Stephan Schroevers
8daedccaea
Update step-security/harden-runner configuration ( #1246 )
...
While apparently the build doesn't fail without this, it is reasonable
for SonarCloud analysis to access the `api.sonarcloud.io` domain.
2024-07-14 14:11:41 +02:00
Picnic-Bot
e7ca4a5325
Upgrade s4u/setup-maven-action v1.12.0 -> v1.13.0 ( #1187 )
...
See:
- https://github.com/s4u/setup-maven-action/releases/tag/v1.13.0
2024-05-22 10:23:23 +02:00
Picnic-Bot
7bab1eb7fd
Upgrade step-security/harden-runner v2.7.1 -> v2.8.0 ( #1188 )
...
See:
- https://github.com/step-security/harden-runner/releases/tag/v2.8.0
2024-05-22 08:36:34 +02:00
Stephan Schroevers
8a8290587a
Update step-security/harden-runner configuration ( #1177 )
...
This resolves recent build failures by ensuring that JDKs can be
downloaded.
2024-05-19 14:14:20 +02:00
Picnic-Bot
e7d50c247d
Upgrade step-security/harden-runner v2.7.0 -> v2.7.1 ( #1160 )
...
See:
- https://github.com/step-security/harden-runner/releases/tag/v2.7.1
2024-04-30 10:02:09 +02:00
Stephan Schroevers
3b005b0edc
Introduce GitHub Actions step-security/harden-runner step ( #1063 )
2024-03-11 21:43:54 +01:00
Stephan Schroevers
b39e322a67
Upgrade JDKs used by GitHub Actions builds ( #1043 )
...
Summary of changes:
- Use JDK 17.0.10 instead of 17.0.8.
- Use JDK 21.0.2 instead of 21.0.0.
- Have GitHub issue template reference more recent version numbers.
See:
- https://adoptium.net/temurin/release-notes/?version=jdk-17.0.9+9
- https://adoptium.net/temurin/release-notes/?version=jdk-17.0.10+7
- https://adoptium.net/temurin/release-notes/?version=jdk-21.0.1+12
- https://adoptium.net/temurin/release-notes/?version=jdk-21.0.2+13
2024-02-18 16:51:54 +01:00
Picnic-Bot
cce897ed4a
Upgrade s4u/setup-maven-action v1.11.0 -> v1.12.0 ( #1030 )
...
See:
- https://github.com/s4u/setup-maven-action/releases/tag/v1.12.0
2024-02-13 08:08:36 +01:00
Stephan Schroevers
1fe67677b4
Re-enable SonarCloud analysis on default branch ( #1029 )
...
This analysis was accidentally disabled by
ff3be8ae3f .
2024-02-12 08:46:45 +01:00
Stephan Schroevers
0b04e0fb3f
Build with Maven 3.9.6 ( #964 )
...
Using the `setup-maven-action` GitHub action we can both simplify the
build configuration and configure the version of Maven to use.
See https://github.com/s4u/setup-maven-action
2024-01-13 17:17:01 +01:00
Stephan Schroevers
ff3be8ae3f
Skip SonarCloud analysis of PRs from forked repositories ( #926 )
...
Because such analysis will fail due to unavailability of the relevant
secrets. Working around this is nontrivial and a likely source of
security issues.
2023-12-18 08:34:30 +01:00
Picnic-Bot
a5b71410ae
Upgrade actions/setup-java v3.13.0 -> v4.0.0 ( #899 )
...
See:
- https://github.com/actions/setup-java/releases/tag/v4.0.0
2023-12-04 07:41:00 +01:00
Picnic-Bot
3a76f91d18
Upgrade actions/checkout v4.1.0 -> v4.1.1 ( #845 )
...
See:
- https://github.com/actions/checkout/releases/tag/v4.1.1
2023-10-18 08:17:15 +02:00
Stephan Schroevers
c03ead9e5d
Upgrade JDKs used by GitHub Actions builds ( #780 )
...
Summary of changes:
- Use JDK 11.0.20 instead of 11.0.19.
- Use JDK 17.0.8 instead of 17.0.7.
- Use JDK 20.0.2 instead of 20.0.1.
See:
- https://www.oracle.com/java/technologies/javase/11-0-20-relnotes.html
- https://www.oracle.com/java/technologies/javase/17-0-8-relnotes.html
- https://www.oracle.com/java/technologies/javase/20-0-2-relnotes.html
2023-10-04 11:22:16 +02:00
Picnic-Bot
67106a9725
Upgrade actions/setup-java v3.12.0 -> v3.13.0 ( #798 )
...
See:
- https://github.com/actions/setup-java/releases/tag/v3.13.0
2023-10-03 13:14:33 +02:00
Picnic-Bot
5602251667
Upgrade actions/checkout v3.6.0 -> v4.1.0 ( #779 )
...
See:
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v410
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v400
2023-10-03 11:51:20 +02:00
Picnic-Bot
431c3e67ac
Upgrade actions/checkout v3.5.3 -> v3.6.0 ( #761 )
...
See:
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v360
2023-08-25 09:34:35 +02:00
Picnic-Bot
3c38fd3495
Upgrade actions/setup-java v3.11.0 -> v3.12.0 ( #730 )
...
See https://github.com/actions/setup-java/releases/tag/v3.12.0
2023-08-01 09:54:17 +02:00
Picnic-Bot
d29fde8856
Upgrade actions/checkout v3.1.0 -> v3.5.3 ( #667 )
...
See:
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v353
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v352
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v351
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v350
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v340
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v330
- https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v320
2023-06-19 09:18:01 +02:00
Picnic-Bot
c40e1d6691
Upgrade actions/setup-java v3.8.0 -> v3.11.0 ( #668 )
...
See:
- https://github.com/actions/setup-java/releases/tag/v3.9.0
- https://github.com/actions/setup-java/releases/tag/v3.10.0
- https://github.com/actions/setup-java/releases/tag/v3.11.0
2023-06-16 15:35:04 +02:00
Stephan Schroevers
de224deffa
Upgrade JDKs used by GitHub Actions builds ( #604 )
...
Summary of changes:
- Use JDK 11.0.19 instead of 11.0.18.
- Use JDK 17.0.7 instead of 17.0.6.
- Use JDK 20.0.1 instead of 19.0.2.
- Drop the early access build, as Error Prone is currently not compatible with JDK 21-ea.
See:
- https://www.oracle.com/java/technologies/javase/11-0-19-relnotes.html
- https://www.oracle.com/java/technologies/javase/17-0-7-relnotes.html
- https://www.oracle.com/java/technologies/javase/20-relnote-issues.html
- https://www.oracle.com/java/technologies/javase/20-0-1-relnotes.html
2023-05-02 08:51:39 +02:00
Stephan Schroevers
e0c795d248
Introduce SonarCloud integration and resolve assorted violations ( #575 )
2023-04-25 08:19:11 +02:00