Skip to content

ci: bump the actions group across 1 directory with 10 updates - #98

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-653522cca2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-653522cca2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on actions/checkout, dtolnay/rust-toolchain, Swatinem/rust-cache, actions/upload-artifact, taiki-e/install-action, EmbarkStudios/cargo-deny-action, actions/attest, release-plz/action, github/codeql-action/init and github/codeql-action/analyze to permit the latest version.
Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dtolnay/rust-toolchain to 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772

Commits

Updates Swatinem/rust-cache from e18b497796c12c097a38f9edb9d0641fb99eee32 to 258712b0b7b1ddf8bddc9fc3b0faca682b2736c3

Changelog

Sourced from Swatinem/rust-cache's changelog.

Changelog

2.9.2

  • Fix credentials.toml cleanup
  • Improvements to cleanup, preserving more valid targets
  • Improvements to cargo install handling
  • Correctly sort/dedupe Rust versions

2.9.1

  • Fix regression in hash calculation

2.9.0

  • Update to node24
  • Support running from within a nix shell
  • Consider all installed toolchains for cache key
  • Use case-insensitive comparison to determine exact cache hit

2.8.2

  • Don't overwrite env for cargo-metadata call

2.8.1

  • Set empty CARGO_ENCODED_RUSTFLAGS when retrieving metadata
  • Various dependency updates

2.8.0

  • Add support for warpbuild cache provider
  • Add new cache-workspace-crates feature

2.7.8

  • Include CPU arch in the cache key

2.7.7

  • Also cache cargo install metadata

2.7.6

  • Allow opting out of caching $CARGO_HOME/bin
  • Add runner OS in cache key
  • Adds an option to do lookup-only of the cache

2.7.5

... (truncated)

Commits
  • 258712b fix: stop cleanup timestamp pruning after the first entry (#377)
  • a45951f Merge pull request #373 from Swatinem/dependabot/github_actions/actions-420be...
  • b882611 Bump the actions group with 2 updates
  • 6323deb 2.9.2
  • b16e8d7 bump rollup and rebuild
  • 3bf42ac invert target/profile check in cleanup
  • 6e5b278 correctly sort and dedupe Rust versions
  • 5adc05f Bump the actions group across 1 directory with 3 updates (#368)
  • 66b1e95 fix: support Cargo V2 build dir layout (#371)
  • 72d126e Merge pull request #367 from Swatinem/dependabot/npm_and_yarn/dev-patch-2b495...
  • Additional commits viewable in compare view

Updates actions/upload-artifact from 4.6.2 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Updates taiki-e/install-action from 2.83.1 to 2.85.10

Release notes

Sourced from taiki-e/install-action's releases.

2.85.10

  • Update uv@latest to 0.12.2.

  • Update tombi@latest to 1.2.7.

  • Update cosign@latest to 3.1.3.

  • Update coreutils@latest to 0.10.0.

  • Update cargo-rdme@latest to 2.2.0.

  • Update cargo-crap@latest to 0.4.3.

2.85.9

  • Update zola@latest to 0.23.1.

  • Update wild@latest to 0.10.0.

  • Update mise@latest to 2026.8.2.

  • Update just@latest to 1.58.0.

  • Update jaq@latest to 3.1.1.

  • Update cargo-nextest@latest to 0.9.143.

  • Update cargo-crap@latest to 0.4.2.

  • Update biome@latest to 2.5.7.

2.85.8

  • Update zizmor@latest to 1.29.0.

  • Update typos@latest to 1.49.0.

  • Update trivy@latest to 0.73.0.

  • Update tombi@latest to 1.2.6.

  • Update prek@latest to 0.4.12.

  • Update mise@latest to 2026.8.1.

  • Update convco@latest to 0.7.1.

  • Update cargo-semver-checks@latest to 0.50.0.

  • Update cargo-crap@latest to 0.4.1.

2.85.7

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.85.13] - 2026-08-13

  • Update tombi@latest to 1.3.3.

  • Update mise@latest to 2026.8.5.

  • Update kingfisher@latest to 1.113.0.

  • Update cargo-shear@latest to 1.13.4.

  • Update bpf-linker@latest to 0.11.0.

[2.85.12] - 2026-08-12

  • Update zola@latest to 0.23.3.

  • Update wasm-tools@latest to 1.256.0.

  • Update tombi@latest to 1.2.10.

  • Update syft@latest to 1.51.0.

  • Update prek@latest to 0.4.13.

  • Update mise@latest to 2026.8.4.

  • Update editorconfig-checker@latest to 3.11.1.

  • Update cargo-tarpaulin@latest to 0.37.1.

  • Update cargo-rdme@latest to 2.2.1.

  • Update biome@latest to 2.5.8.

[2.85.11] - 2026-08-09

  • Update zola@latest to 0.23.2.

... (truncated)

Commits

Updates EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1

Release notes

Sourced from EmbarkStudios/cargo-deny-action's releases.

Release 2.1.1 - cargo-deny 0.20.2

Fixed

  • PR#116 fixed in issue introduced in the 2.1.0 release due the deprecation of the use-git-cli argument. Thanks @​Firestar99!

Release 2.1.0 - cargo-deny 0.20.2

Changed

  • PR#881 refactored the CLI, moving some duplicated options/flags into the root and removing several deprecated options/flags/values. See the PR for a full list of changes.

Added

  • PR#879 resolved #873 by adding a new bans.std-replacements lint which checks the graph for crates.io sourced crates that have been partially or fully replaced in std and/or core.

Fixed

  • PR#880 resolved #765 by respecting non-default build script paths in manifests.
  • PR#881 resolved #874 by cleaning up the CLI, deduplicating some options/flags that caused bug in the list subcommand.
Commits

Updates actions/attest from 4.1.1 to 4.2.2

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

v4.2.1

What's Changed

Full Changelog: actions/attest@v4.2.0...v4.2.1

v4.2.0

What's Changed

Full Changelog: actions/attest@v4.1.1...v4.2.0

Commits
  • 1e69f48 Bump ip-address from 10.2.0 to 10.4.0 (#467)
  • 02787ce Bump brace-expansion (#468)
  • 98ac037 bump @​sigstore/oci from 0.7.1 to 0.7.2 (#469)
  • 508db95 fix: strip OCI image tag when pushing attestation to registry (#464)
  • dda48f2 Bump the npm-development group across 1 directory with 6 updates (#461)
  • 7d789a3 Bump the actions-minor group with 3 updates (#463)
  • 1f3ca2f Add release-cutter canvas extension (#454)
  • d215549 Bump tar from 7.5.17 to 7.5.21 (#459)
  • 20c90ed Bump the npm-development group with 2 updates (#455)
  • 43c2c81 Bump the actions-minor group with 4 updates (#456)
  • Additional commits viewable in compare view

Updates release-plz/action from 0.5.130 to 0.5.131

Release notes

Sourced from release-plz/action's releases.

v0.5.131

What's Changed

Full Changelog: release-plz/action@v0.5...v0.5.131

Commits
  • 2eb1d8b Update to 0.3.160 (#466)
  • bbdaa2c chore(deps): lock file maintenance (#465)
  • 77006e7 chore(deps): update dependency taiki-e/install-action to v2.83.2 (#464)
  • 4671811 chore(deps): update dependency taiki-e/install-action to v2.83.1 (#463)
  • 5825e6a chore(deps): update dependency taiki-e/install-action to v2.83.0 (#462)
  • 9627bb5 chore(deps): update dependency taiki-e/install-action to v2.82.11 (#461)
  • b291097 chore(deps): update dependency taiki-e/install-action to v2.82.10 (#460)
  • 3e68b2c chore(deps): lock file maintenance (#459)
  • 6ce0a80 chore(deps): update dependency taiki-e/install-action to v2.82.9 (#457)
  • 1ff444b chore(deps): update dependency taiki-e/install-action to v2.82.8 (#456)
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.37.0 to 4.37.6

Release notes

Sourced from github/codeql-action/init's releases.

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

... (truncated)

Commits
  • 5595cca Merge pull request #4071 from github/update-v4.37.6-6a9359a1b
  • ec9c757 Add change note for PR 4070
  • 45c8742 Update changelog for v4.37.6
  • 6a9359a Merge pull request #4070 from github/mbg/remote-address/change-file-default
  • 065cdc0 Change DEFAULT_CONFIG_FILE_NAME
  • f99dd5a Merge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 1804b21 Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a1
  • 3020a2f Rebuild
  • 93c3a5a Update changelog and version after v4.37.5
  • d1ba80a Merge pull request #4067 from github/update-v4.37.5-1cd4d01d5
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.37.0 to 4.37.6

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication....

    Description has been truncated


    [!NOTE]
    Low Risk
    Workflow-only SHA bumps with no product code changes; main watchpoint is CI stability after upload-artifact v7 and refreshed rust-cache/cargo-deny pins.

    Overview
    This PR re-pins third-party GitHub Actions across bench.yml, ci.yml, fuzz.yml, release-assets.yml, release-plz.yml, and security.yml. There are no changes to job logic, matrices, or application code—only uses: commit SHAs (and version comments where present).

    Shared CI stack: actions/checkout (v7.0.1), dtolnay/rust-toolchain, and Swatinem/rust-cache are updated everywhere they appear (tests, benchmarks, fuzz, release-plz verify/release).

    Other bumps: taiki-e/install-action in CI workflow-lint and coverage; EmbarkStudios/cargo-deny-action in CI; actions/upload-artifact v7 in bench and fuzz; actions/attest on release asset attestation; release-plz/action on release PR and publish jobs; github/codeql-action/init and analyze in security.

    The largest functional jump is fuzz moving upload-artifact from v4 to v7 (Node/ESM runtime); bench workflows were already on a v7 upload-artifact pin and only change the SHA.

    Reviewed by Cursor Bugbot for commit 3c0680e. Bugbot is set up for automated code reviews on this repo. Configure here.

    Greptile Summary

    This update refreshes immutable GitHub Action revisions across CI, benchmarking, fuzzing, release, and security workflows. The potential failure mode of updated action references no longer resolving or rejecting their existing inputs was disproved: an executed check resolved all 61 changed references and confirmed all 61 configured input sets were accepted. No defects were found, and the change is safe to merge.

    Confidence Score: 5/5

    Safe to merge: the updated automation dependencies resolved successfully and retained compatibility with all configured workflow inputs.

    No publishable defects remain. The executed validation covered every changed Action reference and observed successful resolution and input compatibility.

    Files Needing Attention: No files need follow-up attention.

    T-Rex T-Rex Logs

    What T-Rex did

    • Executed the SHA resolution validator in the repository and the process exited successfully.
    • The validator enumerated 61 changed workflow action references, resolved each action definition, and checked every configured input set.
    • The validation reported 61 reachable action definitions, 61 accepted input sets, and the result showed PASS.
    • No repository workflow source files were modified; only the required validation artifacts were created.

    View all artifacts

    T-Rex Ran code and verified through T-Rex

    Reviews (1): Last reviewed commit: "ci: bump the actions group across 1 dire..." | Re-trigger Greptile

Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [Swatinem/rust-cache](https://github.com/swatinem/rust-cache), [actions/upload-artifact](https://github.com/actions/upload-artifact), [taiki-e/install-action](https://github.com/taiki-e/install-action), [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action), [actions/attest](https://github.com/actions/attest), [release-plz/action](https://github.com/release-plz/action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action) to permit the latest version.

Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `dtolnay/rust-toolchain` to 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772
- [Release notes](https://github.com/dtolnay/rust-toolchain/releases)
- [Commits](https://github.com/dtolnay/rust-toolchain/commits/6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772)

Updates `Swatinem/rust-cache` from e18b497796c12c097a38f9edb9d0641fb99eee32 to 258712b0b7b1ddf8bddc9fc3b0faca682b2736c3
- [Release notes](https://github.com/swatinem/rust-cache/releases)
- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md)
- [Commits](Swatinem/rust-cache@e18b497...258712b)

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...043fb46)

Updates `taiki-e/install-action` from 2.83.1 to 2.85.10
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@2ca9b94...6c6fd71)

Updates `EmbarkStudios/cargo-deny-action` from 2.0.20 to 2.1.1
- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)
- [Commits](EmbarkStudios/cargo-deny-action@bb137d7...3c63498)

Updates `actions/attest` from 4.1.1 to 4.2.2
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@a1948c3...1e69f48)

Updates `release-plz/action` from 0.5.130 to 0.5.131
- [Release notes](https://github.com/release-plz/action/releases)
- [Commits](release-plz/action@e879257...2eb1d8b)

Updates `github/codeql-action/init` from 4.37.0 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...5595cca)

Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...5595cca)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: dtolnay/rust-toolchain
  dependency-version: 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: Swatinem/rust-cache
  dependency-version: 258712b0b7b1ddf8bddc9fc3b0faca682b2736c3
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: EmbarkStudios/cargo-deny-action
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: release-plz/action
  dependency-version: 0.5.131
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 14, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner August 14, 2026 13:19
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 14, 2026
@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

benchmark baseline ns current ns delta
grams_index_sparse 2121463 2815835 +32.7%
grams_index_trigram 57716 100007 +73.3%
grams_query_sparse 862 1132 +31.4%
grams_query_trigram 288 314 +9.1%
index_build_1024x4096_sparse 297826732 177089546 -40.5%
index_build_1024x4096_trigram 23021729 32873188 +42.8%
local_blob_store_segmented_reader_candidate_docs 6517 8240 +26.4%
packed_sort_control_1024 6639 8058 +21.4%
packed_sort_control_128 622 743 +19.5%
packed_sort_control_256 1312 1625 +23.9%
packed_sort_control_4096 30937 37202 +20.3%
packed_sort_control_512 3022 3649 +20.8%
packed_sort_control_65536 745618 910299 +22.1%
packed_sort_hybrid_1024 4201 4838 +15.2%
packed_sort_hybrid_128 633 711 +12.3%
packed_sort_hybrid_256 1314 1552 +18.1%
packed_sort_hybrid_4096 15930 19039 +19.5%
packed_sort_hybrid_512 2270 2649 +16.7%
packed_sort_hybrid_65536 274183 506393 +84.7%
plan_(timeout_panicked_denied) 9302 12621 +35.7%
plan_._ 400 516 +29.0%
plan_ERROR42 1505 1899 +26.2%
plan__CRITICAL_ 3486 4445 +27.5%
plan_customer_id=abc123 request_id=deadbeef 8530 11906 +39.6%
paired benchmark hybrid/control limit
packed sort 128 0.957x 1.150x
packed sort 256 0.955x 1.150x
packed sort 512 0.726x 1.150x
packed sort 1024 0.600x 1.150x
packed sort 4096 0.512x 1.150x
packed sort 65536 0.556x 1.150x
benchmark vs PR base median delta 95% CI limit
grams_index_sparse -0.4% -0.5% to -0.3% +20%
grams_index_trigram -0.4% -0.4% to -0.3% +20%
grams_query_sparse +4.1% +3.9% to +4.2% +30%
grams_query_trigram -3.1% -3.2% to -3.0% +20%
index_build_1024x4096_sparse -1.6% -2.1% to -1.1% +20%
index_build_1024x4096_trigram -0.2% -0.7% to +0.9% +20%
local_blob_store_segmented_reader_candidate_docs -0.6% -0.7% to -0.5% +20%
packed_sort_control_1024 +3.8% +3.7% to +3.8% paired
packed_sort_control_128 +4.7% +4.5% to +4.8% paired
packed_sort_control_256 +3.8% +3.7% to +3.9% paired
packed_sort_control_4096 +3.3% +3.1% to +3.4% paired
packed_sort_control_512 +3.0% +2.9% to +3.1% paired
packed_sort_control_65536 +0.1% +0.0% to +0.3% paired
packed_sort_hybrid_1024 -5.6% -5.8% to -5.5% paired
packed_sort_hybrid_128 -4.3% -4.4% to -4.1% paired
packed_sort_hybrid_256 -5.5% -5.6% to -5.4% paired
packed_sort_hybrid_4096 -5.6% -5.8% to -5.4% paired
packed_sort_hybrid_512 -5.0% -5.1% to -4.7% paired
packed_sort_hybrid_65536 -10.3% -11.4% to -9.1% paired
plan_(timeout_panicked_denied) -2.1% -2.2% to -1.9% +20%
plan_._ -2.1% -2.3% to -1.8% +20%
plan_ERROR42 -5.1% -5.4% to -5.0% +20%
plan__CRITICAL_ -3.3% -3.5% to -3.2% +20%
plan_customer_id=abc123 request_id=deadbeef -1.4% -1.7% to -1.3% +20%

e2e S3

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
short_literal 500 500/1000 0.500 2048000 8.070 8.225 8.225 8.236
long_literal 334 334/1000 0.334 1368064 8.523 8.613 8.613 8.387
alternation 314 314/1000 0.314 1286144 7.655 7.971 7.971 7.744
anchored 91 91/1000 0.091 372736 6.833 6.872 6.872 6.733
no_match 0 0/1000 0.000 0 0.009 0.010 0.010 0.008
QAll 1000 1000/1000 1.000 4096000 9.981 10.047 10.047 9.923
dot_star_gap 100 100/1000 0.100 409600 7.929 8.123 8.123 7.824

scale

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
short_literal 12500 12500/25000 0.500 51200000 268.025 268.025 268.025 212.236
long_literal 8334 8334/25000 0.333 34136064 195.878 195.878 195.878 196.401
alternation 7857 7857/25000 0.314 32182272 192.507 192.507 192.507 190.190
anchored 2273 2273/25000 0.091 9310208 166.598 166.598 166.598 166.007
no_match 0 0/25000 0.000 0 0.043 0.043 0.043 0.011
QAll 25000 25000/25000 1.000 102400000 245.055 245.055 245.055 240.552
dot_star_gap 2500 2500/25000 0.100 10240000 173.227 173.227 173.227 170.464

prose

prose corpus, trigram

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 998/1000 0.998 65407598 164.091 164.091 164.091 126.261
unplanted_phrase 0 996/1000 0.996 65276525 124.736 124.736 124.736 124.280
rare_word 4 4/1000 0.004 262155 1.538 1.538 1.538 1.304
common_word 1000 1000/1000 1.000 65538679 124.186 124.186 124.186 123.859

prose corpus, sparse

scenario hits candidates/total prune ratio bytes p50 ms p95 ms p99 ms concurrency=1 p50 ms
planted_phrase 20 20/1000 0.020 1310768 28.822 28.822 28.822 25.392
unplanted_phrase 0 0/1000 0.000 0 8.697 8.697 8.697 8.265
rare_word 4 4/1000 0.004 262155 4.697 4.697 4.697 4.231
common_word 1000 1000/1000 1.000 65538679 162.381 162.381 162.381 124.233

@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 25, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-653522cca2 branch September 25, 2026 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants