diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index bf975f65..802389fb 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -41,13 +41,13 @@ jobs: uses: actions/checkout@v4 - name: Install Go - uses: actions/setup-go@v4 + uses: actions/setup-go@v5 with: go-version-file: go.mod # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v2 + uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 07e17ca1..6f969ab0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -34,10 +34,10 @@ jobs: name: install cosign uses: sigstore/cosign-installer@main - - uses: anchore/sbom-action/download-syft@v0.14.3 + uses: anchore/sbom-action/download-syft@v0.16.0 - name: Run GoReleaser - uses: goreleaser/goreleaser-action@v5 + uses: goreleaser/goreleaser-action@v6 with: version: latest args: release --clean diff --git a/Dockerfile b/Dockerfile index d4e6f5c1..437b6c1b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM alpine:3.19.0 +FROM alpine:3.20.1 RUN apk -U add curl ENTRYPOINT ["/usr/sbin/conditionorc"] diff --git a/Dockerfile.builder b/Dockerfile.builder index 6168b9bf..bb863760 100644 --- a/Dockerfile.builder +++ b/Dockerfile.builder @@ -1,4 +1,4 @@ -FROM golang:1.22-alpine3.19 AS build +FROM golang:1.22-alpine3.20 AS build WORKDIR /go/src/github.com/metal-toolbox/conditionorc COPY go.mod go.sum ./ @@ -21,7 +21,7 @@ RUN CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -o /usr/sbin/conditionorc \ -X ${LDFLAG_LOCATION}.AppVersion=${VERSION} \ -X ${LDFLAG_LOCATION}.BuildDate=${BUILD_DATE}" -FROM alpine:3.19.0 +FROM alpine:3.20.1 RUN apk -U add curl COPY --from=build /usr/sbin/conditionorc /usr/sbin/