Commit Graph

110 Commits

Author SHA1 Message Date
Herman Slatman
3e90f37689 Revert "Disable govulncheck until go 1.25.5 is available in github actions (#2490)"
This reverts commit 8e76e290c0.
2025-12-03 14:55:50 +01:00
Max
8e76e290c0 Disable govulncheck until go 1.25.5 is available in github actions (#2490) 2025-12-02 19:39:12 -08:00
dependabot[bot]
895e8c61bf Bump softprops/action-gh-release from 2.4.2 to 2.5.0
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.4.2 to 2.5.0.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](5be0e66d93...a06a81a03e)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-01 17:04:12 +00:00
dependabot[bot]
35702e7390 Bump softprops/action-gh-release from 2.4.1 to 2.4.2
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.4.1 to 2.4.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](6da8fa9354...5be0e66d93)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-10 16:36:17 +00:00
dependabot[bot]
ff3c08778f Bump softprops/action-gh-release from 2.3.4 to 2.4.1
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.3.4 to 2.4.1.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](62c96d0c4e...6da8fa9354)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-13 15:24:03 +00:00
dependabot[bot]
3a421512f2 Bump softprops/action-gh-release from 2.3.3 to 2.3.4
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.3.3 to 2.3.4.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](6cbd405e2c...62c96d0c4e)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-06 15:20:37 +00:00
dependabot[bot]
0adecdb845 Bump softprops/action-gh-release from 2.3.2 to 2.3.3
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.3.2 to 2.3.3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](72f2c25fcb...6cbd405e2c)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-08 15:17:22 +00:00
dependabot[bot]
60faccdf6c Bump softprops/action-gh-release from 2.2.2 to 2.3.2
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.2.2 to 2.3.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](da05d55257...72f2c25fcb)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.3.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-16 17:07:34 +00:00
dependabot[bot]
d61c3d9971 Bump softprops/action-gh-release from 2.2.1 to 2.2.2
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.2.1 to 2.2.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](c95fe14893...da05d55257)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-04-21 16:22:00 +00:00
dependabot[bot]
9f50dd9030 Bump softprops/action-gh-release from 2.2.0 to 2.2.1
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.2.0 to 2.2.1.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](7b4da11513...c95fe14893)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-13 15:23:46 +00:00
dependabot[bot]
1bc4eded3b Bump softprops/action-gh-release from 2.1.0 to 2.2.0
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.1.0 to 2.2.0.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](01570a1f39...7b4da11513)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-12-16 16:06:37 +00:00
Joe Doss
2b4894a871 Configure GitHub Actions to publish RPMs and Debs to packages.smallstep.com. 2024-11-18 11:35:50 -06:00
dependabot[bot]
fc007dfd03 Bump softprops/action-gh-release from 2.0.9 to 2.1.0
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.0.9 to 2.1.0.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](e7a8f85e1c...01570a1f39)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-11-18 16:20:05 +00:00
dependabot[bot]
0a0dfc008e Bump softprops/action-gh-release from 2.0.8 to 2.0.9
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.0.8 to 2.0.9.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](c062e08bd5...e7a8f85e1c)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-11-04 15:17:26 +00:00
Max
364629e2a2 [ci] Missing permission in goreleaser job (#1993) 2024-09-13 10:05:38 -07:00
Emmanuel Ferdman
52a4a27972 Update reference to contributing file
Signed-off-by: Emmanuel Ferdman <emmanuelferdman@gmail.com>
2024-09-02 15:21:25 +03:00
dependabot[bot]
2dda026392 Bump softprops/action-gh-release from 2.0.6 to 2.0.8
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.0.6 to 2.0.8.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](a74c6b72af...c062e08bd5)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-22 16:01:34 +00:00
Max
0a9dd62d8f [actions] use ref_name as release name (#1924) 2024-07-12 10:44:58 -07:00
Max
3978d2b859 Update changelog for 0.27.0 | add actionlint | update go.step.sm/crypto (#1923) 2024-07-11 22:00:41 -07:00
dependabot[bot]
fffffc60a8 Bump softprops/action-gh-release from 2.0.5 to 2.0.6
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.0.5 to 2.0.6.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](69320dbe05...a74c6b72af)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-06-24 15:07:24 +00:00
Max
890e81cb66 [actions] dependabot to common workflow | move to new release action (#1887) 2024-06-13 12:25:05 -07:00
dependabot[bot]
bf03d56ae4 Bump dependabot/fetch-metadata from 2.0.0 to 2.1.0
Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](https://github.com/dependabot/fetch-metadata/compare/v2.0.0...v2.1.0)

---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-04-29 15:35:42 +00:00
dependabot[bot]
014b4ef2c0 Bump dependabot/fetch-metadata from 1.6.0 to 2.0.0
Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 1.6.0 to 2.0.0.
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](https://github.com/dependabot/fetch-metadata/compare/v1.6.0...v2.0.0)

---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-03-25 15:54:53 +00:00
Max
c451546cfb [action] fix actionlint warnings (#1598) 2023-10-23 19:22:26 +02:00
dependabot[bot]
f548c13e3e Bump dependabot/fetch-metadata from 1.1.1 to 1.6.0
Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 1.1.1 to 1.6.0.
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](https://github.com/dependabot/fetch-metadata/compare/v1.1.1...v1.6.0)

---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-17 13:39:37 +00:00
Max
830f31c6d1 [action] add dependabot updates for github actions (#1586) 2023-10-17 16:39:17 +03:00
Max
5758657b53 [action] remove gitleaks key from code-scan-cron (#1564) 2023-09-29 19:34:28 +02:00
Max
67d32685c7 [action] updated goCI workflow API (#1429) 2023-06-13 11:13:42 -07:00
Max
53c7774d3c [action] use common goreleaser workflow (#1427) 2023-06-09 16:28:44 -07:00
Max
99f9b2fb3e Update .github/workflows/release.yml
Co-authored-by: Mariano Cano <mariano@smallstep.com>
2023-04-12 18:31:35 -07:00
max furman
574351a8f7 [action] Fix docker image name in release workflow 2023-04-12 18:26:19 -07:00
Max
5ec9e761ca Merge pull request #1299 from smallstep/docker-hsm-glibc
Update Dockerfile.hsm to use debian:bullseye base image
2023-04-12 14:32:11 -07:00
Carl Tashian
3665616015 Deprecate the step-ca-hsm image in favor of step-ca:hsm 2023-04-11 09:40:49 -07:00
Herman Slatman
1cc3ad27a5 Run TPM simulator tests 2023-03-30 11:39:24 +02:00
Carl Tashian
7a3989e7f2 Replace deprecated GoReleaser --rm-dist flag with --clean
See d18adfb57e
2023-03-15 10:52:00 -07:00
max furman
74e6245e90 enable auto merge for dependabot PRs 2023-02-13 17:06:00 -08:00
Mariano Cano
3b1be62663 Add step-kms-plugin to docker images and build a CGO based one 2023-01-26 16:52:19 -08:00
max furman
c36b36f070 [action] cosign over docker image digest 2022-10-27 22:50:04 -07:00
max furman
c43d59a69a [action] keyless cosign for all release artifacts 2022-10-25 21:52:35 -07:00
max furman
91775f6d67 [action] move oss triage wofkow to common workflows 2022-10-18 11:57:47 -07:00
max furman
c66218330a [action] replace secrets.PAT with more specific secrets 2022-10-04 22:02:08 -07:00
max furman
4c687efb17 [action] updates and first pass at goreleaser deb 2022-10-03 15:56:34 -07:00
max furman
505c411a67 [action] remove gitleaks secret, add codecov secret and inheritance 2022-10-03 11:55:53 -07:00
Max
bfe29def59 Merge pull request #1065 from smallstep/max/code-scan
[actiono] Update workflows
2022-09-27 12:26:29 -07:00
Max
ea229e2ba8 Create dependabot.yml 2022-09-26 16:32:51 -07:00
max furman
2fcadce977 [action] remove extraneous new line 2022-09-26 15:48:46 -07:00
max furman
630e7fbba9 [action] Adding the libpcsclite.pc package back. 2022-09-26 15:48:21 -07:00
max furman
8e2fc8ea5a [action] Don't need cgo enabled build for step-ca. 2022-09-26 15:42:30 -07:00
max furman
68f571645b [action] Update code-scan-cron 2022-09-23 23:37:11 -07:00
max furman
fa4986d215 [actiono] Update workflows 2022-09-23 23:21:44 -07:00