Skip to content

chore(deps): Update GitHub Actions#101

Open
williaby wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

chore(deps): Update GitHub Actions#101
williaby wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@williaby

@williaby williaby commented Jun 28, 2026

Copy link
Copy Markdown
Collaborator

Summary

Why

Scheduled patch update, bug fixes and security patches with no API changes.

Changes

This PR contains the following updates:

Package Type Update Change OpenSSF
actions/attest-build-provenance action patch v4.1.0v4.1.1 OpenSSF Scorecard
release-drafter/release-drafter action minor v7.4.0v7.5.1 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

Impact

  • ✅ Patch update: bug fixes and security patches only
  • ✅ No breaking changes

Acceptance Criteria

  • All CI checks pass

Testing

  • CI gates pass (tests, lint, type checking, security scan)

Notes


Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v4.1.1

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.0...v4.1.1

release-drafter/release-drafter (release-drafter/release-drafter)

v7.5.1

Compare Source

What's Changed

Bug Fixes

Full Changelog: release-drafter/release-drafter@v7.5.0...v7.5.1

v7.5.0

Compare Source

What's Changed

New

Bug Fixes

Dependency Updates

Full Changelog: release-drafter/release-drafter@v7.4.0...v7.5.0


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "after 10pm every weekday,before 5am every weekday,every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@coderabbitai

coderabbitai Bot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The release-drafter/release-drafter GitHub Action in the release draft workflow is updated from the v7.4.0 commit pin to the v7.5.0 commit pin.

Changes

Release Drafter Action Bump

Layer / File(s) Summary
release-drafter action pin update
.github/workflows/release-drafter.yml
Bumps the pinned release-drafter/release-drafter action from v7.4.0 to v7.5.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested labels

ci

🐇 A tiny hop, a version leap,
The drafter wakes from its v7.4 sleep.
Now pinned at five, the releases flow,
One line changed — watch the changelogs grow!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is broadly related to the dependency update, though it doesn’t mention the specific GitHub Action changed.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/github-actions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot added the ci label Jun 28, 2026
@williaby williaby added this pull request to the merge queue Jun 28, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Jun 28, 2026
@williaby williaby force-pushed the renovate/github-actions branch from d6e9b13 to 4e8e18e Compare June 28, 2026 17:08
@williaby williaby added this pull request to the merge queue Jun 28, 2026
@williaby williaby changed the title chore(deps): Update GitHub Actions to v7.5.0 chore(deps): Update GitHub Actions to v7.5.1 Jun 28, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Jun 28, 2026
@williaby williaby enabled auto-merge June 29, 2026 17:55
@williaby williaby force-pushed the renovate/github-actions branch from 4e8e18e to 37f5dc5 Compare June 29, 2026 17:55
@williaby williaby changed the title chore(deps): Update GitHub Actions to v7.5.1 chore(deps): Update GitHub Actions Jun 29, 2026
@williaby williaby added this pull request to the merge queue Jun 29, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant