213 Commits

Author SHA1 Message Date
irongut f138489648 merge PR #101 from dependabot/actions/cosign-installer-2.8.1
Bump sigstore/cosign-installer from 2.8.0 to 2.8.1
2022-10-20 02:38:15 +01:00
dependabot[bot] 9986579715 Bump sigstore/cosign-installer from 2.8.0 to 2.8.1
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 2.8.0 to 2.8.1.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/7cc35d7fdbe70d4278a0c96779081e6fac665f88...9becc617647dfa20ae7b1151972e9b3a2c338a2b)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 23:44:08 +00:00
irongut 2b7bf99d3d merge PR #93 from dependabot/actions/cosign-installer-2.8.0
Bump sigstore/cosign-installer from 2.5.1 to 2.8.0
2022-10-18 23:59:20 +01:00
irongut 6381a94beb merge PR #87 from ependabot/actions/harden-runner-1.5.0
Bump step-security/harden-runner from 1.4.5 to 1.5.0
2022-10-18 23:57:41 +01:00
irongut 064d8225cf merge PR #98 from dependabot/actions/setup-buildx-action-2.2.1
Bump docker/setup-buildx-action from 2.0.0 to 2.2.1
2022-10-18 23:56:50 +01:00
irongut dc0965bfd6 merge PR #100 from dependabot/actions/build-push-action-3.2.0
Bump docker/build-push-action from 3.1.1 to 3.2.0
2022-10-18 23:55:53 +01:00
irongut c76d28851c merge PR #99 from dependabot/actions/metadata-action-4.1.1
Bump docker/metadata-action from 4.0.1 to 4.1.1
2022-10-18 23:54:52 +01:00
dependabot[bot] 249f92f672 Bump docker/build-push-action from 3.1.1 to 3.2.0
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 3.1.1 to 3.2.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/c84f38281176d4c9cdb1626ffafcd6b3911b5d94...c56af957549030174b10d6867f20e78cfd7debc5)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 22:53:07 +00:00
dependabot[bot] f157e9605b Bump docker/setup-buildx-action from 2.0.0 to 2.2.1
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 2.0.0 to 2.2.1.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/dc7b9719a96d48369863986a06765841d7ea23f6...8c0edbc76e98fa90f69d9a2c020dcb50019dc325)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 22:52:55 +00:00
irongut e4fa71f987 merge PR #97 from dependabot/actions/labeler-4.0.2
Bump actions/labeler from 4.0.1 to 4.0.2
2022-10-18 23:52:45 +01:00
dependabot[bot] 6c9b394cdc Bump docker/metadata-action from 4.0.1 to 4.1.1
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 4.0.1 to 4.1.1.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](https://github.com/docker/metadata-action/compare/69f6fc9d46f2f8bf0d5491e4aabe0bb8c6a4678a...57396166ad8aefe6098280995947635806a0e6ea)

---
updated-dependencies:
- dependency-name: docker/metadata-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 22:52:24 +00:00
irongut 79572a8bdc merge PR #95 from dependabot/actions/login-action-2.1.0
Bump docker/login-action from 2.0.0 to 2.1.0
2022-10-18 23:52:01 +01:00
irongut 7086c364c7 merge PR #96 from dependabot/actions/codeql-action-2.1.28
Bump github/codeql-action from 2.1.22 to 2.1.28
2022-10-18 23:51:25 +01:00
dependabot[bot] 159f0d3f03 Bump github/codeql-action from 2.1.22 to 2.1.28
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.22 to 2.1.28.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/b398f525a5587552e573b247ac661067fafa920b...cc7986c02bac29104a72998e67239bb5ee2ee110)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 21:36:07 +00:00
dependabot[bot] b371d8d706 Bump sigstore/cosign-installer from 2.5.1 to 2.8.0
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 2.5.1 to 2.8.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/b3413d484cc23cf8778c3d2aa361568d4eb54679...7cc35d7fdbe70d4278a0c96779081e6fac665f88)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 21:35:54 +00:00
dependabot[bot] e58ef3d225 Bump actions/labeler from 4.0.1 to 4.0.2
Bumps [actions/labeler](https://github.com/actions/labeler) from 4.0.1 to 4.0.2.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](https://github.com/actions/labeler/compare/e54e5b338fbd6e6cdb5d60f51c22335fc57c401e...5c7539237e04b714afd8ad9b4aed733815b9fab4)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 21:35:43 +00:00
irongut 8be1ea7dcd merge PR #91 from dependabot/actions/checkout-3.1.0
Bump actions/checkout from 3.0.2 to 3.1.0
2022-10-18 22:35:09 +01:00
dependabot[bot] df694edd1f Bump actions/checkout from 3.0.2 to 3.1.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.0.2 to 3.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/2541b1294d2704b0964813337f33b291d3f8596b...93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 21:23:41 +00:00
dependabot[bot] 389bb15050 Bump docker/login-action from 2.0.0 to 2.1.0
Bumps [docker/login-action](https://github.com/docker/login-action) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/49ed152c8eca782a232dede0303416e8f356c37b...f4ef78c080cd8ba55a85445d5b36e214a81df20a)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-18 21:23:22 +00:00
irongut f9552f243d merge PR #94 from dependabot/actions/setup-dotnet-3.0.2
Bump actions/setup-dotnet from 2.1.0 to 3.0.2
2022-10-18 22:22:54 +01:00
dependabot[bot] 22531c6a84 Bump actions/setup-dotnet from 2.1.0 to 3.0.2
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 2.1.0 to 3.0.2.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](https://github.com/actions/setup-dotnet/compare/c0d4ad69d8bd405d234f1c9166d383b7a4f69ed8...4d4a70f4a5b2a5a5329f13be4ac933f2c9206ac0)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-13 23:39:24 +00:00
dependabot[bot] 32b97a380b Bump step-security/harden-runner from 1.4.5 to 1.5.0
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 1.4.5 to 1.5.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](https://github.com/step-security/harden-runner/compare/dd2c410b088af7c0dc8046f3ac9a8f4148492a95...2e205a28d0e1da00c5f53b161f4067b052c61f34)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-09-30 00:00:38 +00:00
irongut 58d593b91d merge PR #80 from dependabot/actions/codeql-action-2.1.22
Bump github/codeql-action from 2.1.21 to 2.1.22
2022-09-09 20:54:51 +01:00
dependabot[bot] b7e4620db9 Bump github/codeql-action from 2.1.21 to 2.1.22
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.21 to 2.1.22.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/c7f292ea4f542c473194b33813ccd4c207a6c725...b398f525a5587552e573b247ac661067fafa920b)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-09-01 23:57:22 +00:00
irongut 835f52dd6d merge PR #77 from dependabot/actions/codeql-action-2.1.21
Bump github/codeql-action from 2.1.19 to 2.1.21
2022-08-26 20:22:53 +01:00
dependabot[bot] 57a8504803 Bump github/codeql-action from 2.1.19 to 2.1.21
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.19 to 2.1.21.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/f5d217be74900c6ac8fbbe53f3c10376ba4e64da...c7f292ea4f542c473194b33813ccd4c207a6c725)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-25 23:41:40 +00:00
irongut de3bf184e8 merge PR #71 from dependabot/actions/assign-one-project-github-action
Bump srggrs/assign-one-project-github-action from 4d59cc619499b55ca689fb13cfcc72324a8b8435 to 1.3.1
2022-08-21 16:36:45 +01:00
irongut 0adb7a5e81 merge PR #72 from dependabot/actions/labeler
Bump actions/labeler from 472c5d3aaacde439785e94966eb2e545627f4935 to 4.0.1
2022-08-21 16:35:59 +01:00
irongut 193c3d52d4 merge PR #73 from dependabot/actions/cosign-installer
Bump sigstore/cosign-installer from c68f43abf1ae5df2528c9c250088fa14ed2d0ef5 to 2.5.1
2022-08-21 16:35:32 +01:00
irongut 4472978224 merge PR #67 from dependabot/Microsoft.VisualStudio.Azure.Containers.Tools.Targets-1.17.0
Bump Microsoft.VisualStudio.Azure.Containers.Tools.Targets from 1.16.1 to 1.17.0 in /src
2022-08-21 16:35:00 +01:00
irongut ad8e33903c merge PR #70 from dependabot/actions/checkout-3.0.2
Bump actions/checkout from 2 to 3.0.2
2022-08-21 16:34:26 +01:00
irongut b4e48dcc98 merge PR #74 from dependabot/actions/codeql-action
Update github/codeql-action requirement to f5d217be74900c6ac8fbbe53f3c10376ba4e64da
2022-08-21 16:33:29 +01:00
dependabot[bot] 2cba9cd8f8 Update github/codeql-action requirement to f5d217be74900c6ac8fbbe53f3c10376ba4e64da
Updates the requirements on [github/codeql-action](https://github.com/github/codeql-action) to permit the latest version.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/commits/f5d217be74900c6ac8fbbe53f3c10376ba4e64da)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 23:46:13 +00:00
dependabot[bot] 31b2f90c53 Bump sigstore/cosign-installer
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from c68f43abf1ae5df2528c9c250088fa14ed2d0ef5 to 2.5.1. This release includes the previously tagged commit.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/c68f43abf1ae5df2528c9c250088fa14ed2d0ef5...b3413d484cc23cf8778c3d2aa361568d4eb54679)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 00:44:36 +00:00
dependabot[bot] 3a1aab172a Bump actions/labeler
Bumps [actions/labeler](https://github.com/actions/labeler) from 472c5d3aaacde439785e94966eb2e545627f4935 to 4.0.1. This release includes the previously tagged commit.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](https://github.com/actions/labeler/compare/472c5d3aaacde439785e94966eb2e545627f4935...e54e5b338fbd6e6cdb5d60f51c22335fc57c401e)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 00:44:33 +00:00
dependabot[bot] 80e8804405 Bump srggrs/assign-one-project-github-action
Bumps [srggrs/assign-one-project-github-action](https://github.com/srggrs/assign-one-project-github-action) from 4d59cc619499b55ca689fb13cfcc72324a8b8435 to 1.3.1. This release includes the previously tagged commit.
- [Release notes](https://github.com/srggrs/assign-one-project-github-action/releases)
- [Changelog](https://github.com/srggrs/assign-one-project-github-action/blob/master/CHANGELOG.md)
- [Commits](https://github.com/srggrs/assign-one-project-github-action/compare/4d59cc619499b55ca689fb13cfcc72324a8b8435...65a8ddab497df42ef268001e67bbf976f8fd39e1)

---
updated-dependencies:
- dependency-name: srggrs/assign-one-project-github-action
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 00:44:30 +00:00
dependabot[bot] be73105298 Bump actions/checkout from 2 to 3.0.2
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.0.2.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...2541b1294d2704b0964813337f33b291d3f8596b)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 00:44:27 +00:00
dependabot[bot] 9dd4a48e5d Bump Microsoft.VisualStudio.Azure.Containers.Tools.Targets in /src
Bumps Microsoft.VisualStudio.Azure.Containers.Tools.Targets from 1.16.1 to 1.17.0.

---
updated-dependencies:
- dependency-name: Microsoft.VisualStudio.Azure.Containers.Tools.Targets
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-16 23:47:20 +00:00
irongut a989a1acc2 merge PR #65 Add Dockerfile linter
PR: Add Dockerfile linter
2022-08-14 02:17:23 +01:00
irongut b5c414e325 add hadolint Dockerfile linter 2022-08-14 02:14:19 +01:00
irongut 3d044cdcd5 merge PR #64 from dependabot/actions/harden-runner-1.4.5
Bump step-security/harden-runner from 1.4.4 to 1.4.5
2022-08-13 19:23:52 +01:00
irongut 3a7e9990c1 merge PR #63 from dependabot/actions/build-push-action-3.1.1
Bump docker/build-push-action from 3.1.0 to 3.1.1
2022-08-13 19:22:48 +01:00
dependabot[bot] 7142272b0a Bump step-security/harden-runner from 1.4.4 to 1.4.5
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 1.4.4 to 1.4.5.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](https://github.com/step-security/harden-runner/compare/74b568e8591fbb3115c70f3436a0c6b0909a8504...dd2c410b088af7c0dc8046f3ac9a8f4148492a95)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-12 23:37:51 +00:00
irongut 23dcb1b683 updated readme 2022-08-08 00:19:10 +01:00
dependabot[bot] d5f059c9e5 Bump docker/build-push-action from 3.1.0 to 3.1.1
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 3.1.0 to 3.1.1.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/1cb9d22b932e4832bb29793b7777ec860fc1cde0...c84f38281176d4c9cdb1626ffafcd6b3911b5d94)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-05 23:36:29 +00:00
irongut 84eac7e593 merge PR #62 Implement StepSecurity Secure Workflows (policy)
PR: Implement StepSecurity Secure Workflows (policy)
2022-08-05 23:57:50 +01:00
irongut 74295b4928 implement stepsecurity policy for release workflow #51 2022-08-05 23:47:41 +01:00
irongut 3216094ffb implement stepsecurity policy for ci build workflow #51 2022-08-05 23:26:04 +01:00
irongut 59bf0ee52a implement stepsecurity policy for codeql workflow #51 2022-08-05 23:22:45 +01:00
irongut 9702896171 implement stepsecurity policy for pm workflows #51 2022-08-05 23:22:13 +01:00