.yml` from 1.14.4 to 1.14.5 - [Release notes](https://github.com/fish-shop/workflows/releases) - [Commits](https://github.com/fish-shop/workflows/compare/06fb481cda13d4b0505d160e025e5eb682771476...f51e302b38504e77ec3d2a6c874a45406bd14aad) Updates `step-security/harden-runner` from 2.19.0 to 2.19.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...a5ad31d6a139d249332a2605b85202e8c0b78450) Updates `fish-shop/install-fish-shell` from 2.1.11 to 2.1.12 - [Release notes](https://github.com/fish-shop/install-fish-shell/releases) - [Commits](https://github.com/fish-shop/install-fish-shell/compare/939056556c2bfd55b3e2c039e9d34b237c0b9d5b...ccc661674ad75f594cc6b6bf96e4ed76633454e2) --- updated-dependencies: - dependency-name: fish-shop/workflows/.github/workflows/codeql-analysis.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/workflows/.github/workflows/dependency-review.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/workflows/.github/workflows/gitleaks.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/workflows/.github/workflows/markdown-links.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/workflows/.github/workflows/openssf-scorecard.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/workflows/.github/workflows/release-tags.yml dependency-version: 1.14.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: step-security/harden-runner dependency-version: 2.19.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: fish-shop/install-fish-shell dependency-version: 2.1.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/codeql-analysis.yml | 2 +- .github/workflows/dependency-review.yml | 2 +- .github/workflows/gitleaks.yml | 2 +- .github/workflows/markdown-links.yml | 2 +- .github/workflows/openssf-scorecard.yml | 2 +- .github/workflows/release-tags.yml | 2 +- .github/workflows/test.yml | 4 ++-- 7 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 7bf10d7..7820e4a 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -17,4 +17,4 @@ jobs: name: CodeQL Analysis permissions: security-events: write - uses: fish-shop/workflows/.github/workflows/codeql-analysis.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/codeql-analysis.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 1a56c68..a98c385 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -11,4 +11,4 @@ jobs: name: Dependency Review permissions: pull-requests: write - uses: fish-shop/workflows/.github/workflows/dependency-review.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/dependency-review.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index 204fec2..c5babdd 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -14,6 +14,6 @@ jobs: name: Gitleaks SAST scan permissions: pull-requests: write - uses: fish-shop/workflows/.github/workflows/gitleaks.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/gitleaks.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 secrets: gitleaks_license: ${secrets.GITLEAKS_LICENSE} diff --git a/.github/workflows/markdown-links.yml b/.github/workflows/markdown-links.yml index 0e51f4d..cbd9b32 100644 --- a/.github/workflows/markdown-links.yml +++ b/.github/workflows/markdown-links.yml @@ -11,4 +11,4 @@ jobs: name: Markdown Links Check permissions: pull-requests: write - uses: fish-shop/workflows/.github/workflows/markdown-links.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/markdown-links.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 diff --git a/.github/workflows/openssf-scorecard.yml b/.github/workflows/openssf-scorecard.yml index 201ef97..c0b29f7 100644 --- a/.github/workflows/openssf-scorecard.yml +++ b/.github/workflows/openssf-scorecard.yml @@ -14,4 +14,4 @@ jobs: permissions: security-events: write # Needed to upload the results to code scanning dashboard id-token: write # Needed to publish results to OpenSSF API and get a badge - uses: fish-shop/workflows/.github/workflows/openssf-scorecard.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/openssf-scorecard.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 diff --git a/.github/workflows/release-tags.yml b/.github/workflows/release-tags.yml index 50b2c60..c4cef97 100644 --- a/.github/workflows/release-tags.yml +++ b/.github/workflows/release-tags.yml @@ -11,4 +11,4 @@ jobs: name: Release Tags permissions: contents: write - uses: fish-shop/workflows/.github/workflows/release-tags.yml@06fb481cda13d4b0505d160e025e5eb682771476 # v1.14.4 + uses: fish-shop/workflows/.github/workflows/release-tags.yml@f51e302b38504e77ec3d2a6c874a45406bd14aad # v1.14.5 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 66d38d9..fc1f14b 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -30,13 +30,13 @@ jobs: runs-on: ${{ matrix.os }} steps: - name: Harden runner - uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 + uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1 with: egress-policy: audit - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install fish shell - uses: fish-shop/install-fish-shell@939056556c2bfd55b3e2c039e9d34b237c0b9d5b # v2.1.11 + uses: fish-shop/install-fish-shell@ccc661674ad75f594cc6b6bf96e4ed76633454e2 # v2.1.12 - name: Create fish shell file with valid indentation run: | echo "\