Skip to content

Update actions/setup-java digest to b6effb0 - #177

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-setup-java-digest
Open

Update actions/setup-java digest to b6effb0#177
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-setup-java-digest

Conversation

@renovate

@renovate renovate Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/setup-java (changelog) action digest 1bcf9fbb6effb0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
⚠️ ACTION actionlint 4 2 0 0.07s
❌ ACTION zizmor 4 22 0 2.35s
✅ COPYPASTE jscpd yes no no 0.51s
✅ JAVASCRIPT eslint 11 0 0 0.9s
✅ JSON jsonlint 8 0 0 0.11s
✅ JSON npm-package-json-lint yes no no 0.48s
✅ JSON prettier 8 0 0 0.33s
✅ JSON v8r 8 0 0 15.02s
⚠️ MARKDOWN markdownlint 10 30 0 0.95s
⚠️ MARKDOWN markdown-table-formatter 10 1 0 0.26s
✅ REPOSITORY betterleaks yes no no 0.61s
✅ REPOSITORY checkov yes no no 21.89s
✅ REPOSITORY gitleaks yes no no 0.75s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 63.31s
❌ REPOSITORY osv-scanner yes 4 no 0.81s
✅ REPOSITORY secretlint yes no no 1.01s
✅ REPOSITORY syft yes no no 2.11s
❌ REPOSITORY trivy yes 1 no 13.11s
✅ REPOSITORY trivy-sbom yes no no 0.54s
✅ REPOSITORY trufflehog yes no no 3.38s
✅ SPELL cspell 46 0 0 3.87s
⚠️ SPELL lychee 29 4 0 0.85s
✅ TYPESCRIPT eslint 1 0 0 0.35s
✅ TYPESCRIPT prettier 1 0 0 0.43s
⚠️ TYPESCRIPT ts-standard 1 1 0 0.44s
✅ YAML prettier 9 0 0 0.48s
✅ YAML v8r 9 0 0 7.97s
✅ YAML yamllint 9 0 0 0.57s

Detailed Issues

❌ REPOSITORY / osv-scanner - 4 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned package-lock.json file and found 158 packages
End status: 52 dirs visited, 151 inodes visited, 1 Extract calls, 19.97788ms elapsed, 19.97808ms wall time

Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 2 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
4 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE            |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.8         | package-lock.json |
| https://osv.dev/GHSA-724g-mxrg-4qvm | 5.3  | npm       | js-yaml (dev)         | 5.2.0   | 5.2.1         | package-lock.json |
| https://osv.dev/GHSA-pm4m-ph32-ghv5 | 7.5  | npm       | js-yaml (dev)         | 5.2.0   | 5.2.2         | package-lock.json |
| https://osv.dev/GHSA-r292-9mhp-454m | 5.3  | npm       | tar                   | 7.5.19  | 7.5.21        | package-lock.json |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
❌ REPOSITORY / trivy - 1 error
------------------------------------->] 100.00% 78.48 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 78.48 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 73.42 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 73.42 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 73.42 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 68.68 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 68.68 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 68.68 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 64.25 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 64.25 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 64.25 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 60.11 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 60.11 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-------------------------------------------->] 100.00% 60.11 MiB p/s ETA 0s103.21 MiB / 103.21 MiB [-----------------------------------------------] 100.00% 15.97 MiB p/s 6.7s2026-07-31T21:18:20Z	INFO	[vulndb] Artifact successfully downloaded	repo="mirror.gcr.io/aquasec/trivy-db:2"
2026-07-31T21:18:20Z	INFO	[vuln] Vulnerability scanning is enabled
2026-07-31T21:18:20Z	INFO	[misconfig] Misconfiguration scanning is enabled
2026-07-31T21:18:20Z	INFO	[checks-client] Need to update the checks bundle
2026-07-31T21:18:20Z	INFO	[checks-client] Downloading the checks bundle...
234.65 KiB / 234.65 KiB [--------------------------------------------------------->] 100.00% ? p/s ?234.65 KiB / 234.65 KiB [----------------------------------------------] 100.00% 12.94 MiB p/s 200ms2026-07-31T21:18:24Z	INFO	[npm] Run "npm install" to collect the license information of packages	dir="node_modules"
2026-07-31T21:18:24Z	INFO	Suppressing dependencies for development and testing. To display them, try the '--include-dev-deps' flag.
2026-07-31T21:18:24Z	INFO	Number of language-specific files	num=1
2026-07-31T21:18:24Z	INFO	[npm] Detecting vulnerabilities...
2026-07-31T21:18:24Z	INFO	Detected config files	num=0

Report Summary

┌───────────────────┬──────┬─────────────────┬───────────────────┐
│      Target       │ Type │ Vulnerabilities │ Misconfigurations │
├───────────────────┼──────┼─────────────────┼───────────────────┤
│ package-lock.json │ npm  │        1        │         -         │
└───────────────────┴──────┴─────────────────┴───────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.71/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


package-lock.json (npm)
=======================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)

┌─────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────┐
│ Library │    Vulnerability    │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                          │
├─────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────┼────────────────────────────────────────────────────────┤
│ tar     │ GHSA-r292-9mhp-454m │ MEDIUM   │ fixed  │ 7.5.19            │ 7.5.21        │ node-tar: Uncontrolled recursion in mapHas/filesFilter │
│         │                     │          │        │                   │               │ allows uncatchable stack-overflow DoS via crafted      │
│         │                     │          │        │                   │               │ long-path...                                           │
│         │                     │          │        │                   │               │ https://github.com/advisories/GHSA-r292-9mhp-454m      │
└─────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────┴────────────────────────────────────────────────────────┘

📣 Notices:
  - Version 0.72.0 of Trivy is now available, current version is 0.71.2

To suppress version checks, run Trivy scans with the --skip-version-check flag

(Truncated to last 5000 characters out of 7151)
❌ ACTION / zizmor - 22 errors
ub/workflows/mega-linter.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/test.yml
warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/deploy.yml:31:75
   |
31 |       - uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/deploy.yml:34:77
   |
34 |       - uses: actions/setup-node@HIDDEN_BY_MEGALINTER# v6
   |         -----------------------------------------------------------------   ^^ points to commit 249970729cb0
   |         |
   |         is pointed to by tag v6.4.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/deploy.yml:61:75
   |
61 |       - uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/deploy.yml:64:77
   |
64 |       - uses: actions/setup-node@HIDDEN_BY_MEGALINTER# v6
   |         -----------------------------------------------------------------   ^^ points to commit 249970729cb0
   |         |
   |         is pointed to by tag v6.4.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/github-dependents-info.yml:33:75
   |
33 |         uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/mega-linter.yml:27:75
   |
27 |         uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/test.yml:37:75
   |
37 |         uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/test.yml:41:77
   |
41 |         uses: actions/setup-node@HIDDEN_BY_MEGALINTER# v6
   |         -----------------------------------------------------------------   ^^ points to commit 249970729cb0
   |         |
   |         is pointed to by tag v6.4.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

warning[ref-version-mismatch]: action's hash pin has mismatched or missing version comment
  --> .github/workflows/test.yml:69:75
   |
69 |         uses: actions/checkout@HIDDEN_BY_MEGALINTER# v7
   |         ---------------------------------------------------------------   ^^ points to commit 3d3c42e5aac5
   |         |
   |         is pointed to by tag v7.0.0
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#ref-version-mismatch

22 findings (3 ignored, 10 suppressed, 9 unsafe fixes): 0 informational, 0 low, 9 medium, 0 high

(Truncated to last 5000 characters out of 5208)
⚠️ ACTION / actionlint - 2 errors
.github/workflows/github-dependents-info.yml:55:9: shellcheck reported issue in this script: SC2086:info:1:15: Double quote to prevent globbing and word splitting [shellcheck]
   |
55 |         run: sudo chown -R $USER:$USER .
   |         ^~~~
.github/workflows/github-dependents-info.yml:55:9: shellcheck reported issue in this script: SC2086:info:1:21: Double quote to prevent globbing and word splitting [shellcheck]
   |
55 |         run: sudo chown -R $USER:$USER .
   |         ^~~~
⚠️ SPELL / lychee - 4 errors
📝 Summary
---------------------
🔍 Total...........74
🔗 Unique..........62
✅ Successful......23
⏳ Timeouts.........0
🔀 Redirected.......7
👻 Excluded........47
❓ Unknown..........0
🚫 Errors...........4
⛔ Unsupported......4

Errors in README.md
[403] https://npmjs.org/package/java-caller (at 5:1) | Rejected status code: 403 Forbidden | Followed 1 redirect. Redirects: https://npmjs.org/package/java-caller --[301]--> https://www.npmjs.com/package/java-caller
[403] https://npmjs.org/package/java-caller (at 6:1) | Rejected status code: 403 Forbidden | Followed 1 redirect. Redirects: https://npmjs.org/package/java-caller --[301]--> https://www.npmjs.com/package/java-caller
[403] https://www.npmjs.com/package/java-caller (at 4:1) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/njre (at 16:145) | Rejected status code: 403 Forbidden

Hint: Followed 7 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ MARKDOWN / markdown-table-formatter - 1 error
1 files contain markdown tables to format:
- README.md
⚠️ MARKDOWN / markdownlint - 30 errors
.claude/agents/pr-fix.md:9:401 error MD013/line-length Line length [Expected: 400; Actual: 406]
.claude/agents/pr-fix.md:9 error MD041/first-line-heading/first-line-h1 First line in a file should be a top-level heading [Context: "You are the smart fixer for **..."]
.claude/agents/pr-fix.md:11:401 error MD013/line-length Line length [Expected: 400; Actual: 458]
.claude/agents/pr-fix.md:19:401 error MD013/line-length Line length [Expected: 400; Actual: 511]
.claude/agents/pr-fix.md:27:401 error MD013/line-length Line length [Expected: 400; Actual: 712]
.claude/agents/pr-fix.md:44 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
.claude/agents/pr-watch.md:9 error MD041/first-line-heading/first-line-h1 First line in a file should be a top-level heading [Context: "You collect data about a GitHu..."]
.claude/agents/pr-watch.md:65:9 error MD038/no-space-in-code Spaces inside code span elements [Context: "`error  `"]
.claude/agents/pr-watch.md:77 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
.claude/skills/pr-watch-fix/SKILL.md:9 error MD041/first-line-heading/first-line-h1 First line in a file should be a top-level heading [Context: "Watch the open PR for the curr..."]
.claude/skills/pr-watch-fix/SKILL.md:52 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
.claude/skills/pr-watch-fix/SKILL.md:81:401 error MD013/line-length Line length [Expected: 400; Actual: 448]
.claude/skills/pr-watch-fix/SKILL.md:105 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
CODE_OF_CONDUCT.md:58:44 error MD034/no-bare-urls Bare URL used [Context: "nicolas.vuillamy@gmail.com"]
CODE_OF_CONDUCT.md:71:14 error MD034/no-bare-urls Bare URL used [Context: "https://www.contributor-covena..."]
CODE_OF_CONDUCT.md:76:1 error MD034/no-bare-urls Bare URL used [Context: "https://www.contributor-covena..."]
README.md:66:13 error MD060/table-column-style Table column style [Table pipe is missing space to the left for style "compact"]
README.md:66:27 error MD060/table-column-style Table column style [Table pipe is missing space to the left for style "compact"]
README.md:66:37 error MD060/table-column-style Table column style [Table pipe is missing space to the left for style "compact"]
README.md:66:47 error MD060/table-column-style Table column style [Table pipe is missing space to the left for style "compact"]
README.md:66:1 error MD060/table-column-style Table column style [Table pipe is missing space to the right for style "compact"]
README.md:66:13 error MD060/table-column-style Table column style [Table pipe is missing space to the right for style "compact"]
README.md:66:27 error MD060/table-column-style Table column style [Table pipe is missing space to the right for style "compact"]
README.md:66:37 error MD060/table-column-style Table column style [Table pipe is missing space to the right for style "compact"]
README.md:67:361 error MD055/table-pipe-style Table pipe style [Expected: leading_and_trailing; Actual: leading_only; Missing trailing pipe]
README.md:69:123 error MD060/table-column-style Table column style [Table pipe has extra space to the left for style "compact"]
README.md:73:315 error MD055/table-pipe-style Table pipe style [Expected: leading_and_trailing; Actual: leading_only; Missing trailing pipe]
README.md:74:310 error MD055/table-pipe-style Table pipe style [Expected: leading_and_trailing; Actual: leading_only; Missing trailing pipe]
README.md:75:208 error MD055/table-pipe-style Table pipe style [Expected: leading_and_trailing; Actual: leading_only; Missing trailing pipe]
README.md:76:233 error MD055/table-pipe-style Table pipe style [Expected: leading_and_trailing; Actual: leading_only; Missing trailing pipe]
⚠️ TYPESCRIPT / ts-standard - 1 error
Unable to locate the project file. A project file (tsconfig.json or tsconfig.eslint.json) is required in order to use ts-standard.

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,COPYPASTE_JSCPD,JAVASCRIPT_ES,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_CSPELL,SPELL_LYCHEE,TYPESCRIPT_ES,TYPESCRIPT_STANDARD,TYPESCRIPT_PRETTIER,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@renovate renovate Bot changed the title Update actions/setup-java digest to 0f481fc Update actions/setup-java digest to 03ad4de Jul 16, 2026
@renovate
renovate Bot force-pushed the renovate/actions-setup-java-digest branch from b85f7e2 to b7a8f06 Compare July 16, 2026 19:41
@renovate renovate Bot changed the title Update actions/setup-java digest to 03ad4de Update actions/setup-java digest to b6effb0 Jul 31, 2026
@renovate
renovate Bot force-pushed the renovate/actions-setup-java-digest branch from b7a8f06 to 4dfff80 Compare July 31, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants