Gregory Oschwald
b86944d9f4
Pin GitHub Actions to SHA for security
...
Update official GitHub Actions (actions/*, github/*) to use pinned
commit SHAs instead of version tags. This satisfies zizmor's
unpinned-action-reference security check.
🤖 Generated with [Claude Code](https://claude.com/claude-code )
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-07 14:14:00 -08:00
William Storey
b416ef9876
Test on PHP 8.5
2025-12-29 08:48:33 -08:00
Gregory Oschwald
01b96934bb
Update Dependabot cooldown from 4 to 7 days
2025-12-12 09:19:33 -08:00
Gregory Oschwald
7095078684
Replace i386 tests with arm64 in CI workflow
...
i386 support has been dropped upstream in setup-php due to deb.sury
removing i386 packages.
See: https://github.com/shivammathur/setup-php/issues/1040#issuecomment-3608728874
🤖 Generated with [Claude Code](https://claude.com/claude-code )
Co-Authored-By: Claude <noreply@anthropic.com >
2025-12-04 07:04:36 -08:00
dependabot[bot]
ca64b098d6
Bump shivammathur/setup-php from 2.35.5 to 2.36.0
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.35.5 to 2.36.0.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/bf6b4fbd49ca58e4608c9c89fba0b8d90bd2a39f...44454db4f0199b8b9685a5d763dc37cbf79108e1 )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-02 14:05:38 +00:00
dependabot[bot]
de83442d3e
Bump zizmorcore/zizmor-action from 0.2.0 to 0.3.0
...
Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action ) from 0.2.0 to 0.3.0.
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases )
- [Commits](https://github.com/zizmorcore/zizmor-action/compare/e673c3917a1aef3c65c972347ed84ccd013ecda4...e639db99335bc9038abc0e066dfcd72e23d26fb4 )
---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
dependency-version: 0.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-27 14:05:26 +00:00
dependabot[bot]
ff324006ae
Bump actions/checkout from 5 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-25 14:05:30 +00:00
Gregory Oschwald
ae1a4ccb46
Set Dependabot cooldown period to 4 days
...
This addresses the zizmor findings by setting a cooldown period of 4 days
for all package ecosystems in dependabot.yml.
Related to: ENG-3236
2025-10-30 14:28:20 -07:00
William Storey
0690503a6c
Run zizmor via zizmorcore/zizmor-action
2025-10-09 22:04:03 +00:00
dependabot[bot]
419cd60834
Bump astral-sh/setup-uv from 6.8.0 to 7.0.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.8.0 to 7.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/d0cc045d04ccac9d8b7881df0226f9e82c39688e...eb1897b8dc4b5d5bfe39a428a8f2304605e0983c )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-08 14:05:31 +00:00
dependabot[bot]
d236b0678e
Bump astral-sh/setup-uv from 6.7.0 to 6.8.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.7.0 to 6.8.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/b75a909f75acd358c2196fb9a5f1299a9a8868a4...d0cc045d04ccac9d8b7881df0226f9e82c39688e )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-01 14:06:48 +00:00
dependabot[bot]
b34e587142
Bump shivammathur/setup-php from 2.35.4 to 2.35.5
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.35.4 to 2.35.5.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/ec406be512d7077f68eed36e63f4d91bc006edc4...bf6b4fbd49ca58e4608c9c89fba0b8d90bd2a39f )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.35.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-19 14:04:49 +00:00
Marsel Mavletkulov
616306d5f9
update zizmor to version 1.13.0
2025-09-16 18:07:28 +00:00
dependabot[bot]
b7de78b024
Bump astral-sh/setup-uv from 6.6.1 to 6.7.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.6.1 to 6.7.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/557e51de59eb14aaaba2ed9621916900a91d50c6...b75a909f75acd358c2196fb9a5f1299a9a8868a4 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-15 14:37:23 +00:00
dependabot[bot]
02d82a2dc5
Bump astral-sh/setup-uv from 6.6.0 to 6.6.1
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.6.0 to 6.6.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/4959332f0f014c5280e7eac8b70c90cb574c9f9b...557e51de59eb14aaaba2ed9621916900a91d50c6 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.6.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-03 09:59:44 +00:00
dependabot[bot]
fbc53ce83d
Bump shivammathur/setup-php from 2.35.3 to 2.35.4
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.35.3 to 2.35.4.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/20529878ed81ef8e78ddf08b480401e6101a850f...ec406be512d7077f68eed36e63f4d91bc006edc4 )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.35.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-26 02:07:10 +00:00
dependabot[bot]
0dd3e84c31
Bump astral-sh/setup-uv from 6.5.0 to 6.6.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.5.0 to 6.6.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1...4959332f0f014c5280e7eac8b70c90cb574c9f9b )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-21 14:24:54 +00:00
Marsel Mavletkulov
487d99f6f0
update zizmor to version 1.12.1
2025-08-18 16:38:54 +00:00
dependabot[bot]
3ff63eab84
Bump astral-sh/setup-uv from 6.4.3 to 6.5.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.4.3 to 6.5.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/e92bafb6253dcd438e0484186d7669ea7a8ca1cc...d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-13 14:32:30 +00:00
William Storey
c2b7aa85ea
Merge pull request #207 from maxmind/dependabot/github_actions/actions/checkout-5
...
Bump actions/checkout from 4 to 5
2025-08-12 08:30:51 -07:00
dependabot[bot]
b66d588fdd
Bump shivammathur/setup-php from 2.35.2 to 2.35.3
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.35.2 to 2.35.3.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/ccf2c627fe61b1b4d924adfcbd19d661a18133a0...20529878ed81ef8e78ddf08b480401e6101a850f )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.35.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-11 21:27:28 +00:00
dependabot[bot]
1ada4068a7
Bump actions/checkout from 4 to 5
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-11 20:25:15 +00:00
dependabot[bot]
c07dfd63b7
Bump shivammathur/setup-php from 2.34.1 to 2.35.2
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.34.1 to 2.35.2.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/0f7f1d08e3e32076e51cae65eb0b0c871405b16e...ccf2c627fe61b1b4d924adfcbd19d661a18133a0 )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.35.2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-29 14:41:17 +00:00
dependabot[bot]
2a9b6a6541
Bump astral-sh/setup-uv from 6.4.2 to 6.4.3
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.4.2 to 6.4.3.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/2c7142f755d7b37bdaea8d226073714c732889fe...e92bafb6253dcd438e0484186d7669ea7a8ca1cc )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.4.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-24 14:07:10 +00:00
dependabot[bot]
74808be9b3
Bump astral-sh/setup-uv from 6.4.1 to 6.4.2
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.4.1 to 6.4.2.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/7edac99f961f18b581bbd960d59d049f04c0002f...2c7142f755d7b37bdaea8d226073714c732889fe )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.4.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-23 14:35:15 +00:00
William Storey
a61c4f7a5a
Update dependabot schedule
2025-07-21 11:44:51 -07:00
dependabot[bot]
ac4edcb6c9
Bump astral-sh/setup-uv from 6.3.1 to 6.4.1
...
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.4.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-21 04:44:55 +00:00
Marsel Mavletkulov
c181615ef8
update zizmor to verson 1.11.0
2025-07-15 17:28:00 +00:00
dependabot[bot]
422b44ce03
Bump astral-sh/setup-uv from 6.3.0 to 6.3.1
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.3.0 to 6.3.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/445689ea25e0de0a23313031f5fe577c74ae45a1...bd01e18f51369d5a26f1651c3cb451d3417e3bba )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-26 04:37:10 +00:00
dependabot[bot]
0992e208c5
Bump astral-sh/setup-uv from 6.1.0 to 6.3.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.1.0 to 6.3.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb...445689ea25e0de0a23313031f5fe577c74ae45a1 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-20 04:38:29 +00:00
Naji Obeid
bdfb6dcd8b
update zizmor to verson 1.9.0
2025-06-17 19:32:37 +00:00
dependabot[bot]
f6d786b785
Bump shivammathur/setup-php from 2.34.0 to 2.34.1
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.34.0 to 2.34.1.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/27853eb8b46dc01c33bf9fef67d98df2683c3be2...0f7f1d08e3e32076e51cae65eb0b0c871405b16e )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.34.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-13 04:35:41 +00:00
dependabot[bot]
7bca9126c5
Bump shivammathur/setup-php from 2.33.0 to 2.34.0
...
Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php ) from 2.33.0 to 2.34.0.
- [Release notes](https://github.com/shivammathur/setup-php/releases )
- [Commits](https://github.com/shivammathur/setup-php/compare/cf4cade2721270509d5b1c766ab3549210a39a2a...27853eb8b46dc01c33bf9fef67d98df2683c3be2 )
---
updated-dependencies:
- dependency-name: shivammathur/setup-php
dependency-version: 2.34.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-11 04:46:51 +00:00
dependabot[bot]
88ae9f8a4f
Bump astral-sh/setup-uv from 6.0.1 to 6.1.0
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 6.0.1 to 6.1.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/6b9c6063abd6010835644d4c2e1bef4cf5cd0fca...f0ec1fc3b38f5e7cd731bb6ce540c5af426746bb )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-26 04:49:41 +00:00
Philip Nelson
65c3e0c740
update zizmor to verson 1.7.0
2025-05-16 19:43:44 +00:00
dependabot[bot]
b4b67dcb3e
Bump astral-sh/setup-uv from 5 to 6
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 5 to 6.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-25 04:50:47 +00:00
Naji Obeid
c58a50bc8c
update zizmor to verson 1.5.2
2025-04-16 20:13:31 +00:00
Nick Logan
196c187cb1
update zizmor to verson 1.5.1
2025-03-20 20:25:54 +00:00
Naji Obeid
f0752a2b7a
update zizmor to verson 1.3.1
2025-02-12 17:22:53 +00:00
Naji Obeid
ae36d6bf7a
update zizmor to verson 1.3.0
2025-02-07 17:16:41 +00:00
Naji Obeid
52b34d7bd6
update zizmor to verson 1.2.2
2025-01-24 01:46:46 +00:00
Naji Obeid
a154e4865b
change zizmor output format to report warnings
2025-01-08 15:27:50 +00:00
Naji Obeid
f956db7189
integrate zizmor in github actions
2025-01-03 17:17:42 +00:00
Gregory Oschwald
7f540acbc1
Make matrix naming more consistent
2024-11-14 12:53:01 -08:00
Gregory Oschwald
80d53a06ee
Don't test 8.4 on i386
2024-11-14 12:52:31 -08:00
Gregory Oschwald
3731c7dbd8
Test on 8.3 and 8.4
2024-11-14 09:55:14 -08:00
Gregory Oschwald
f05efb9bdc
Remove generation of coverage info
...
We don't look at it.
2024-06-10 13:01:57 -07:00
Gregory Oschwald
2b74ba0e0a
Run composer validate from GitHub Action
2024-04-08 15:08:45 -07:00
dependabot[bot]
29f739f7da
Bump actions/checkout from 3 to 4
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3 to 4.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-09-05 04:30:52 +00:00
Gregory Oschwald
40c3bfc0a1
Revert "Merge pull request #157 from maxmind/greg/test-build"
...
This reverts commit b9ca942054 , reversing
changes made to f8cd5d7f83 .
2023-07-05 10:49:50 -07:00