Skip to content

ci: bump the actions group across 1 directory with 11 updates - #107

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-d96068e50a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-d96068e50a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on actions/checkout, dtolnay/rust-toolchain, Swatinem/rust-cache, actions/upload-artifact, taiki-e/install-action, EmbarkStudios/cargo-deny-action, codecov/codecov-action, actions/attest, release-plz/action, github/codeql-action/init and github/codeql-action/analyze to permit the latest version.
Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dtolnay/rust-toolchain to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

Commits

Updates Swatinem/rust-cache from e18b497796c12c097a38f9edb9d0641fb99eee32 to f0d9c3887740aee45f6153b24b3a6b815192ec16

Changelog

Sourced from Swatinem/rust-cache's changelog.

Changelog

2.9.2

  • Fix credentials.toml cleanup
  • Improvements to cleanup, preserving more valid targets
  • Improvements to cargo install handling
  • Correctly sort/dedupe Rust versions

2.9.1

  • Fix regression in hash calculation

2.9.0

  • Update to node24
  • Support running from within a nix shell
  • Consider all installed toolchains for cache key
  • Use case-insensitive comparison to determine exact cache hit

2.8.2

  • Don't overwrite env for cargo-metadata call

2.8.1

  • Set empty CARGO_ENCODED_RUSTFLAGS when retrieving metadata
  • Various dependency updates

2.8.0

  • Add support for warpbuild cache provider
  • Add new cache-workspace-crates feature

2.7.8

  • Include CPU arch in the cache key

2.7.7

  • Also cache cargo install metadata

2.7.6

  • Allow opting out of caching $CARGO_HOME/bin
  • Add runner OS in cache key
  • Adds an option to do lookup-only of the cache

2.7.5

... (truncated)

Commits
  • f0d9c38 Merge pull request #380 from Swatinem/dependabot/github_actions/actions-8ff58...
  • ccd9742 Bump the actions group with 2 updates
  • 258712b fix: stop cleanup timestamp pruning after the first entry (#377)
  • a45951f Merge pull request #373 from Swatinem/dependabot/github_actions/actions-420be...
  • b882611 Bump the actions group with 2 updates
  • 6323deb 2.9.2
  • b16e8d7 bump rollup and rebuild
  • 3bf42ac invert target/profile check in cleanup
  • 6e5b278 correctly sort and dedupe Rust versions
  • 5adc05f Bump the actions group across 1 directory with 3 updates (#368)
  • Additional commits viewable in compare view

Updates actions/upload-artifact from 4.6.2 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Updates taiki-e/install-action from 2.83.1 to 2.87.15

Release notes

Sourced from taiki-e/install-action's releases.

2.87.15

  • Update syft@latest to 1.52.0.

  • Update mise@latest to 2026.9.10.

  • Update kingfisher@latest to 2.4.0.

  • Update kache@latest to 0.23.1.

  • Update coreutils@latest to 0.12.0.

  • Update cargo-nextest@latest to 0.9.145.

2.87.14

  • Update vacuum@latest to 0.30.6.

  • Update uv@latest to 0.12.15.

  • Update typos@latest to 1.50.2.

  • Update sccache@latest to 0.18.0.

  • Update oxfmt@latest to 1.83.0.

  • Update mise@latest to 2026.9.9.

  • Update kingfisher@latest to 2.3.0.

  • Update kache@latest to 0.22.0.

  • Update biome@latest to 2.5.14.

2.87.13

  • Update zola@latest to 0.23.6.

  • Update vacuum@latest to 0.30.5.

  • Update tombi@latest to 1.5.5.

  • Update release-plz@latest to 0.3.167.

  • Update protoc-gen-connect-openapi@latest to 0.27.2.

  • Update prek@latest to 0.5.3.

  • Update osv-scanner@latest to 2.6.0.

  • Update mise@latest to 2026.9.7.

  • Update kache@latest to 0.21.0.

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.87.20] - 2026-09-24

  • Update uv@latest to 0.12.18.

  • Update cargo-shear@latest to 1.14.0.

[2.87.19] - 2026-09-23

  • Update wasmtime@latest to 49.0.0.

  • Update cargo-shear@latest to 1.13.5.

  • Update cargo-nextest@latest to 0.9.146.

[2.87.18] - 2026-09-22

  • Update oxfmt@latest to 1.84.0.

  • Update mise@latest to 2026.9.12.

  • Update kache@latest to 0.26.3.

  • Update cargo-tarpaulin@latest to 0.37.4.

  • Update cargo-rdme@latest to 2.2.3.

[2.87.17] - 2026-09-20

  • Update uv@latest to 0.12.17.

  • Update release-plz@latest to 0.3.169.

  • Update kingfisher@latest to 2.5.0.

  • Update kache@latest to 0.25.0.

  • Update git-cliff@latest to 2.14.2.

... (truncated)

Commits

Updates EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1

Release notes

Sourced from EmbarkStudios/cargo-deny-action's releases.

Release 2.1.1 - cargo-deny 0.20.2

Fixed

  • PR#116 fixed in issue introduced in the 2.1.0 release due the deprecation of the use-git-cli argument. Thanks @​Firestar99!

Release 2.1.0 - cargo-deny 0.20.2

Changed

  • PR#881 refactored the CLI, moving some duplicated options/flags into the root and removing several deprecated options/flags/values. See the PR for a full list of changes.

Added

  • PR#879 resolved #873 by adding a new bans.std-replacements lint which checks the graph for crates.io sourced crates that have been partially or fully replaced in std and/or core.

Fixed

  • PR#880 resolved #765 by respecting non-default build script paths in manifests.
  • PR#881 resolved #874 by cleaning up the CLI, deduplicating some options/flags that caused bug in the list subcommand.
Commits

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Updates actions/attest from 4.1.1 to 4.2.2

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

v4.2.1

What's Changed

Full Changelog: actions/attest@v4.2.0...v4.2.1

v4.2.0

What's Changed

Full Changelog: actions/attest@v4.1.1...v4.2.0

Commits
  • 1e69f48 Bump ip-address from 10.2.0 to 10.4.0 (#467)
  • 02787ce Bump brace-expansion (#468)
  • 98ac037 bump @​sigstore/oci from 0.7.1 to 0.7.2 (#469)
  • 508db95 fix: strip OCI image tag when pushing attestation to registry (#464)
  • dda48f2 Bump the npm-development group across 1 directory with 6 updates (#461)
  • 7d789a3 Bump the actions-minor group with 3 updates (#463)
  • 1f3ca2f Add release-cutter canvas extension (#454)
  • d215549 Bump tar from 7.5.17 to 7.5.21 (#459)
  • 20c90ed Bump the npm-development group with 2 updates (#455)
  • 43c2c81 Bump the actions-minor group with 4 updates (#456)
  • Additional commits viewable in compare view

Updates release-plz/action from 0.5.130 to 0.5.138

Release notes

Sourced from release-plz/action's releases.

v0.5.138

What's Changed

Full Changelog: release-plz/action@v0.5.137...v0.5.138

v0.5.137

What's Changed

New Contributors

Full Changelog: release-plz/action@v0.5.136...v0.5.137

v0.5.136

What's Changed

Full Changelog: release-plz/action@v0.5.135...v0.5.136

v0.5.135

What's Changed

Full Changelog: release-plz/action@v0.5.134...v0.5.135

v0.5.134

What's Changed

Full Changelog: release-plz/action@v0.5.133...v0.5.134

v0.5.133

What's Changed

... (truncated)

Commits
  • d6c5627 Update to 0.3.168 (#535)
  • 3acb31e chore(deps): update dependency taiki-e/install-action to v2.87.13 (#534)
  • f77cdb1 chore(deps): lock file maintenance (#532)
  • 8e61445 Update to 0.3.167 (#531)
  • c9cf542 chore(deps): update dependency taiki-e/install-action to v2.87.12 (#530)
  • c4d7bf6 fix: support Gitea runners without GitHub identity lookup (#528)
  • 825b14a chore(deps): update dependency taiki-e/install-action to v2.87.11 (#529)
  • 4745e52 chore(deps): update dependency taiki-e/install-action to v2.87.10 (#526)
  • a80d79e Update to 0.3.165 (#525)
  • 346832d Update to 0.3.164 (#523)
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.37.0 to 4.38.1

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

v4.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

v4.37.9

  • Update default CodeQL bundle version to 2.26.4. #4106

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.37.0 to 4.38.1

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

v4.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

v4.37.9

  • Update default CodeQL bundle version to 2.26.4. #4106

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from RetriggerConfidence Score: 5/5

No blocking issue was established; this review does not identify a reason to prevent merging.

What we checked:

  • Ran the repository’s cargo-deny workflow using both the previous and updated action entrypoints with each release’s cargo-deny binary, and both runs reached all four checks with identical advisory failures and no command or configuration compatibility differences. T-Rex
  • Ran the fuzz artifact action bundles against identical missing-directory and crash-file fixtures; both runs found the crash file and handled the missing directory the same way, and the manifest retained relevant inputs and defaults, though an actual upload requires a GitHub Actions runtime token. T-Rex
  • At ci.yml:164-166, both runs reached all four checks, each reporting advisories FAILED, bans ok, licenses ok, sources ok, and an entrypoint exit code of 1, with no command-parsing or deny.toml compatibility errors. T-Rex
  • The upstream v7.0.1 manifest confirms the pin, unchanged relevant inputs, and node24 runtime; its archive input defaults to true, so the new direct-upload behavior does not override the configured artifact name, and upstream specifies runner 2.327.1+ for Node 24, though this job used ubuntu-latest and hosted-runner execution was not reproduced. T-Rex

Summary

The PR updates pinned GitHub Actions revisions across six workflows without changing their inputs or job structure. Checks of the cargo-deny step and fuzz artifact handling found no regression attributable to these updates.

Reviews (1) · Last reviewed commit: "ci: bump the actions group across 1 dire..."

Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [Swatinem/rust-cache](https://github.com/swatinem/rust-cache), [actions/upload-artifact](https://github.com/actions/upload-artifact), [taiki-e/install-action](https://github.com/taiki-e/install-action), [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action), [codecov/codecov-action](https://github.com/codecov/codecov-action), [actions/attest](https://github.com/actions/attest), [release-plz/action](https://github.com/release-plz/action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action) to permit the latest version.

Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `dtolnay/rust-toolchain` to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de
- [Release notes](https://github.com/dtolnay/rust-toolchain/releases)
- [Commits](https://github.com/dtolnay/rust-toolchain/commits/02cb101ec7c40f2c49e1d9714d64511d8e1b74de)

Updates `Swatinem/rust-cache` from e18b497796c12c097a38f9edb9d0641fb99eee32 to f0d9c3887740aee45f6153b24b3a6b815192ec16
- [Release notes](https://github.com/swatinem/rust-cache/releases)
- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md)
- [Commits](Swatinem/rust-cache@e18b497...f0d9c38)

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...043fb46)

Updates `taiki-e/install-action` from 2.83.1 to 2.87.15
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@2ca9b94...4076c08)

Updates `EmbarkStudios/cargo-deny-action` from 2.0.20 to 2.1.1
- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)
- [Commits](EmbarkStudios/cargo-deny-action@bb137d7...3c63498)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@fb8b358...303a32d)

Updates `actions/attest` from 4.1.1 to 4.2.2
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@a1948c3...1e69f48)

Updates `release-plz/action` from 0.5.130 to 0.5.138
- [Release notes](https://github.com/release-plz/action/releases)
- [Commits](release-plz/action@e879257...d6c5627)

Updates `github/codeql-action/init` from 4.37.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...1c5b675)

Updates `github/codeql-action/analyze` from 4.37.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...1c5b675)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: dtolnay/rust-toolchain
  dependency-version: 02cb101ec7c40f2c49e1d9714d64511d8e1b74de
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: Swatinem/rust-cache
  dependency-version: f0d9c3887740aee45f6153b24b3a6b815192ec16
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: taiki-e/install-action
  dependency-version: 2.87.15
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: EmbarkStudios/cargo-deny-action
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: release-plz/action
  dependency-version: 0.5.138
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner September 25, 2026 13:17
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a5fb7c41-1fe2-478f-bc33-4a971a1793c4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

benchmark baseline ns current ns delta
grams_index_sparse 2121463 2811713 +32.5%
grams_index_trigram 57716 99989 +73.2%
grams_query_sparse 862 1085 +25.9%
grams_query_trigram 288 315 +9.2%
index_build_1024x4096_sparse 297826732 176328446 -40.8%
index_build_1024x4096_trigram 23021729 32500801 +41.2%
local_blob_store_segmented_reader_candidate_docs 6517 8363 +28.3%
packed_sort_control_1024 6639 8090 +21.9%
packed_sort_control_128 622 742 +19.3%
packed_sort_control_256 1312 1629 +24.1%
packed_sort_control_4096 30937 37207 +20.3%
packed_sort_control_512 3022 3670 +21.4%
packed_sort_control_65536 745618 907945 +21.8%
packed_sort_hybrid_1024 4201 4933 +17.4%
packed_sort_hybrid_128 633 708 +11.8%
packed_sort_hybrid_256 1314 1556 +18.4%
packed_sort_hybrid_4096 15930 18746 +17.7%
packed_sort_hybrid_512 2270 2701 +19.0%
packed_sort_hybrid_65536 274183 548630 +100.1%
plan_(timeout_panicked_denied) 9302 12804 +37.6%
plan_._ 400 512 +27.9%
plan_ERROR42 1505 1882 +25.1%
plan__CRITICAL_ 3486 4464 +28.0%
plan_customer_id=abc123 request_id=deadbeef 8530 11727 +37.5%
paired benchmark hybrid/control limit
packed sort 128 0.954x 1.150x
packed sort 256 0.956x 1.150x
packed sort 512 0.736x 1.150x
packed sort 1024 0.610x 1.150x
packed sort 4096 0.504x 1.150x
packed sort 65536 0.604x 1.150x
benchmark vs PR base median delta 95% CI limit
grams_index_sparse -2.8% -2.9% to -2.8% +20%
grams_index_trigram +0.7% +0.6% to +0.7% +20%
grams_query_sparse +0.2% +0.1% to +0.3% +30%
grams_query_trigram -2.0% -2.1% to -1.9% +20%
index_build_1024x4096_sparse -0.2% -0.6% to +0.1% +20%
index_build_1024x4096_trigram +0.9% +0.1% to +2.6% +20%
local_blob_store_segmented_reader_candidate_docs -0.2% -0.3% to -0.2% +20%
packed_sort_control_1024 +4.0% +3.9% to +4.1% paired
packed_sort_control_128 +4.6% +4.4% to +4.9% paired
packed_sort_control_256 +4.1% +3.9% to +4.2% paired
packed_sort_control_4096 +3.2% +3.1% to +3.3% paired
packed_sort_control_512 +4.7% +4.6% to +4.8% paired
packed_sort_control_65536 +0.1% +0.0% to +0.3% paired
packed_sort_hybrid_1024 -4.0% -4.3% to -3.8% paired
packed_sort_hybrid_128 -4.7% -4.9% to -4.6% paired
packed_sort_hybrid_256 -5.4% -5.6% to -5.3% paired
packed_sort_hybrid_4096 -5.9% -6.1% to -5.7% paired
packed_sort_hybrid_512 -3.5% -3.7% to -3.3% paired
packed_sort_hybrid_65536 -1.8% -3.4% to -0.7% paired
plan_(timeout_panicked_denied) +0.4% +0.3% to +0.6% +20%
plan_._ -2.3% -2.4% to -2.2% +20%
plan_ERROR42 +0.0% -0.2% to +0.2% +20%
plan__CRITICAL_ +1.4% +1.3% to +1.5% +20%
plan_customer_id=abc123 request_id=deadbeef -2.2% -2.3% to -2.1% +20%

e2e S3

e2e did not produce a table

scale

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
short_literal 12500 12500/25000 0.500 51200000 166.836 166.836 166.836 129.108
long_literal 8334 8334/25000 0.333 34136064 125.838 125.838 125.838 136.417
alternation 7857 7857/25000 0.314 32182272 129.302 129.302 129.302 130.990
anchored 2273 2273/25000 0.091 9310208 111.200 111.200 111.200 110.519
no_match 0 0/25000 0.000 0 0.047 0.047 0.047 0.007
QAll 25000 25000/25000 1.000 102400000 166.130 166.130 166.130 163.704
dot_star_gap 2500 2500/25000 0.100 10240000 116.406 116.406 116.406 117.431

prose

prose corpus, trigram

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 998/1000 0.998 65407598 105.195 105.195 105.195 81.813
unplanted_phrase 0 996/1000 0.996 65276525 81.777 81.777 81.777 100.857
rare_word 4 4/1000 0.004 262155 1.147 1.147 1.147 1.062
common_word 1000 1000/1000 1.000 65538679 96.992 96.992 96.992 81.124

prose corpus, sparse

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 20/1000 0.020 1310768 18.134 18.134 18.134 15.884
unplanted_phrase 0 0/1000 0.000 0 5.433 5.433 5.433 5.171
rare_word 4 4/1000 0.004 262155 3.045 3.045 3.045 2.590
common_word 1000 1000/1000 1.000 65538679 99.094 99.094 99.094 73.706

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants