Repository navigation
Bump the github-actions group across 1 directory with 8 updates - #28
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.2` | `3.0.3` | | [actions/setup-java](https://github.com/actions/setup-java) | `6.0.0` | `6.0.1` | | [gradle/actions/setup-gradle](https://github.com/gradle/actions) | `6.3.0` | `6.4.0` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.0.1` | `10.2.0` | | [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.321.0` | `1.327.0` | | [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain) | `02cb101ec7c40f2c49e1d9714d64511d8e1b74de` | `7e38f4b43b4db5c8dd498af069a4f6196df1d067` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.87.9` | `2.87.22` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.6.2` | `0.6.4` | Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@3d0d988...efb3536) Updates `actions/setup-java` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@dd06d9c...de7274f) Updates `gradle/actions/setup-gradle` from 6.3.0 to 6.4.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@9c97196...3f5f9ad) Updates `astral-sh/setup-uv` from 10.0.1 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@20cfd1b...c18668a) Updates `ruby/setup-ruby` from 1.321.0 to 1.327.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](ruby/setup-ruby@95ef2b0...1459426) Updates `dtolnay/rust-toolchain` from 02cb101ec7c40f2c49e1d9714d64511d8e1b74de to 7e38f4b43b4db5c8dd498af069a4f6196df1d067 - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](dtolnay/rust-toolchain@02cb101...7e38f4b) Updates `taiki-e/install-action` from 2.87.9 to 2.87.22 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@c3ec0de...83ac0ad) Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@3dc1ecc...cc914d7) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: gradle/actions/setup-gradle dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ruby/setup-ruby dependency-version: 1.327.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dtolnay/rust-toolchain dependency-version: 7e38f4b43b4db5c8dd498af069a4f6196df1d067 dependency-type: direct:production dependency-group: github-actions - dependency-name: taiki-e/install-action dependency-version: 2.87.22 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approved
All action references are consistently updated to valid full commit pins with matching version annotations.
Review effort: Balanced
Findings: None
What changed in this PR
Updates eight pinned GitHub Actions dependencies across CI and release workflows.
Changes:
- Updates language toolchain and package installer actions.
- Updates release and security-analysis actions.
- Preserves immutable full-SHA pinning.
[!TIP]
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or rungh pr ready --undo.
Click "Ready for review" or rungh pr readyto reengage.
| File | Description |
|---|---|
.github/workflows/test.yml |
Updates eight CI action references. |
.github/workflows/release-rust.yml |
Updates Rust setup and installer actions. |
.github/workflows/release-ruby.yml |
Updates Ruby setup actions. |
.github/workflows/release-python.yml |
Updates uv setup actions. |
.github/workflows/release-kotlin.yml |
Updates Java and Gradle setup actions. |
.github/workflows/release-github.yml |
Updates the GitHub release action. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 8 updates in the / directory:
3.0.23.0.36.0.06.0.16.3.06.4.010.0.110.2.01.321.01.327.002cb101ec7c40f2c49e1d9714d64511d8e1b74de7e38f4b43b4db5c8dd498af069a4f6196df1d0672.87.92.87.220.6.20.6.4Updates
softprops/action-gh-releasefrom 3.0.2 to 3.0.3Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
efb3536release 3.0.3 (#840)6441963chore(deps): bump the npm group with 2 updates (#839)e5ee6bcchore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)d1e6617chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)6403751chore(deps): bump the npm group with 2 updates (#835)7c7184bchore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)0f3f0d2chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)77fb938chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)5a6f517chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)a3c91c9chore(deps): bump the github-actions group with 2 updates (#825)Updates
actions/setup-javafrom 6.0.0 to 6.0.1Release notes
Sourced from actions/setup-java's releases.
Commits
de7274fAvoid macOS GPG socket overflow on long runner paths (#1266)134912aFix import-safe checks when scripts are run from a path with symlinks (#1265)0781fc6Fix alpine failures by switching default back to only warn on verification fa...4889c4aFix Temurin EA E2E signature verification (#1260)8fd3240[WIP] Fix failing GitHub Actions job for temurin 17 (#1259)2732291chore(deps-dev): update eslint and globals (#1256)1a8f22bchore: streamline Dependabot updates (#1255)85030b7docs: complete v6 release highlights (#1254)Updates
gradle/actions/setup-gradlefrom 6.3.0 to 6.4.0Release notes
Sourced from gradle/actions/setup-gradle's releases.
... (truncated)
Commits
3f5f9adDocument the new Gradle signing key for dependency verification (#1071)b031f6d[bot] Update dist directory5bc4175Bump dependency-graph-gradle-plugin to 1.5.0 (#1069)f3ff59bCombined automated updates: wrapper checksums, npm dependencies, setup-java (...7927085Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 (#1068)c3897a4[bot] Update dist directory6b92be1Update dependencies (#1065)0d208da[bot] Update dist directorye49d0a3Report EOL and maintenance status for Gradle versions (#1057)575435bUse the root-qualified:wrappertask (#1064)Updates
astral-sh/setup-uvfrom 10.0.1 to 10.2.0Release notes
Sourced from astral-sh/setup-uv's releases.
... (truncated)
Commits
c18668achore(deps): roll up Dependabot updates (#1059)ffe1476chore: update known checksums for 0.12.17 (#1058)f5548c5chore: update known checksums for 0.12.16 (#1057)a761a4eDisable automatic cache saves for merge queues (#1056)3377a30chore: update known checksums for 0.12.15 (#1054)dfb5f38chore: update known checksums for 0.12.14 (#1053)45c121fchore: update known checksums for 0.12.13 (#1045)8073452docs: update version references to v10.1.0 (#1044)bec219dchore(deps-dev): roll up Dependabot updates (#1043)b90ec40fix: respect no proxy directive (#1037)Updates
ruby/setup-rubyfrom 1.321.0 to 1.327.0Release notes
Sourced from ruby/setup-ruby's releases.
Commits
1459426Update CRuby releases on Windows762794cAdd ruby-3.4.11e8944e8Add jruby-10.0.7.0,jruby-10.1.2.0a0102e0Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0984c0c8Update CRuby releases on Windowsbec3f19Add ruby-4.0.7Updates
dtolnay/rust-toolchainfrom 02cb101ec7c40f2c49e1d9714d64511d8e1b74de to 7e38f4b43b4db5c8dd498af069a4f6196df1d067Commits
7e38f4bMerge pull request #186 from WaterWhisperer/feat/retry-install7645b07Retry release-server checksum failuresUpdates
taiki-e/install-actionfrom 2.87.9 to 2.87.22Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
83ac0adRelease 2.87.2233ae788Updatekache@latestto 0.28.0fe1dc90Update uv manifestab1690bUpdatetypos@latestto 1.50.3e8f3088Updatetombi@latestto 1.5.85016a80Updateprek@latestto 0.5.471fcea0Updatemise@latestto 2026.9.16194a943Updatekache@latestto 0.27.0a681fbeUpdategungraun-runner@latestto 0.20.08422291Updatecargo-tarpaulin@latestto 0.37.5Updates
zizmorcore/zizmor-actionfrom 0.6.2 to 0.6.4Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
cc914d7Sync zizmor versions (#166)bae72b7chore(deps): bump the github-actions group with 2 updates (#165)27604f9chore(deps): bump the github-actions group with 2 updates (#164)c41d665README: bump pins (#163)70fb788Sync zizmor versions (#162)7999d8cchore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...2ae1ce9chore(deps): bump github/codeql-action/upload-sarif (#160)951a5eeSkip prerelease versions in sync-zizmor-versions workflow (#158)79f0191chore(deps): bump github/codeql-action/upload-sarif (#156)26a3ae6sync-zizmor-versions: retry up to 5 times (#155)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions