Commit Graph
93 Commits
Author SHA1 Message Date
dependabot[bot] e1738affb4 Bump azure/login from 3.0.0 to 3.0.1 (#15731)
Bumps [azure/login](https://github.com/azure/login) from 3.0.0 to 3.0.1.
- [Release notes](https://github.com/azure/login/releases)
- [Commits](https://github.com/azure/login/compare/532459ea530d8321f2fb9bb10d1e0bcf23869a43...f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca)

---
updated-dependencies:
- dependency-name: azure/login
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-16 08:19:13 +02:00
dependabot[bot] 2d60a959c0 Bump actions/checkout from 7.0.0 to 7.0.1 (#15698)
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-29 09:55:25 +02:00
dependabot[bot] 6f9f2d1429 Bump actions/checkout from 6.0.3 to 7.0.0 (#15536)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-01 13:07:18 +02:00
dependabot[bot] 03c42d723c Bump actions/checkout from 6.0.2 to 6.0.3 (#15449)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-13 14:13:07 +02:00
dependabot[bot] 1f50ad0aa5 Bump azure/trusted-signing-action from 1.2.0 to 2.0.0 (#15422)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 1.2.0 to 2.0.0.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/b443cf8ea4124818d2ea9f043cba29fc3ec47b16...c7ab2a863ab5f9a846ddb8265964877ef296ee82)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-28 10:39:43 +02:00
José Valim 42a005e4df Bump CI to OTP 29 (#15367) 2026-05-13 14:52:22 +02:00
dependabot[bot] 13d412864c Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#15299)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-26 09:34:15 +02:00
dependabot[bot] 5c845c796c Bump azure/trusted-signing-action from 1.1.0 to 1.2.0 (#15225)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 1.1.0 to 1.2.0.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/87c2e83e6868da99d3380aa309851b32ed9a8346...b443cf8ea4124818d2ea9f043cba29fc3ec47b16)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 10:19:21 +02:00
dependabot[bot] 28b6616a59 Bump actions/download-artifact from 8.0.0 to 8.0.1 (#15214)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 8.0.0 to 8.0.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3...3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 10:22:44 +02:00
dependabot[bot] 7c2d4f3d8e Bump actions/attest-sbom from 4.0.0 to 4.1.0 (#15213)
Bumps [actions/attest-sbom](https://github.com/actions/attest-sbom) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/actions/attest-sbom/releases)
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-sbom/compare/07e74fc4e78d1aad915e867f9a094073a9f71527...c604332985a26aa8cf1bdc465b92731239ec6b9e)

---
updated-dependencies:
- dependency-name: actions/attest-sbom
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 10:22:28 +02:00
dependabot[bot] ba4eb73734 Bump azure/login from 2.3.0 to 3.0.0 (#15212)
Bumps [azure/login](https://github.com/azure/login) from 2.3.0 to 3.0.0.
- [Release notes](https://github.com/azure/login/releases)
- [Commits](https://github.com/azure/login/compare/a457da9ea143d694b1b9c7c869ebb04ebe844ef5...532459ea530d8321f2fb9bb10d1e0bcf23869a43)

---
updated-dependencies:
- dependency-name: azure/login
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 10:22:03 +02:00
dependabot[bot] 445895c98a Bump actions/attest-sbom from 3.0.0 to 4.0.0 (#15177)
Bumps [actions/attest-sbom](https://github.com/actions/attest-sbom) from 3.0.0 to 4.0.0.
- [Release notes](https://github.com/actions/attest-sbom/releases)
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-sbom/compare/4651f806c01d8637787e274ac3bdf724ef169f34...07e74fc4e78d1aad915e867f9a094073a9f71527)

---
updated-dependencies:
- dependency-name: actions/attest-sbom
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-14 09:50:35 +01:00
dependabot[bot] e9adf01e3f Bump actions/upload-artifact from 6.0.0 to 7.0.0 (#15176)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/b7c566a772e6b6bfb58ed0dc250532a479d7789f...bbbca2ddaa5d8feaa63e36b76fdaad77386f024f)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-14 09:50:21 +01:00
dependabot[bot] c184b82b5f Bump actions/download-artifact from 7.0.0 to 8.0.0 (#15126)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 7.0.0 to 8.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/37930b1c2abaa49bbe596cd826c3c89aef350131...70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-10 09:01:25 +01:00
Jean Klingler 13024f43c0 Remove OTP26 support and add OTP29-rc (#15164)
* Update OTP compatibility table

* Add OTP 29.0 rc to CI, remove 26.0

* Remove :elxiir_json polyfill

* Remove :elixir_utils.jaro_similarity polyfill

* defdelegate directly to :proc_lib.set_label/2
2026-03-10 15:10:19 +09:00
Eric Meadows-Jönsson 80df1fe3dc Fix undefined ref_name variable in release S3 upload (#15139) 2026-03-06 12:15:42 +01:00
Jonatan Männchen a71a4e8f7a Keep credentials for release branch tagging (#15115)
The checkout in create_draft_release needs credentials to push
the branch-latest tag to origin.
2026-02-25 13:16:23 +01:00
Jonatan Männchen 32d20fd77c Prevent template injection in GitHub Actions workflows
Use environment variables instead of direct template expansion
in shell run blocks to prevent potential code injection.

See: https://docs.zizmor.sh/audits/#template-injection
2026-02-25 12:59:01 +01:00
Jonatan Männchen dfe857e7df Prevent credential persistence in checkout actions
Add `persist-credentials: false` to all `actions/checkout` usages
to prevent Git credentials from being persisted in the repository
after checkout completes.

See: https://docs.zizmor.sh/audits/#artipacked
2026-02-25 12:59:01 +01:00
dependabot[bot] d8eed7812b Bump azure/trusted-signing-action from 1.0.0 to 1.1.0 (#15103)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 1.0.0 to 1.1.0.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/db7a3a6bd3912025c705162fb7475389f5b69ec6...87c2e83e6868da99d3380aa309851b32ed9a8346)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 23:23:45 +01:00
dependabot[bot] ff132444ca Bump actions/checkout from 6.0.1 to 6.0.2 (#15078)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.1 to 6.0.2.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/8e8c483db84b4bee98b60c0593521ed34d9990e8...de0fac2e4500dabe0009e67214ff5f5447ce83dd)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 07:58:52 +01:00
dependabot[bot] a26c321e79 Bump azure/trusted-signing-action from 0.5.11 to 1.0.0 (#15072)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 0.5.11 to 1.0.0.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/1d365fec12862c4aa68fcac418143d73f0cea293...db7a3a6bd3912025c705162fb7475389f5b69ec6)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-20 09:00:13 +01:00
dependabot[bot] 7a01f5bab2 Bump actions/download-artifact from 6.0.0 to 7.0.0 (#15016)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/018cc2cf5baa6db3ef3c5f8a56943fffe632ef53...37930b1c2abaa49bbe596cd826c3c89aef350131)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-29 12:48:48 +01:00
dependabot[bot] f7904a4aa6 Bump actions/upload-artifact from 5.0.0 to 6.0.0 (#15015)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/330a01c490aca151604b8cf639adc76d48f6c5d4...b7c566a772e6b6bfb58ed0dc250532a479d7789f)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-29 12:48:39 +01:00
dependabot[bot] 6948d08d51 Bump actions/checkout from 6.0.0 to 6.0.1 (#15005)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.0 to 6.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/1af3b93b6815bc44a9784bd300feb67ff0d1eeb3...8e8c483db84b4bee98b60c0593521ed34d9990e8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-29 12:48:24 +01:00
dependabot[bot] 0473fec367 Bump azure/trusted-signing-action from 0.5.10 to 0.5.11 (#15004)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 0.5.10 to 0.5.11.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/fc390cf8ed0f14e248a542af1d838388a47c7a7c...1d365fec12862c4aa68fcac418143d73f0cea293)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 0.5.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-29 12:48:15 +01:00
Eksperimental b58cdd823c CI: Minor improvements to release.yml (#14983) 2025-12-02 11:02:01 +01:00
Eksperimental 2acf5804d3 CI: Update Ubuntu to latest LTS version (#14974) 2025-11-29 18:06:06 +01:00
dependabot[bot] da1481e433 Bump actions/checkout from 5.0.1 to 6.0.0 (#14956)
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.1 to 6.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/93cb6efe18208431cddfb8368fd83d5badbf9bfd...1af3b93b6815bc44a9784bd300feb67ff0d1eeb3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-11-27 10:49:38 +01:00
dependabot[bot] 98b35eaa53 Bump actions/checkout from 5.0.0 to 5.0.1 (#14919)
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.0 to 5.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/08c6903cd8c0fde910a37f88322edcfb5dd907a8...93cb6efe18208431cddfb8368fd83d5badbf9bfd)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-11-17 13:52:53 -08:00
dependabot[bot] 58c45612dc Bump actions/download-artifact from 5.0.0 to 6.0.0 (#14864)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/634f93cb2916e3fdff6788551b99b062d0335ce0...018cc2cf5baa6db3ef3c5f8a56943fffe632ef53)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-28 08:05:00 +01:00
dependabot[bot] e9370bb023 Bump actions/upload-artifact from 4.6.2 to 5.0.0 (#14863)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 5.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/ea165f8d65b6e75b540449e92b4886f43607fa02...330a01c490aca151604b8cf639adc76d48f6c5d4)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-28 08:04:35 +01:00
dependabot[bot] e1214a64c9 Bump azure/trusted-signing-action from 0.5.9 to 0.5.10 (#14848)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 0.5.9 to 0.5.10.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/bb15ca63eb5548cc306f4f335c5617bb414abcad...fc390cf8ed0f14e248a542af1d838388a47c7a7c)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 0.5.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-21 12:59:34 +02:00
Eric Meadows-Jönsson c265744b9c Fix hex upload of Elixir build without -otp- suffix (#14840)
OTP 25 is no longer supported so we didn't upload a generic build.
Instead find the oldest version instead of hardcoding it.
2025-10-17 22:13:34 +02:00
Jonatan Männchen 2e7ee76ac2 Correct builds.hex.pm Publish Condition in CI (#14772) 2025-09-15 23:13:08 +02:00
dependabot[bot] 0dd3985f16 Bump actions/attest-sbom from 2.4.0 to 3.0.0 (#14752)
Bumps [actions/attest-sbom](https://github.com/actions/attest-sbom) from 2.4.0 to 3.0.0.
- [Release notes](https://github.com/actions/attest-sbom/releases)
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-sbom/compare/bd218ad0dbcb3e146bd073d1d9c6d78e08aa8a0b...4651f806c01d8637787e274ac3bdf724ef169f34)

---
updated-dependencies:
- dependency-name: actions/attest-sbom
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-09 20:05:09 +02:00
Jonatan Männchen 56333d451e tighten CI secret scope and move AWS config to environment vars (#14627)
* Add `environment: release` to the "publish-to-hex" job so that only
  workflows explicitly targeting the release environment can read
  sensitive values.
* Gate the job behind `if: ${{ vars.HEX_AWS_REGION }}` to avoid noisy
  failures in forks where the variable is not configured.
* Replace `${{ secrets.HEX_AWS_REGION }}` / `${{ secrets.HEX_AWS_S3_BUCKET }}`
  references with `${{ vars.* }}`.  These are not credentials, so
  environment-level *variables* are a better fit and keep them readable
  only by jobs that declare the environment.
* Remove Fastly secrets from the job-wide `env:` block and inject them
  only into the Fastly purge step, following the principle of least
  privilege.  Other steps no longer see these tokens.

Restricting secret visibility to an environment and to the exact step
that needs them reduces the blast radius of a compromised workflow run,
blocks accidental exposure in logs of unrelated steps, and stops forks
from obtaining privileged data.
2025-09-03 22:14:09 +02:00
dependabot[bot] eee42e4448 Bump actions/checkout from 4.2.2 to 5.0.0 (#14710)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/11bd71901bbe5b1630ceea73d27597364c9af683...08c6903cd8c0fde910a37f88322edcfb5dd907a8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-30 10:58:44 +02:00
dependabot[bot] 03522aaeb2 Bump actions/download-artifact from 4.3.0 to 5.0.0 (#14708)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.3.0 to 5.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/d3f86a106a0bac45b974a628896c90dbdf5c8093...634f93cb2916e3fdff6788551b99b062d0335ce0)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-12 09:34:43 +02:00
dependabot[bot] a4f40f7622 Bump azure/trusted-signing-action from 0.5.1 to 0.5.9 (#14653)
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 0.5.1 to 0.5.9.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](https://github.com/azure/trusted-signing-action/compare/0d74250c661747df006298d0fb49944c10f16e03...bb15ca63eb5548cc306f4f335c5617bb414abcad)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: 0.5.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-15 12:45:34 +02:00
Jonatan Männchen 1753c81f9e Use Workload Identity Federation for Windows Trusted Signing (#14604) 2025-06-25 19:29:47 +02:00
dependabot[bot] dc4c1cf402 Bump actions/attest-sbom from 2.2.0 to 2.4.0 (#14582)
Bumps [actions/attest-sbom](https://github.com/actions/attest-sbom) from 2.2.0 to 2.4.0.
- [Release notes](https://github.com/actions/attest-sbom/releases)
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-sbom/compare/115c3be05ff3974bcbd596578934b3f9ce39bf68...bd218ad0dbcb3e146bd073d1d9c6d78e08aa8a0b)

---
updated-dependencies:
- dependency-name: actions/attest-sbom
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-16 16:14:39 -07:00
José Valim 51e160e6f8 Add OTP 28 to CI (#14510) 2025-05-21 13:48:13 +02:00
dependabot[bot] ef11da961d Bump actions/download-artifact from 4.2.1 to 4.3.0 (#14457)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.2.1 to 4.3.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/95815c38cf2ff2164869cbab79da8d1f422bc89e...d3f86a106a0bac45b974a628896c90dbdf5c8093)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-29 22:33:35 +02:00
dependabot[bot] 5c63c8d94d Bump actions/download-artifact from 4.1.9 to 4.2.1 (#14361)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.1.9 to 4.2.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/cc203385981b70ca67e1cc392babf9cc229d5806...95815c38cf2ff2164869cbab79da8d1f422bc89e)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 10:06:25 +01:00
dependabot[bot] 95b63d74dc Bump actions/upload-artifact from 4.6.1 to 4.6.2 (#14360)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.1 to 4.6.2.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1...ea165f8d65b6e75b540449e92b4886f43607fa02)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 09:57:06 +01:00
Jonatan Männchen 37faa6761f Limit GH Actions Token Permissions (#14333) 2025-03-17 14:25:44 +01:00
Jonatan Männchen 6cd8082494 Pin GitHub Actions (#14332) 2025-03-17 14:25:22 +01:00
Wojtek Mach cd6fcc41a6 Add instructions for updating AZURE_CLIENT_SECRET (#14284) 2025-02-19 11:26:22 +01:00
Jonatan Männchen e45a1f2593 Improve SBoM Details (#14258) 2025-02-09 17:35:07 +01:00