diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 699ff38a88..e806e98ee6 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -42,7 +42,7 @@ jobs: uses: gradle/actions/setup-gradle@4d9f0ba0025fe599b4ebab900eb7f3a1d93ef4c2 # v5.0.0 - name: Initialize CodeQL - uses: github/codeql-action/init@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8 + uses: github/codeql-action/init@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9 with: languages: ${{ matrix.language }} # using "linked" helps to keep up with the latest Kotlin support @@ -59,7 +59,7 @@ jobs: DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }} - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8 + uses: github/codeql-action/analyze@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index 9b5a33556a..77166a657d 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -44,6 +44,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@1b168cd39490f61582a9beae412bb7057a6b2c4e # v4.31.8 + uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9 with: sarif_file: results.sarif diff --git a/log-appender/build.gradle.kts b/log-appender/build.gradle.kts index 1d8ff014c4..09a565f474 100644 --- a/log-appender/build.gradle.kts +++ b/log-appender/build.gradle.kts @@ -23,7 +23,7 @@ dependencies { implementation("org.slf4j:jul-to-slf4j:2.0.17") // Log4j - implementation(platform("org.apache.logging.log4j:log4j-bom:2.25.2")) + implementation(platform("org.apache.logging.log4j:log4j-bom:2.25.3")) implementation("org.apache.logging.log4j:log4j-api") implementation("org.apache.logging.log4j:log4j-core") diff --git a/otlp/docker/docker-compose.yaml b/otlp/docker/docker-compose.yaml index cf3558e2db..acf2f6bd2b 100644 --- a/otlp/docker/docker-compose.yaml +++ b/otlp/docker/docker-compose.yaml @@ -36,7 +36,7 @@ services: prometheus: container_name: prometheus - image: prom/prometheus:v3.8.0@sha256:d936808bdea528155c0154a922cd42fd75716b8bb7ba302641350f9f3eaeba09 + image: prom/prometheus:v3.8.1@sha256:2b6f734e372c1b4717008f7d0a0152316aedd4d13ae17ef1e3268dbfaf68041b volumes: - ./prometheus.yaml:/etc/prometheus/prometheus.yml ports: diff --git a/prometheus/docker-compose.yml b/prometheus/docker-compose.yml index 2ef127487b..0c59721879 100644 --- a/prometheus/docker-compose.yml +++ b/prometheus/docker-compose.yml @@ -4,7 +4,7 @@ services: ports: - '19090:19090' prometheus: - image: prom/prometheus@sha256:d936808bdea528155c0154a922cd42fd75716b8bb7ba302641350f9f3eaeba09 + image: prom/prometheus@sha256:2b6f734e372c1b4717008f7d0a0152316aedd4d13ae17ef1e3268dbfaf68041b volumes: - ./prometheus.yml:/etc/prometheus/prometheus.yml depends_on: diff --git a/settings.gradle.kts b/settings.gradle.kts index 3ee955564e..c6244418d3 100644 --- a/settings.gradle.kts +++ b/settings.gradle.kts @@ -2,7 +2,7 @@ pluginManagement { plugins { id("com.diffplug.spotless") version "8.1.0" id("com.gradleup.shadow") version "9.3.0" - id("com.google.protobuf") version "0.9.5" + id("com.google.protobuf") version "0.9.6" id("org.gradle.toolchains.foojay-resolver-convention") version "1.0.0" id("com.google.cloud.tools.jib") version "3.5.2" id("com.gradle.develocity") version "4.3"