Skip to content

ci: bump the actions group across 1 directory with 9 updates - #92

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-f89e2d92cd
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-f89e2d92cd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on actions/checkout, dtolnay/rust-toolchain, actions/upload-artifact, taiki-e/install-action, EmbarkStudios/cargo-deny-action, actions/attest, release-plz/action, github/codeql-action/init and github/codeql-action/analyze to permit the latest version.
Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dtolnay/rust-toolchain to 2c7215f132e9ebf062739d9130488b56d53c060c

Commits

Updates actions/upload-artifact from 4.6.2 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Updates taiki-e/install-action from 2.83.1 to 2.85.0

Release notes

Sourced from taiki-e/install-action's releases.

2.85.0

  • Support wild (alias: wild-linker). (#1949)

  • Support bpf-linker. (#1950)

  • Support rafn. (#1935, thanks @​DarkWanderer)

  • Update cargo-neat@latest to 0.5.1.

  • Update zizmor@latest to 1.28.0.

  • Update wasmtime@latest to 47.0.2.

  • Update uv@latest to 0.11.31.

  • Update syft@latest to 1.49.0.

2.84.1

  • Update wasmtime@latest to 47.0.1.

  • Update wasm-tools@latest to 1.254.0.

  • Update uv@latest to 0.11.30.

  • Update mise@latest to 2026.7.11.

  • Update cargo-neat@latest to 0.5.0.

  • Update cargo-crap@latest to 0.3.1.

  • Update biome@latest to 2.5.5.

2.84.0

  • Support d2. (#1944)

  • Support protoc-gen-connect-openapi. (#1922, thanks @​JasterV)

  • Update convco@latest to 0.7.0. (#1941, thanks @​graelo)

  • Update just@latest to 1.57.0.

  • Update cargo-semver-checks@latest to 0.49.0.

  • Update tombi@latest to 1.2.4.

  • Update cosign@latest to 3.1.2.

2.83.4

  • Update vacuum@latest to 0.29.10.

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.85.5] - 2026-07-30

  • Update uv@latest to 0.12.0.

  • Update syft@latest to 1.50.0.

  • Update sccache@latest to 0.17.0.

  • Update mise@latest to 2026.7.16.

[2.85.4] - 2026-07-29

  • Update uv@latest to 0.11.33.

  • Update mise@latest to 2026.7.15.

  • Update biome@latest to 2.5.6.

[2.85.3] - 2026-07-28

  • Update xh@latest to 0.26.2.

  • Update ubi@latest to 0.10.0.

  • Update mise@latest to 2026.7.14.

  • Update martin@latest to 1.13.0.

  • Update cargo-shear@latest to 1.13.3.

  • Update cargo-binstall@latest to 1.21.1.

[2.85.2] - 2026-07-26

  • Update prek@latest to 0.4.11.

  • Update mise@latest to 2026.7.13.

... (truncated)

Commits

Updates EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1

Commits

Updates actions/attest from 4.1.1 to 4.2.0

Release notes

Sourced from actions/attest's releases.

v4.2.0

What's Changed

Full Changelog: actions/attest@v4.1.1...v4.2.0

Commits
  • f7c74d2 feat: support SHA-2 subject digests (#446)
  • 88633d1 Bump js-yaml from 4.2.0 to 5.2.1 (#452)
  • 5dff824 Bump the actions-minor group with 3 updates (#453)
  • e67e539 Bump the npm-development group across 1 directory with 2 updates (#448)
  • 95f6155 Bump @​types/node from 25.9.2 to 26.1.1 (#449)
  • b644c72 Read subjects from GITHUB_ARTIFACTS_LIST (#447)
  • 7d3af28 Bump csv-parse from 6.2.1 to 7.0.1 (#437)
  • 52cbb4d Bump @​actions/glob from 0.6.1 to 0.7.0 in the npm-production group across 1 d...
  • a5ce33e ci: download rebuilt dist/ artifact outside the checkout workspace (#445)
  • 4c65731 ci: auto-rebuild dist/ for Dependabot production bumps (#444)
  • Additional commits viewable in compare view

Updates release-plz/action from 0.5.130 to 0.5.131

Release notes

Sourced from release-plz/action's releases.

v0.5.131

What's Changed

Full Changelog: release-plz/action@v0.5...v0.5.131

Commits
  • 2eb1d8b Update to 0.3.160 (#466)
  • bbdaa2c chore(deps): lock file maintenance (#465)
  • 77006e7 chore(deps): update dependency taiki-e/install-action to v2.83.2 (#464)
  • 4671811 chore(deps): update dependency taiki-e/install-action to v2.83.1 (#463)
  • 5825e6a chore(deps): update dependency taiki-e/install-action to v2.83.0 (#462)
  • 9627bb5 chore(deps): update dependency taiki-e/install-action to v2.82.11 (#461)
  • b291097 chore(deps): update dependency taiki-e/install-action to v2.82.10 (#460)
  • 3e68b2c chore(deps): lock file maintenance (#459)
  • 6ce0a80 chore(deps): update dependency taiki-e/install-action to v2.82.9 (#457)
  • 1ff444b chore(deps): update dependency taiki-e/install-action to v2.82.8 (#456)
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.37.0 to 4.37.3

Release notes

Sourced from github/codeql-action/init's releases.

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

4.36.0 - 22 May 2026

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893

... (truncated)

Commits
  • e4fba86 Merge pull request #4031 from github/update-v4.37.3-72f6a9da0
  • fb50ab5 Update changelog for v4.37.3
  • 72f6a9d Merge pull request #4030 from github/mbg/fix/no-proxy
  • 3b5ee58 Use default request options instead of undefined
  • bfb6be4 Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621
  • 526ab84 Rebuild
  • d6217b9 Update changelog and version after v4.37.2
  • e064762 Merge pull request #4027 from github/update-v4.37.2-385bcdc5a
  • e0faed8 Add a couple of change notes
  • 73aad0e Update changelog for v4.37.2
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.37.0 to 4.37.3

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

4.36.0 - 22 May 2026

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893

... (truncated)

Commits
  • e4fba86 Merge pull request #4031 from github/update-v4.37.3-72f6a9da0
  • fb50ab5 Update changelog for v4.37.3
  • 72f6a9d Merge pull request #4030 from github/mbg/fix/no-proxy
  • 3b5ee58 Use default request options instead of undefined
  • bfb6be4 Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621
  • 526ab84 Rebuild
  • d6217b9 Update changelog and version after v4.37.2
  • e064762 Merge pull request #4027 from github/update-v4.37.2-385bcdc5a
  • e0faed8 Add a couple of change notes
  • 73aad0e Update changelog for v4.37.2
  • Additional commits viewable in compare view


Note

Low Risk
CI-only dependency pin updates with no application logic changes; main caveat is upload-artifact v4→v7 on fuzz failure uploads, which is a major version bump but limited to artifact upload on failure.

Overview
Bumps pinned commit SHAs for third-party GitHub Actions in .github/workflows/* only—no Rust or product code changes.

actions/checkout moves to v7.0.1 everywhere it appears (bench, CI, fuzz, release, security). taiki-e/install-action is updated in CI (nextest, typos/zizmor, llvm-cov). EmbarkStudios/cargo-deny-action, release-plz/action, github/codeql-action init/analyze, actions/attest (release assets), and actions/upload-artifact (fuzz crash uploads; bench already on the new upload-artifact pin in context) get new SHAs. dtolnay/rust-toolchain is aligned to a single newer master commit in fuzz (other workflows were already on that pin).

Workflow structure, job matrices, and step commands are unchanged; only uses: references move to newer action versions.

Reviewed by Cursor Bugbot for commit f1858d4. Bugbot is set up for automated code reviews on this repo. Configure here.

Greptile Summary

Updates full-SHA-pinned GitHub Actions dependencies across six CI workflows.

  • Upgrades checkout references throughout benchmark, CI, fuzzing, release, and security jobs.
  • Updates artifact upload, attestation, Rust tooling, cargo-deny, release-plz, and CodeQL actions.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failures remain.

Files Needing Attention: No files need attention.

T-Rex T-Rex Logs

What T-Rex did

  • The PR proof validated that the old parent workflows were parsed and their pins and tags resolved, and this step completed with exit code 0.
  • The PR proof re-parsed the changed workflows and resolved every upgraded commit and tag mapping using live GitHub API responses, with exit code 0.
  • A generated validator and a concise resolved-reference output were created to enable reproducibility.
  • Artifacts were produced to support review, including a Python validator script and three log artifacts.

View all artifacts

T-Rex Ran code and verified through T-Rex

Important Files Changed

Filename Overview
.github/workflows/bench.yml Updates all checkout steps to the v7.0.1 commit.
.github/workflows/ci.yml Updates checkout, install-action, and cargo-deny-action revisions without changing job configuration.
.github/workflows/fuzz.yml Updates checkout, Rust toolchain, and artifact upload action revisions.
.github/workflows/release-assets.yml Updates checkout and attestation action revisions used by release asset jobs.
.github/workflows/release-plz.yml Updates checkout and release-plz action revisions without changing release commands or permissions.
.github/workflows/security.yml Updates checkout and both CodeQL action revisions without changing analysis configuration.

Reviews (2): Last reviewed commit: "ci: bump the actions group across 1 dire..." | Re-trigger Greptile

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 24, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner July 24, 2026 13:18
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 24, 2026
@github-actions

github-actions Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

seagrep benchmarks

micro

benchmark baseline ns current ns delta
grams_index_sparse 2121463 2942004 +38.7%
grams_index_trigram 57716 72171 +25.0%
grams_query_sparse 862 1129 +31.1%
grams_query_trigram 288 326 +13.1%
index_build_1024x4096_sparse 297826732 182009461 -38.9%
index_build_1024x4096_trigram 23021729 31172200 +35.4%
local_blob_store_segmented_reader_candidate_docs 6517 8708 +33.6%
packed_sort_control_1024 6639 8928 +34.5%
packed_sort_control_128 622 849 +36.5%
packed_sort_control_256 1312 1771 +35.0%
packed_sort_control_4096 30937 41235 +33.3%
packed_sort_control_512 3022 4097 +35.6%
packed_sort_control_65536 745618 967120 +29.7%
packed_sort_hybrid_1024 4201 5378 +28.0%
packed_sort_hybrid_128 633 819 +29.4%
packed_sort_hybrid_256 1314 1692 +28.7%
packed_sort_hybrid_4096 15930 20955 +31.5%
packed_sort_hybrid_512 2270 2942 +29.6%
packed_sort_hybrid_65536 274183 352400 +28.5%
plan_(timeout_panicked_denied) 9302 12179 +30.9%
plan_._ 400 530 +32.4%
plan_ERROR42 1505 1837 +22.1%
plan__CRITICAL_ 3486 4459 +27.9%
plan_customer_id=abc123 request_id=deadbeef 8530 11931 +39.9%
paired benchmark hybrid/control limit
packed sort 128 0.965x 1.150x
packed sort 256 0.956x 1.150x
packed sort 512 0.718x 1.150x
packed sort 1024 0.602x 1.150x
packed sort 4096 0.508x 1.150x
packed sort 65536 0.364x 1.150x
benchmark vs PR base median delta 95% CI limit
grams_index_sparse -0.3% -0.4% to -0.2% +20%
grams_index_trigram -0.2% -0.3% to -0.0% +20%
grams_query_sparse +0.6% +0.6% to +0.8% +30%
grams_query_trigram -1.1% -1.3% to -1.0% +20%
index_build_1024x4096_sparse +0.8% -0.3% to +1.1% +20%
index_build_1024x4096_trigram +1.3% +0.1% to +2.2% +20%
local_blob_store_segmented_reader_candidate_docs +2.8% +2.6% to +3.0% +20%
packed_sort_control_1024 +4.0% +4.0% to +4.1% paired
packed_sort_control_128 +6.5% +6.4% to +6.6% paired
packed_sort_control_256 +4.3% +4.2% to +4.5% paired
packed_sort_control_4096 +3.6% +3.5% to +3.7% paired
packed_sort_control_512 +5.9% +5.8% to +6.0% paired
packed_sort_control_65536 +0.5% +0.1% to +0.7% paired
packed_sort_hybrid_1024 -16.5% -16.6% to -16.3% paired
packed_sort_hybrid_128 -2.0% -2.3% to -1.7% paired
packed_sort_hybrid_256 -4.9% -5.0% to -4.8% paired
packed_sort_hybrid_4096 -11.5% -11.6% to -11.4% paired
packed_sort_hybrid_512 -8.2% -8.3% to -7.8% paired
packed_sort_hybrid_65536 -0.3% -0.5% to -0.2% paired
plan_(timeout_panicked_denied) -2.7% -2.8% to -2.6% +20%
plan_._ -0.6% -0.8% to +0.1% +20%
plan_ERROR42 -3.3% -3.4% to -3.1% +20%
plan__CRITICAL_ -1.1% -1.4% to -0.9% +20%
plan_customer_id=abc123 request_id=deadbeef +0.1% -0.0% to +0.3% +20%

e2e S3

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
short_literal 500 500/1000 0.500 2048000 8.387 8.496 8.496 8.324
long_literal 334 334/1000 0.334 1368064 8.664 8.901 8.901 8.846
alternation 314 314/1000 0.314 1286144 8.006 8.021 8.021 8.135
anchored 91 91/1000 0.091 372736 7.050 7.096 7.096 7.105
no_match 0 0/1000 0.000 0 0.012 0.015 0.015 0.010
QAll 1000 1000/1000 1.000 4096000 10.127 10.287 10.287 10.212
dot_star_gap 100 100/1000 0.100 409600 8.084 8.141 8.141 8.103

scale

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
short_literal 12500 12500/25000 0.500 51200000 273.636 273.636 273.636 210.324
long_literal 8334 8334/25000 0.333 34136064 196.691 196.691 196.691 195.392
alternation 7857 7857/25000 0.314 32182272 191.938 191.938 191.938 188.984
anchored 2273 2273/25000 0.091 9310208 167.148 167.148 167.148 167.196
no_match 0 0/25000 0.000 0 0.044 0.044 0.044 0.013
QAll 25000 25000/25000 1.000 102400000 244.596 244.596 244.596 241.726
dot_star_gap 2500 2500/25000 0.100 10240000 174.901 174.901 174.901 171.355

prose

prose corpus, trigram

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 998/1000 0.998 65407598 167.669 167.669 167.669 126.427
unplanted_phrase 0 996/1000 0.996 65276525 125.153 125.153 125.153 124.854
rare_word 4 4/1000 0.004 262155 1.577 1.577 1.577 1.319
common_word 1000 1000/1000 1.000 65538679 124.592 124.592 124.592 124.478

prose corpus, sparse

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 20/1000 0.020 1310768 28.993 28.993 28.993 25.219
unplanted_phrase 0 0/1000 0.000 0 8.705 8.705 8.705 8.488
rare_word 4 4/1000 0.004 262155 4.568 4.568 4.568 3.975
common_word 1000 1000/1000 1.000 65538679 162.518 162.518 162.518 124.314

Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [actions/upload-artifact](https://github.com/actions/upload-artifact), [taiki-e/install-action](https://github.com/taiki-e/install-action), [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action), [actions/attest](https://github.com/actions/attest), [release-plz/action](https://github.com/release-plz/action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action) to permit the latest version.

Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `dtolnay/rust-toolchain` to 2c7215f132e9ebf062739d9130488b56d53c060c
- [Release notes](https://github.com/dtolnay/rust-toolchain/releases)
- [Commits](https://github.com/dtolnay/rust-toolchain/commits/2c7215f132e9ebf062739d9130488b56d53c060c)

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...043fb46)

Updates `taiki-e/install-action` from 2.83.1 to 2.85.0
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@2ca9b94...7572810)

Updates `EmbarkStudios/cargo-deny-action` from 2.0.20 to 2.1.1
- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)
- [Commits](EmbarkStudios/cargo-deny-action@bb137d7...3c63498)

Updates `actions/attest` from 4.1.1 to 4.2.0
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@a1948c3...f7c74d2)

Updates `release-plz/action` from 0.5.130 to 0.5.131
- [Release notes](https://github.com/release-plz/action/releases)
- [Commits](release-plz/action@e879257...2eb1d8b)

Updates `github/codeql-action/init` from 4.37.0 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)

Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)

---
updated-dependencies:
- dependency-name: actions/attest
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: dtolnay/rust-toolchain
  dependency-version: 2c7215f132e9ebf062739d9130488b56d53c060c
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: EmbarkStudios/cargo-deny-action
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: release-plz/action
  dependency-version: 0.5.131
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: taiki-e/install-action
  dependency-version: 2.83.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title ci: bump the actions group with 9 updates ci: bump the actions group across 1 directory with 9 updates Jul 31, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-f89e2d92cd branch from b6083ea to f1858d4 Compare July 31, 2026 13:18
@dependabot @github

dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 14, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-f89e2d92cd branch August 14, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants