diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..81ef7b0a --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,22 @@ +version: 2 +updates: + - package-ecosystem: gomod + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 10 + groups: + gomod: + update-types: + - "patch" + + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 10 + groups: + actions: + update-types: + - "minor" + - "patch" diff --git a/.github/workflows/docker-image.yaml b/.github/workflows/docker-image.yaml index 417ebfd6..27b03bca 100644 --- a/.github/workflows/docker-image.yaml +++ b/.github/workflows/docker-image.yaml @@ -45,7 +45,7 @@ jobs: with: username: ${{ secrets.DOCKERHUB_USER }} password: ${{ secrets.DOCKERHUB_SECRET }} - + - name: Docker Meta id: meta_falcoctl uses: docker/metadata-action@507c2f2dc502c992ad446e3d7a5dfbe311567a96 # v4.3.0 diff --git a/.github/workflows/lint.yaml b/.github/workflows/lint.yaml index f6b3638a..10447009 100644 --- a/.github/workflows/lint.yaml +++ b/.github/workflows/lint.yaml @@ -25,7 +25,7 @@ jobs: uses: golangci/golangci-lint-action@3a919529898de77ec3da873e3063ca4b10e7f5cc # v3.7.0 with: only-new-issues: true - version: v1.54.2 + version: v1.55 args: --timeout=900s gomodtidy: diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index a86644f9..fdf2109d 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -36,7 +36,7 @@ jobs: args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - + - name: Generate subject id: hash env: @@ -46,7 +46,7 @@ jobs: checksum_file=$(echo "$ARTIFACTS" | jq -r '.[] | select (.type=="Checksum") | .path') echo "hashes=$(cat $checksum_file | base64 -w0)" >> "$GITHUB_OUTPUT" - + provenance-for-binaries: needs: [goreleaser] permissions: @@ -57,7 +57,7 @@ jobs: with: base64-subjects: "${{ needs.goreleaser.outputs.hashes }}" upload-assets: true # upload to a new release - + verification: needs: [goreleaser, provenance-for-binaries] runs-on: ubuntu-latest @@ -75,7 +75,7 @@ jobs: gh -R "$GITHUB_REPOSITORY" release download "$GITHUB_REF_NAME" -p "*.tar.gz" gh -R "$GITHUB_REPOSITORY" release download "$GITHUB_REF_NAME" -p "*.zip" gh -R "$GITHUB_REPOSITORY" release download "$GITHUB_REF_NAME" -p "$PROVENANCE" - + - name: Verify assets env: CHECKSUMS: ${{ needs.goreleaser.outputs.hashes }} @@ -105,7 +105,7 @@ jobs: echo "release=$(echo $GITHUB_REF | cut -d / -f 3 | sed 's/^v//')" >> $GITHUB_OUTPUT echo "commit=${{ github.sha }}" >> $GITHUB_OUTPUT echo "build_date=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" >> $GITHUB_OUTPUT - + docker-image: needs: docker-configure uses: ./.github/workflows/docker-image.yaml