renovate[bot]
805d427e47
fix(deps): update all non-major dependencies
2025-12-13 05:50:40 +00:00
renovate[bot]
92ef98329d
fix(deps): update all non-major dependencies
2025-12-03 15:16:23 +00:00
renovate[bot]
056bfbdbbc
chore(deps): update actions/checkout action to v6
2025-12-01 01:12:44 +00:00
renovate[bot]
e5b5a204d4
fix(deps): update all non-major dependencies
2025-11-27 10:16:30 +00:00
renovate[bot]
18ef52acc1
fix(deps): update all non-major dependencies
2025-11-11 13:38:56 +00:00
renovate[bot]
c5a7f52681
fix(deps): update all non-major dependencies
2025-11-03 16:39:17 +09:00
renovate[bot]
8b6bd0cb40
fix(deps): update all non-major dependencies
2025-10-30 09:57:02 +00:00
renovate[bot]
092cd08973
chore(deps): update github/codeql-action action to v4
2025-10-20 02:39:31 +00:00
renovate[bot]
1f9f243a75
fix(deps): update all non-major dependencies
2025-10-13 08:58:25 +00:00
renovate[bot]
372c8d7f00
fix(deps): update all non-major dependencies
2025-10-08 07:53:07 +00:00
Kazuki Yamada
cd185a1ea3
chore(ci): replace ratchet with pinact for GitHub Actions SHA pinning
...
This replaces the ratchet tool with pinact for managing GitHub Actions SHA pinning across all workflow files. The changes include:
- Remove ratchet-update.yml and ratchet-verify.yml workflows
- Add new pinact.yml workflow for automated SHA pinning
- Update all workflow files to use pinact-style comments (# v1.2.3 instead of # ratchet:action@v1)
- Add .pinact.yaml configuration file with ignore rules for Homebrew actions and local actions
- Update package.json scripts to use pinact commands instead of ratchet
Pinact provides more reliable SHA pinning with better GitHub Actions integration.
2025-09-23 23:18:06 +09:00
renovate[bot]
cd128fc45c
chore(deps): update actions/checkout action to v5
2025-09-22 01:02:08 +00:00
Kazuki Yamada
8cfc400a9f
chore(ci): Update GitHub Actions SHAs to latest versions
...
- Update all workflow files with latest action SHAs using ratchet
- Ensure security through SHA pinning while using current versions
- Automated update as part of ratchet workflow implementation
2025-08-20 23:55:39 +09:00
Kazuki Yamada
2b04948a6d
Merge pull request #786 from yamadashy/dependabot/github_actions/github/codeql-action-3.29.10
2025-08-19 09:56:46 +09:00
dependabot[bot]
17f78d2c87
chore(deps): bump github/codeql-action from 3.29.8 to 3.29.10
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.29.8 to 3.29.10.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](76621b61de...96f518a34f )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 3.29.10
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-18 19:09:51 +00:00
renovate[bot]
7c77a4953e
chore(deps): update actions/checkout digest to 08eba0b
2025-08-18 01:51:47 +00:00
dependabot[bot]
a9483abe24
chore(deps): bump actions/checkout from 4.2.2 to 5.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4.2.2 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](11bd71901b...08c6903cd8 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 5.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-12 01:04:26 +00:00
dependabot[bot]
dd0941d2b5
chore(deps): bump github/codeql-action from 3.29.3 to 3.29.8
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.29.3 to 3.29.8.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d6bbdef45e...76621b61de )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 3.29.8
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-11 18:24:27 +00:00
dependabot[bot]
86fa1f9b86
chore(deps): bump github/codeql-action from 3.29.2 to 3.29.3
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.29.2 to 3.29.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](181d5eefc2...d6bbdef45e )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 3.29.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-21 15:45:16 +00:00
dependabot[bot]
80417443a5
chore(deps): bump github/codeql-action from 3.29.1 to 3.29.2
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.29.1 to 3.29.2.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](39edc492db...181d5eefc2 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 3.29.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-02 12:52:38 +09:00
dependabot[bot]
2e93a0ddfb
chore(deps): bump github/codeql-action from 3.29.0 to 3.29.1
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.29.0 to 3.29.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](ce28f5bb42...39edc492db )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 3.29.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-27 13:48:24 +00:00
Krish Ray
9df336b999
Fix: pin all GitHub Actions to immutable SHAs via ratchet
2025-06-15 14:20:37 +09:00
Kazuki Yamada
ea6f6e3075
chore(ci): Create codeql.yml
2024-09-22 23:08:32 +09:00