From af0a2aff1f7626d822d423a53deff37bce777de4 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 02:03:59 +0000 Subject: [PATCH] build(deps): bump the github-actions group with 2 updates Bumps the github-actions group with 2 updates: [thingzio/actions/.github/workflows/codeql-go.yaml](https://github.com/thingzio/actions) and [thingzio/actions/.github/workflows/release-go.yaml](https://github.com/thingzio/actions). Updates `thingzio/actions/.github/workflows/codeql-go.yaml` from 1.7.1 to 1.8.0 - [Release notes](https://github.com/thingzio/actions/releases) - [Commits](https://github.com/thingzio/actions/compare/368b3e12df4c41d9079b26e41a03efcd90461d56...7276775800dbfef1d9671e60c337f3b4b479a4e8) Updates `thingzio/actions/.github/workflows/release-go.yaml` from 1.7.1 to 1.8.0 - [Release notes](https://github.com/thingzio/actions/releases) - [Commits](https://github.com/thingzio/actions/compare/368b3e12df4c41d9079b26e41a03efcd90461d56...7276775800dbfef1d9671e60c337f3b4b479a4e8) --- updated-dependencies: - dependency-name: thingzio/actions/.github/workflows/codeql-go.yaml dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: thingzio/actions/.github/workflows/release-go.yaml dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/codeql.yaml | 2 +- .github/workflows/release.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index 96dfe3a..052ff3f 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -19,7 +19,7 @@ jobs: actions: read contents: read security-events: write - uses: thingzio/actions/.github/workflows/codeql-go.yaml@368b3e12df4c41d9079b26e41a03efcd90461d56 # v1.7.1 + uses: thingzio/actions/.github/workflows/codeql-go.yaml@7276775800dbfef1d9671e60c337f3b4b479a4e8 # v1.8.0 with: # .go-version owns the toolchain here, not .versions.yaml, so that # setup-go can read it without a YAML parser. diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 21601b5..d09c5e1 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -157,7 +157,7 @@ jobs: # receives it, and that job runs no code from this repository. id-token: write attestations: write - uses: thingzio/actions/.github/workflows/release-go.yaml@368b3e12df4c41d9079b26e41a03efcd90461d56 # v1.7.1 + uses: thingzio/actions/.github/workflows/release-go.yaml@7276775800dbfef1d9671e60c337f3b4b479a4e8 # v1.8.0 with: # Passed explicitly, not inherited. v1.7.0 changed this input's default # from .go-version to go.mod; both say 1.27.1 here so the result is the