121 Commits

Author SHA1 Message Date
Sebb
b6d39a4257 Don't persist credentials unnecessarily 2022-10-08 15:23:43 +01:00
Gary Gregory
912682d0bb Set to level permissions to 'read' 2022-10-07 20:09:42 -04:00
dependabot[bot]
862f537846 Bump actions/cache from 3.0.9 to 3.0.10
Bumps [actions/cache](https://github.com/actions/cache) from 3.0.9 to 3.0.10.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v3.0.9...v3.0.10)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-08 11:25:48 +13:00
dependabot[bot]
74ff229b56 Bump actions/checkout from 3.0.2 to 3.1.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.0.2 to 3.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v3.0.2...93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-08 11:18:03 +13:00
Gary Gregory
5cf676b5b9 Bump actions/setup-java from 3 to 3.5.1 2022-10-01 14:52:28 -04:00
dependabot[bot]
8488f01f89 Bump actions/cache from 3.0.8 to 3.0.9
Bumps [actions/cache](https://github.com/actions/cache) from 3.0.8 to 3.0.9.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v3.0.8...v3.0.9)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-10-01 16:05:17 +13:00
Gary Gregory
b548be5f64 Use GitHub cache for CodeQL 2022-09-22 08:49:41 -04:00
Gary Gregory
10cd60c87d Use read-all permissions for GitHub workflow 2022-09-12 10:23:46 -07:00
Gary Gregory
4e5cda0dcf Make workflow readonly 2022-09-12 10:11:48 -07:00
Gary Gregory
a55a922f81 Add same scorecards-analysis.yml as Apache Log4j (except for branches) 2022-09-12 09:42:46 -07:00
Gary Gregory
a0234a6cad Bump actions/checkout from 3 to 3.0.2. 2022-09-06 09:32:42 -07:00
Gary Gregory
75f35d6dc0 Bump actions/cache from 3.0.7 to 3.0.8 2022-08-22 15:25:44 -04:00
Gary Gregory
969a9d9f11 Bump actions/cache from 3.0.6 to 3.0.7 2022-08-12 07:17:39 -04:00
Gary Gregory
43658a2785 Bump actions/cache from 3.0.5 to 3.0.6 2022-08-05 08:39:34 -04:00
Gary Gregory
744d3d1634 Update GitHub builds to use Temurin 2022-07-29 08:40:18 -04:00
Gary Gregory
e18a744880 Bump actions/cache 3.0.4 to 3.0.5 2022-07-15 20:15:14 -04:00
Gary Gregory
351df93276 Bump actions/cache 3.0.4 to 3.0.5 2022-07-15 08:37:57 -04:00
Gary Gregory
edb7a6775a Add GitHub coverage.yml. 2022-06-08 12:37:01 -04:00
Gary Gregory
80b36f1ea6 Bump actions/cache from 3.0.3 to 3.0.4 2022-06-07 14:00:29 -04:00
Gary Gregory
330ba4d932 Bump actions/cache from 3.0.2 to 3.0.3 2022-05-31 16:37:13 -04:00
Gary Gregory
0bf7b5380f Set permissions to read for coverage 2022-05-26 12:10:11 -04:00
Gary Gregory
3e67d33d25 Add coverage.yml 2022-05-26 08:22:58 -04:00
Varun Sharma
711782470f ci: add GitHub token permissions 2022-05-20 16:24:18 +12:00
dependabot[bot]
505f76724c
Bump github/codeql-action from 1 to 2 (#886)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-05-01 14:09:07 -04:00
Gary Gregory
0b51bc7bee Bump actions/cache from 3 to 3.0.2 2022-04-12 08:43:41 -04:00
dependabot[bot]
dded8fd504 Bump actions/setup-java from 2 to 3
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 2 to 3.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](https://github.com/actions/setup-java/compare/v2...v3)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-04-09 09:39:02 +12:00
dependabot[bot]
35f3293b50
Bump actions/cache from 2.1.7 to 3 (#867)
Bumps [actions/cache](https://github.com/actions/cache) from 2.1.7 to 3.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2.1.7...v3)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-03-25 08:48:07 -07:00
dependabot[bot]
bddebf5cd3
Bump actions/checkout from 2 to 3 (#859)
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...v3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-03-04 10:16:57 -05:00
Gary Gregory
184e20697b
Add CodeQL and see what it says. 2022-01-30 15:04:16 -05:00
Rob Tompkins
ac37c4a46a
update(dependabot): daily -> weekly;friday 2021-12-29 11:59:41 -05:00
dependabot[bot]
2e6b228355 Bump actions/cache from 2.1.6 to 2.1.7
Bumps [actions/cache](https://github.com/actions/cache) from 2.1.6 to 2.1.7.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2.1.6...v2.1.7)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-11-24 13:45:43 +13:00
dependabot[bot]
6004a7d954
Bump actions/checkout from 2.3.5 to 2.4.0 (#825)
Bumps [actions/checkout](https://github.com/actions/checkout) from 2.3.5 to 2.4.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2.3.5...v2.4.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-11-12 08:00:23 -05:00
dependabot[bot]
b8b052e55b
Bump actions/checkout from 2.3.4 to 2.3.5 (#819)
Bumps [actions/checkout](https://github.com/actions/checkout) from 2.3.4 to 2.3.5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2.3.4...v2.3.5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-10-22 14:38:57 -04:00
Gary Gregory
b153aca877 Update GitHub build from Java 16 to 17.
Update GitHub build from Java 17-EA to 18-EA but comment it (not there
yet).
2021-09-28 11:18:19 -04:00
Gary Gregory
8d30dfb09f AdoptOpenJDK is moving to the Eclipse Foundation and rebranding as
Eclipse Temurin.
2021-08-29 00:18:52 -04:00
dependabot[bot]
8abcc1a54c
Bump actions/cache from 2.1.5 to 2.1.6 (#764)
Bumps [actions/cache](https://github.com/actions/cache) from 2.1.5 to 2.1.6.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2.1.5...v2.1.6)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-06-22 08:44:02 -04:00
Gary Gregory
a5d4660eed Allow Java 16 to fail to allow Java 8 and 11 to run until we know what's
wrong on Java 16.
2021-04-19 08:41:55 -04:00
Gary Gregory
07f7143092 Allow Java 16 to fail to allow Java 8 and 11 to run until we know what's
wrong on Java 16.
2021-04-19 08:39:40 -04:00
Gary Gregory
6ad3961b3f Bump actions/setup-java from v1.4.3 to v2.
Update changes.xml for recent PRs.
2021-04-18 18:47:19 -04:00
dependabot[bot]
f0ed760004
Bump actions/cache from v2.1.4 to v2.1.5 (#742)
Bumps [actions/cache](https://github.com/actions/cache) from v2.1.4 to v2.1.5.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2.1.4...1a9e2138d905efd099035b49d8b7a3888c653ca8)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-04-18 18:39:32 -04:00
Gary Gregory
69c9593cc1 Replace GitHub build for Java 15 with Java 16 and drop Java 16-ea. 2021-03-17 15:49:49 -04:00
dependabot[bot]
dd9a45ea45
Bump actions/cache from v2 to v2.1.4 (#710)
Bumps [actions/cache](https://github.com/actions/cache) from v2 to v2.1.4.
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](https://github.com/actions/cache/compare/v2...26968a09c0ea4f3e233fdddbafd1166051a095f6)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-02-10 17:09:22 -05:00
Gary Gregory
b5680c55f3 Add Java 17-EA to the GitHub build. 2020-12-29 19:13:52 -05:00
dependabot[bot]
553e192aac
Bump actions/checkout from v2.3.3 to v2.3.4 (#639)
Bumps [actions/checkout](https://github.com/actions/checkout) from v2.3.3 to v2.3.4.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2.3.3...5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2020-11-06 09:42:09 -05:00
Rob Tompkins
69598f5b30
Merge pull request #619 from apache/dependabot/github_actions/actions/checkout-v2.3.3
Bump actions/checkout from v2.3.2 to v2.3.3
2020-10-01 10:14:37 -04:00
dependabot[bot]
737f32a06c
Bump actions/setup-java from v1.4.2 to v1.4.3
Bumps [actions/setup-java](https://github.com/actions/setup-java) from v1.4.2 to v1.4.3.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](https://github.com/actions/setup-java/compare/v1.4.2...d202f5dbf7256730fb690ec59f6381650114feb2)

Signed-off-by: dependabot[bot] <support@github.com>
2020-10-01 06:01:33 +00:00
dependabot[bot]
4a5cfd3368
Bump actions/checkout from v2.3.2 to v2.3.3
Bumps [actions/checkout](https://github.com/actions/checkout) from v2.3.2 to v2.3.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2.3.2...a81bbbf8298c0fa03ea29cdc473d45769f953675)

Signed-off-by: dependabot[bot] <support@github.com>
2020-09-24 05:53:46 +00:00
Gary Gregory
8e0a8f2298 Replace Java 14 with Java 15 as the latest Java version to test. Use
Jaav 16 EA as the EA version to test.
2020-09-19 15:46:59 -04:00
Gary Gregory
649dedbbe8 Trigger a GitHub build on pull requests. 2020-08-31 21:25:40 -04:00
dependabot[bot]
0823b7568f
Bump actions/setup-java from v1.4.0 to v1.4.2 (#612)
Bumps [actions/setup-java](https://github.com/actions/setup-java) from v1.4.0 to v1.4.2.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](https://github.com/actions/setup-java/compare/v1.4.0...8bb50d97d6b4d316daf284fdf8eafbfc988421fc)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2020-08-30 11:33:46 -04:00