Repository navigation
ci: bump the actions group across 1 directory with 9 updates - #92
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
seagrep benchmarksmicro
e2e S3
scale
proseprose corpus, trigram
prose corpus, sparse
|
Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [actions/upload-artifact](https://github.com/actions/upload-artifact), [taiki-e/install-action](https://github.com/taiki-e/install-action), [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action), [actions/attest](https://github.com/actions/attest), [release-plz/action](https://github.com/release-plz/action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action) to permit the latest version. Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@9c091bb...3d3c42e) Updates `dtolnay/rust-toolchain` to 2c7215f132e9ebf062739d9130488b56d53c060c - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](https://github.com/dtolnay/rust-toolchain/commits/2c7215f132e9ebf062739d9130488b56d53c060c) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4.6.2...043fb46) Updates `taiki-e/install-action` from 2.83.1 to 2.85.0 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@2ca9b94...7572810) Updates `EmbarkStudios/cargo-deny-action` from 2.0.20 to 2.1.1 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@bb137d7...3c63498) Updates `actions/attest` from 4.1.1 to 4.2.0 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@a1948c3...f7c74d2) Updates `release-plz/action` from 0.5.130 to 0.5.131 - [Release notes](https://github.com/release-plz/action/releases) - [Commits](release-plz/action@e879257...2eb1d8b) Updates `github/codeql-action/init` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: dtolnay/rust-toolchain dependency-version: 2c7215f132e9ebf062739d9130488b56d53c060c dependency-type: direct:production dependency-group: actions - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/init dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: release-plz/action dependency-version: 0.5.131 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: taiki-e/install-action dependency-version: 2.83.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions-f89e2d92cd
branch
from
July 31, 2026 13:18
b6083ea to
f1858d4
Compare
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/github_actions/actions-f89e2d92cd
branch
August 14, 2026 13:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on actions/checkout, dtolnay/rust-toolchain, actions/upload-artifact, taiki-e/install-action, EmbarkStudios/cargo-deny-action, actions/attest, release-plz/action, github/codeql-action/init and github/codeql-action/analyze to permit the latest version.
Updates
actions/checkoutfrom 7.0.0 to 7.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
dtolnay/rust-toolchainto 2c7215f132e9ebf062739d9130488b56d53c060cCommits
Updates
actions/upload-artifactfrom 4.6.2 to 7.0.1Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEUpdates
taiki-e/install-actionfrom 2.83.1 to 2.85.0Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
7572810Release 2.85.0d73fed9Update changelog20d0440Support bpf-linker (#1950)05a01b6Update vacuum manifest23a3cceUpdatecargo-neat@latestto 0.5.154ede98Support rafn (#1935)411aa4bSupport wild (#1949)4427ee3Updatezizmor@latestto 1.28.068a5a96Updatewasmtime@latestto 47.0.2f276a80Updateuv@latestto 0.11.31Updates
EmbarkStudios/cargo-deny-actionfrom 2.0.20 to 2.1.1Commits
3c63498Fix use-git-cli deprecation (#116)6f99e34Bump to 0.20.28b229e2Deprecate use-git-cliUpdates
actions/attestfrom 4.1.1 to 4.2.0Release notes
Sourced from actions/attest's releases.
Commits
f7c74d2feat: support SHA-2 subject digests (#446)88633d1Bump js-yaml from 4.2.0 to 5.2.1 (#452)5dff824Bump the actions-minor group with 3 updates (#453)e67e539Bump the npm-development group across 1 directory with 2 updates (#448)95f6155Bump@types/nodefrom 25.9.2 to 26.1.1 (#449)b644c72Read subjects from GITHUB_ARTIFACTS_LIST (#447)7d3af28Bump csv-parse from 6.2.1 to 7.0.1 (#437)52cbb4dBump@actions/globfrom 0.6.1 to 0.7.0 in the npm-production group across 1 d...a5ce33eci: download rebuilt dist/ artifact outside the checkout workspace (#445)4c65731ci: auto-rebuild dist/ for Dependabot production bumps (#444)Updates
release-plz/actionfrom 0.5.130 to 0.5.131Release notes
Sourced from release-plz/action's releases.
Commits
2eb1d8bUpdate to 0.3.160 (#466)bbdaa2cchore(deps): lock file maintenance (#465)77006e7chore(deps): update dependency taiki-e/install-action to v2.83.2 (#464)4671811chore(deps): update dependency taiki-e/install-action to v2.83.1 (#463)5825e6achore(deps): update dependency taiki-e/install-action to v2.83.0 (#462)9627bb5chore(deps): update dependency taiki-e/install-action to v2.82.11 (#461)b291097chore(deps): update dependency taiki-e/install-action to v2.82.10 (#460)3e68b2cchore(deps): lock file maintenance (#459)6ce0a80chore(deps): update dependency taiki-e/install-action to v2.82.9 (#457)1ff444bchore(deps): update dependency taiki-e/install-action to v2.82.8 (#456)Updates
github/codeql-action/initfrom 4.37.0 to 4.37.3Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
e4fba86Merge pull request #4031 from github/update-v4.37.3-72f6a9da0fb50ab5Update changelog for v4.37.372f6a9dMerge pull request #4030 from github/mbg/fix/no-proxy3b5ee58Use defaultrequestoptions instead ofundefinedbfb6be4Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621526ab84Rebuildd6217b9Update changelog and version after v4.37.2e064762Merge pull request #4027 from github/update-v4.37.2-385bcdc5ae0faed8Add a couple of change notes73aad0eUpdate changelog for v4.37.2Updates
github/codeql-action/analyzefrom 4.37.0 to 4.37.3Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
e4fba86Merge pull request #4031 from github/update-v4.37.3-72f6a9da0fb50ab5Update changelog for v4.37.372f6a9dMerge pull request #4030 from github/mbg/fix/no-proxy3b5ee58Use defaultrequestoptions instead ofundefinedbfb6be4Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621526ab84Rebuildd6217b9Update changelog and version after v4.37.2e064762Merge pull request #4027 from github/update-v4.37.2-385bcdc5ae0faed8Add a couple of change notes73aad0eUpdate changelog for v4.37.2Note
Low Risk
CI-only dependency pin updates with no application logic changes; main caveat is upload-artifact v4→v7 on fuzz failure uploads, which is a major version bump but limited to artifact upload on failure.
Overview
Bumps pinned commit SHAs for third-party GitHub Actions in
.github/workflows/*only—no Rust or product code changes.actions/checkoutmoves to v7.0.1 everywhere it appears (bench, CI, fuzz, release, security).taiki-e/install-actionis updated in CI (nextest, typos/zizmor, llvm-cov).EmbarkStudios/cargo-deny-action,release-plz/action,github/codeql-actioninit/analyze,actions/attest(release assets), andactions/upload-artifact(fuzz crash uploads; bench already on the new upload-artifact pin in context) get new SHAs.dtolnay/rust-toolchainis aligned to a single newermastercommit in fuzz (other workflows were already on that pin).Workflow structure, job matrices, and step commands are unchanged; only
uses:references move to newer action versions.Reviewed by Cursor Bugbot for commit f1858d4. Bugbot is set up for automated code reviews on this repo. Configure here.
Greptile Summary
Updates full-SHA-pinned GitHub Actions dependencies across six CI workflows.
Confidence Score: 5/5
The PR appears safe to merge.
No blocking failures remain.
Files Needing Attention: No files need attention.
What T-Rex did
Important Files Changed
Reviews (2): Last reviewed commit: "ci: bump the actions group across 1 dire..." | Re-trigger Greptile