Commit Graph

533 Commits

Author SHA1 Message Date
Alexey Pustovalov
863b1628bb
Merge pull request #1823 from zabbix/dependabot/github_actions/actions/cache-5.0.1
Bump actions/cache from 4.3.0 to 5.0.1
2025-12-17 13:06:18 +09:00
Alexey Pustovalov
186d29fc77
Merge pull request #1822 from zabbix/dependabot/github_actions/docker/setup-qemu-action-3.7.0
Bump docker/setup-qemu-action from 3.6.0 to 3.7.0
2025-12-17 13:05:56 +09:00
dependabot[bot]
801a741d50
Bump actions/dependency-review-action from 4.8.1 to 4.8.2
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.8.1 to 4.8.2.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](40c09b7dc9...3c4e3dcb1a)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: 4.8.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-17 04:05:33 +00:00
Alexey Pustovalov
89cb6bdc66
Merge pull request #1820 from zabbix/dependabot/github_actions/actions/upload-artifact-6.0.0
Bump actions/upload-artifact from 4.6.1 to 6.0.0
2025-12-17 13:05:17 +09:00
Alexey Pustovalov
005be07c63
Merge pull request #1819 from zabbix/dependabot/github_actions/peter-evans/dockerhub-description-5.0.0
Bump peter-evans/dockerhub-description from 4.0.0 to 5.0.0
2025-12-17 13:04:52 +09:00
Alexey Pustovalov
eafb5340ff
Merge pull request #1818 from zabbix/dependabot/github_actions/actions/checkout-6.0.1
Bump actions/checkout from 5.0.0 to 6.0.1
2025-12-17 13:04:21 +09:00
Alexey Pustovalov
8d14b04c58
Merge pull request #1817 from zabbix/dependabot/github_actions/SonarSource/sonarqube-scan-action-7.0.0
Bump SonarSource/sonarqube-scan-action from 6.0.0 to 7.0.0
2025-12-17 13:03:53 +09:00
Alexey Pustovalov
4c52d38506
Merge pull request #1816 from zabbix/dependabot/github_actions/ossf/scorecard-action-2.4.3
Bump ossf/scorecard-action from 2.4.1 to 2.4.3
2025-12-17 13:03:41 +09:00
Alexey Pustovalov
a75b0c69d7
Merge pull request #1815 from zabbix/dependabot/github_actions/step-security/harden-runner-2.14.0
Bump step-security/harden-runner from 2.13.1 to 2.14.0
2025-12-17 13:03:21 +09:00
dependabot[bot]
1a584b5a23
Bump actions/checkout from 5.0.0 to 6.0.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.0 to 6.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](08c6903cd8...8e8c483db8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-16 01:32:47 +00:00
Alexey Pustovalov
50b027269f Updated allowed endpoints 2025-12-16 10:31:25 +09:00
dependabot[bot]
2989ded3c1
Bump actions/cache from 4.3.0 to 5.0.1
Bumps [actions/cache](https://github.com/actions/cache) from 4.3.0 to 5.0.1.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](0057852bfa...9255dc7a25)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:58 +00:00
dependabot[bot]
53886b1e56
Bump docker/setup-qemu-action from 3.6.0 to 3.7.0
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](29109295f8...c7c5346462)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:44 +00:00
dependabot[bot]
ef94106497
Bump actions/upload-artifact from 4.6.1 to 6.0.0
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.1 to 6.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](4cec3d8aa0...b7c566a772)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:36 +00:00
dependabot[bot]
b3d5beabaa
Bump peter-evans/dockerhub-description from 4.0.0 to 5.0.0
Bumps [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/peter-evans/dockerhub-description/releases)
- [Commits](e98e4d1628...1b9a80c056)

---
updated-dependencies:
- dependency-name: peter-evans/dockerhub-description
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:31 +00:00
dependabot[bot]
750c9d982e
Bump SonarSource/sonarqube-scan-action from 6.0.0 to 7.0.0
Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/v6.0.0...v7.0.0)

---
updated-dependencies:
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:14 +00:00
dependabot[bot]
e7d4568afb
Bump ossf/scorecard-action from 2.4.1 to 2.4.3
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.1 to 2.4.3.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](f49aabe0b5...4eaacf0543)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:11 +00:00
dependabot[bot]
a333b4c03a
Bump step-security/harden-runner from 2.13.1 to 2.14.0
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.13.1 to 2.14.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](f4a75cfd61...20cf305ff2)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 06:11:06 +00:00
Alexey Pustovalov
13dd4cf567 Updated allowed endpoints 2025-12-15 15:04:55 +09:00
Alexey Pustovalov
739f83c427
Merge pull request #1746 from zabbix/dependabot/github_actions/docker/metadata-action-5.8.0
Bump docker/metadata-action from 5.7.0 to 5.8.0
2025-12-15 14:00:58 +09:00
Alexey Pustovalov
6b11be7b10
Merge pull request #1753 from zabbix/dependabot/github_actions/actions/checkout-5.0.0
Bump actions/checkout from 4.1.7 to 5.0.0
2025-12-15 14:00:46 +09:00
Alexey Pustovalov
866aa4e53c
Merge pull request #1766 from zabbix/dependabot/github_actions/actions/attest-build-provenance-3
Bump actions/attest-build-provenance from 2 to 3
2025-12-15 14:00:32 +09:00
Alexey Pustovalov
1ab0f7910a
Merge pull request #1769 from zabbix/dependabot/github_actions/actions/setup-python-6.0.0
Bump actions/setup-python from 5.4.0 to 6.0.0
2025-12-15 14:00:21 +09:00
Alexey Pustovalov
70ebd63b52
Merge pull request #1773 from zabbix/dependabot/github_actions/step-security/harden-runner-2.13.1
Bump step-security/harden-runner from 2.11.0 to 2.13.1
2025-12-15 14:00:09 +09:00
Alexey Pustovalov
47c3305a6c
Merge pull request #1781 from zabbix/dependabot/github_actions/actions/cache-4.3.0
Bump actions/cache from 4.2.2 to 4.3.0
2025-12-15 13:59:57 +09:00
Alexey Pustovalov
dcf2cda1a1
Merge pull request #1788 from zabbix/dependabot/github_actions/docker/login-action-3.6.0
Bump docker/login-action from 3.2.0 to 3.6.0
2025-12-15 13:59:45 +09:00
Alexey Pustovalov
540346db0a
Merge pull request #1797 from zabbix/dependabot/github_actions/actions/dependency-review-action-4.8.1
Bump actions/dependency-review-action from 4.3.3 to 4.8.1
2025-12-15 13:59:22 +09:00
Alexey Pustovalov
f0af7685c7
Merge pull request #1798 from zabbix/dependabot/github_actions/sigstore/cosign-installer-4.0.0
Bump sigstore/cosign-installer from 3.9.2 to 4.0.0
2025-12-15 13:59:11 +09:00
Alexey Pustovalov
c2dee31637
Merge pull request #1802 from zabbix/dependabot/github_actions/github/codeql-action-4.31.0
Bump github/codeql-action from 3.28.10 to 4.31.0
2025-12-15 13:58:29 +09:00
Alexey Pustovalov
c826638d38 Removed CentOS 10 from scan for vulnerabilities 2025-12-04 13:33:15 +09:00
Alexey Pustovalov
f76b8d285a Fixed RedHat images build process 2025-12-02 15:57:37 +09:00
dependabot[bot]
407291fa27
Bump github/codeql-action from 3.28.10 to 4.31.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.28.10 to 4.31.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](b56ba49b26...4e94bd11f7)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.31.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-27 06:26:17 +00:00
dependabot[bot]
69342d9c63
Bump sigstore/cosign-installer from 3.9.2 to 4.0.0
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.9.2 to 4.0.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](d58896d6a1...faadad0cce)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-17 06:08:47 +00:00
dependabot[bot]
b5cd390fec
Bump actions/dependency-review-action from 4.3.3 to 4.8.1
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.3.3 to 4.8.1.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](72eb03d02c...40c09b7dc9)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: 4.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-13 06:12:49 +00:00
dependabot[bot]
f9d4a03f85
Bump docker/login-action from 3.2.0 to 3.6.0
Bumps [docker/login-action](https://github.com/docker/login-action) from 3.2.0 to 3.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](0d4c9c5ea7...5e57cd1181)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-30 06:09:05 +00:00
dependabot[bot]
5630d98490
Bump SonarSource/sonarqube-scan-action in /.github/workflows
Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 5.3.1 to 6.0.0.
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/v5.3.1...v6.0.0)

---
updated-dependencies:
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 6.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-26 13:20:24 +00:00
dependabot[bot]
422e32f250
Bump SonarSource/sonarqube-scan-action in /.github/workflows
Bumps [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) from 5.2.0 to 5.3.1.
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/v5.2.0...v5.3.1)

---
updated-dependencies:
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 5.3.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-26 02:59:40 +00:00
dependabot[bot]
30b3b669fb
Bump actions/cache from 4.2.2 to 4.3.0
Bumps [actions/cache](https://github.com/actions/cache) from 4.2.2 to 4.3.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](d4323d4df1...0057852bfa)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-25 06:09:59 +00:00
dependabot[bot]
724a95d843
Bump step-security/harden-runner from 2.11.0 to 2.13.1
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.11.0 to 2.13.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](4d991eb9b9...f4a75cfd61)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-10 06:10:19 +00:00
dependabot[bot]
e670510045
Bump actions/setup-python from 5.4.0 to 6.0.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.4.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](42375524e2...e797f83bcb)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-04 11:15:59 +00:00
dependabot[bot]
f8ab63edab
Bump actions/attest-build-provenance from 2 to 3
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 2 to 3.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-build-provenance/compare/v2...v3)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-29 06:09:31 +00:00
dependabot[bot]
b8688e438c
Bump actions/checkout from 4.1.7 to 5.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.1.7 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](692973e3d9...08c6903cd8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-12 13:56:17 +00:00
Alexey Pustovalov
54b5482cb1 Removed static cosign version 2025-08-06 13:24:12 +09:00
Alexey Pustovalov
0940058fd6
Merge pull request #1731 from zabbix/dependabot/github_actions/sigstore/cosign-installer-3.9.2
Bump sigstore/cosign-installer from 3.8.1 to 3.9.2
2025-08-06 12:49:37 +09:00
dependabot[bot]
3ef7c9131c
Bump docker/metadata-action from 5.7.0 to 5.8.0
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 5.7.0 to 5.8.0.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](902fa8ec7d...c1e51972af)

---
updated-dependencies:
- dependency-name: docker/metadata-action
  dependency-version: 5.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-04 09:13:33 +00:00
Alexey Pustovalov
80ae6c771f Updated Sonacloud workflow 2025-07-18 15:45:11 +09:00
dependabot[bot]
33b0cee1db
Bump sigstore/cosign-installer from 3.8.1 to 3.9.2
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.8.1 to 3.9.2.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](d7d6bc7722...d58896d6a1)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-version: 3.9.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-07-18 06:32:33 +00:00
Alexey Pustovalov
136d09f45e Fixed PostgreSQL 17 on Ubuntu images 2025-07-16 11:17:32 +09:00
Alexey Pustovalov
ea607c9ddd Updated Sonarcloud default branch 2025-07-01 11:20:08 +03:00
Alexey Pustovalov
6ae4e8adf5 Increased build time for images 2025-05-29 10:26:18 +09:00