Skip to content

deps(deps): update github actions (minor) - #191

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v6.0.2v6.1.0
actions/labeler action minor v6.1.0v6.2.0
actions/setup-go action minor v6.4.0v6.5.0
actions/stale action minor v10.3.0v10.4.0
crate-ci/typos action minor v1.46.3v1.50.2
editorconfig-checker/action-editorconfig-checker action minor v2.2.0v2.3.0
go uses-with minor 1.26.31.27.1
golangci/golangci-lint-action action minor v9.2.1v9.3.0
google/osv-scanner-action workflow minor v2.3.8v2.6.0
reviewdog/action-actionlint action minor v1.72.0v1.76.1
securego/gosec action minor v2.26.1v2.29.0
semgrep/semgrep container digest 7cad2bc34ab619
step-security/harden-runner action minor v2.19.4v2.21.1
trufflesecurity/trufflehog action minor v3.95.3v3.97.5

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

v6.0.3

Compare Source

actions/labeler (actions/labeler)

v6.2.0

Compare Source

What's Changed

Bug Fix
Dependency Updates

Full Changelog: actions/labeler@v6.1.0...v6.2.0

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

actions/stale (actions/stale)

v10.4.0

Compare Source

What's Changed

Bug Fix
Dependency Updates
  • Bump undici to 6.27.0 via override, clean up stale license files, and version to 10.4.0. by @​dependabot in #​1342

New Contributors

Full Changelog: actions/stale@v10.3.0...v10.4.0

crate-ci/typos (crate-ci/typos)

v1.50.2

Compare Source

[1.50.2] - 2026-09-15

Fixes
  • Don't panic when files being examined are removed

v1.50.1

Compare Source

[1.50.1] - 2026-09-01

Fixes
  • Don't correct asend in Python code

v1.50.0

Compare Source

[1.50.0] - 2026-08-28

Features

v1.49.1

Compare Source

[1.49.1] - 2026-08-27

Fixes
  • Don't correct the brand name HashiCorp

v1.49.0

Compare Source

[1.49.0] - 2026-08-03

Features
  • Updated the dictionary with the July 2026 changes

v1.48.0

Compare Source

[1.48.0] - 2026-06-30

Features
  • Updated the dictionary with the June 2026 changes

v1.47.2

Compare Source

[1.47.2] - 2026-06-04

Fixes
  • Don't correct inferrable
  • Correct unused inferible variant

v1.47.1

Compare Source

[1.47.1] - 2026-06-03

Fixes
  • Don't correct requestors

v1.47.0

Compare Source

[1.47.0] - 2026-05-29

Features
  • Updated the dictionary with the May 2026 changes
editorconfig-checker/action-editorconfig-checker (editorconfig-checker/action-editorconfig-checker)

v2.3.0: last v2 release

Compare Source

This release is the last release of this action, that fixes the editorconfig-checker core version to v3.11.3 - which is the last release that still uses the ec binary name.

Full Changelog: editorconfig-checker/action-editorconfig-checker@v2.2.0...v2.3.0

actions/go-versions (go)

v1.27.1: 1.27.1

Compare Source

Go 1.27.1

v1.27.0: 1.27.0

Compare Source

Go 1.27.0

v1.26.8: 1.26.8

Compare Source

Go 1.26.8

v1.26.7: 1.26.7

Compare Source

Go 1.26.7

v1.26.6: 1.26.6

Compare Source

Go 1.26.6

v1.26.5: 1.26.5

Compare Source

Go 1.26.5

v1.26.4: 1.26.4

Compare Source

Go 1.26.4

golangci/golangci-lint-action (golangci/golangci-lint-action)

v9.3.0

Compare Source

What's Changed

Changes
Dependencies

Full Changelog: golangci/golangci-lint-action@v9.2.1...v9.3.0

google/osv-scanner-action (google/osv-scanner-action)

v2.6.0

Compare Source

What's Changed
New Contributors

Full Changelog: google/osv-scanner-action@v2.5.1...v2.6.0

v2.5.1

Compare Source

This updates OSV-Scanner to v2.3.8.

What's Changed
Fixes:
  • Preserve package namespaces when querying osv.dev API (fixes #​2978).
  • Re-add support for the OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY environment variable (fixes #​2983).
  • Fix local vulnerability matching (--offline-vulnerabilities) not working when network capability is NetworkOnline.

Full Changelog: google/osv-scanner-action@v2.5.0...v2.5.1

v2.5.0

Compare Source

This updates OSV-Scanner to v2.5.0 as well as:

What's Changed

New Contributors

Full Changelog: google/osv-scanner-action@v2.3.8...v2.5.0

reviewdog/action-actionlint (reviewdog/action-actionlint)

v1.76.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.76.0...v1.76.1

v1.76.0

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.75.3...v1.76.0

v1.75.3

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.75.2...v1.75.3

v1.75.2

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.75.1...v1.75.2

v1.75.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.75.0...v1.75.1

v1.75.0

Compare Source

What's Changed

New Contributors

Full Changelog: reviewdog/action-actionlint@v1.74.0...v1.75.0

v1.74.0

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.4...v1.74.0

v1.73.4

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.3...v1.73.4

v1.73.3

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.2...v1.73.3

v1.73.2

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.1...v1.73.2

v1.73.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.0...v1.73.1

v1.73.0

Compare Source

What's Changed

New Contributors

Full Changelog: reviewdog/action-actionlint@v1.72.1...v1.73.0

v1.72.1

Compare Source

v1.72.1: PR #​211 - fix: include digest in Docker image reference for action.yml

securego/gosec (securego/gosec)

v2.29.0

Compare Source

Changelog

v2.28.0

Compare Source

Changelog

v2.27.1

Compare Source

Changelog

v2.27.0

Compare Source

Changelog

step-security/harden-runner (step-security/harden-runner)

v2.21.1

Compare Source

What's Changed
  • Improved performance of the disable-sudo feature.
  • Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode.
  • Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners.
  • Documentation updates: clarified which features are in the Community (free) vs Enterprise tier.

Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1

v2.21.0

Compare Source

What's Changed
  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0

v2.20.1

Compare Source

What's Changed
  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1

v2.20.0

Compare Source

What's Changed
  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

trufflesecurity/trufflehog (trufflesecurity/trufflehog)

v3.97.5

Compare Source

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.4...v3.97.5

v3.97.4

Compare Source

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.3...v3.97.4

v3.97.3

Compare Source

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.2...v3.97.3

v3.97.2

Compare Source

What's Changed
New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.1...v3.97.2

v3.97.1

Compare Source

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.0...v3.97.1

v3.97.0

Compare Source

What's Changed

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency label Jun 8, 2026
@renovate
renovate Bot requested a review from amiwrpremium as a code owner June 8, 2026 00:48
@renovate
renovate Bot enabled auto-merge (squash) June 8, 2026 00:48
@codacy-production

codacy-production Bot commented Jun 8, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@github-actions github-actions Bot added area:ci .github/ — workflows, settings, rulesets and removed dependencies Pull requests that update a dependency labels Jun 8, 2026
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 16b5d9e to 4fd6d58 Compare June 10, 2026 15:33
@renovate
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 09595c7 to fe06901 Compare June 24, 2026 06:07
@renovate
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from ca80a3d to ef72fdb Compare June 30, 2026 22:01
@renovate
renovate Bot force-pushed the renovate/github-actions branch from ef72fdb to 77c73f3 Compare July 7, 2026 09:57
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@renovate
renovate Bot force-pushed the renovate/github-actions branch 5 times, most recently from fba28ff to f659691 Compare July 14, 2026 11:54
@renovate
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from d99ffbc to 946fda1 Compare July 21, 2026 23:59
@renovate
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from 0c549be to 38c4d11 Compare July 28, 2026 23:25
@renovate
renovate Bot force-pushed the renovate/github-actions branch 4 times, most recently from c92a75a to 4c0576a Compare August 7, 2026 06:05
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4c0576a to b4aae7e Compare August 12, 2026 22:28
@renovate
renovate Bot force-pushed the renovate/github-actions branch 5 times, most recently from 61c1fab to 9286444 Compare August 20, 2026 05:39
@renovate
renovate Bot force-pushed the renovate/github-actions branch 6 times, most recently from 8532c7f to 9c4ee37 Compare August 31, 2026 03:06
@renovate
renovate Bot force-pushed the renovate/github-actions branch 7 times, most recently from a72aa78 to a21f442 Compare September 4, 2026 20:33
@renovate
renovate Bot force-pushed the renovate/github-actions branch 6 times, most recently from 3ccf32a to a0a0d65 Compare September 15, 2026 20:45
@renovate
renovate Bot force-pushed the renovate/github-actions branch 4 times, most recently from 9d90e03 to 17abec8 Compare September 18, 2026 21:56
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 17abec8 to 66b429b Compare September 22, 2026 03:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:ci .github/ — workflows, settings, rulesets

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant