From 9b7a0895c4b0546746627578a2ac7581d896dc8b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 31 Aug 2026 17:26:09 +0000 Subject: [PATCH] chore(deps): bump the version-updates group across 1 directory with 12 updates Bumps the version-updates group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `6` | `7` | | [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) | `7.3.1` | `7.7.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` | | [docker/login-action](https://github.com/docker/login-action) | `3` | `4` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6` | `7` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.0` | `0.24.2` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.4.0` | `7.4.2` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3` | `4` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `8` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.6.2` | `3.0.2` | | [actions/github-script](https://github.com/actions/github-script) | `7` | `9` | Updates `actions/checkout` from 6 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v6...v7) Updates `release-drafter/release-drafter` from 7.3.1 to 7.7.0 - [Release notes](https://github.com/release-drafter/release-drafter/releases) - [Commits](https://github.com/release-drafter/release-drafter/compare/693d20e7c1ce1a81d3a41962f85914253b518449...34d80673e067bdc0c24568d3af899c216adcfaa9) Updates `docker/setup-buildx-action` from 3 to 4 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4) Updates `docker/login-action` from 3 to 4 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/v3...v4) Updates `docker/build-push-action` from 6 to 7 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/v6...v7) Updates `anchore/sbom-action` from 0.22.0 to 0.24.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/sbom-action/compare/62ad5284b8ced813296287a0b63906cb364b73ee...3ad7283483fc7af8ff2b4ea19663c2d5ca935e26) Updates `anchore/scan-action` from 7.4.0 to 7.4.2 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/scan-action/compare/e1165082ffb1fe366ebaf02d8526e7c4989ea9d2...27805bf3b4e84b4a5c980df22ed233c00390a439) Updates `actions/attest-build-provenance` from 3 to 4 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/v3...v4) Updates `actions/setup-python` from 5 to 7 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/v5...v7) Updates `actions/download-artifact` from 4 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v4...v8) Updates `softprops/action-gh-release` from 2.6.2 to 3.0.2 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/3bb12739c298aeb8a4eeaf626c5b8d85266b0e65...3d0d9888cb7fd7b750713d6e236d1fcb99157228) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v7...v9) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: release-drafter/release-drafter dependency-version: 7.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: version-updates - dependency-name: docker/setup-buildx-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: docker/login-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: docker/build-push-action dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: version-updates - dependency-name: anchore/scan-action dependency-version: 7.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: softprops/action-gh-release dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: version-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/chaos-regression.yml | 2 +- .github/workflows/ci.yml | 42 +++++++++++----------- .github/workflows/kubernetes-proof.yml | 2 +- .github/workflows/perf-nightly.yml | 2 +- .github/workflows/promote.yml | 2 +- .github/workflows/release-drafter.yml | 2 +- .github/workflows/release.yml | 48 +++++++++++++------------- .github/workflows/rendered-diff.yml | 6 ++-- .github/workflows/version-check.yml | 2 +- 9 files changed, 54 insertions(+), 54 deletions(-) diff --git a/.github/workflows/chaos-regression.yml b/.github/workflows/chaos-regression.yml index 019d3d14..e996e036 100644 --- a/.github/workflows/chaos-regression.yml +++ b/.github/workflows/chaos-regression.yml @@ -40,6 +40,6 @@ jobs: github.event.pull_request.head.repo.full_name == github.repository) timeout-minutes: 20 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Reboot/chaos self-heal regression probe run: bash scripts/ops/chaos_probe.sh diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0d7e4f92..a2325ed0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -24,7 +24,7 @@ jobs: pre-commit: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind + dev deps @@ -48,7 +48,7 @@ jobs: public-checks: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — no dependency on a pre-provisioned runner) run: | curl -LsSf https://astral.sh/uv/install.sh | sh @@ -98,7 +98,7 @@ jobs: audit: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Run forbidden-pattern audit run: python3 scripts/checks/audit_forbidden.py --fail --json audit-report.json - if: always() @@ -111,7 +111,7 @@ jobs: schema-validate: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Validate all service descriptors @@ -134,7 +134,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -150,7 +150,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -166,7 +166,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -181,7 +181,7 @@ jobs: constraints-validate: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Validate dependency constraint planes run: python3 scripts/checks/constraints_check.py @@ -189,7 +189,7 @@ jobs: docs-mirror-validate: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Validate README language mirrors run: python3 scripts/checks/docs_mirror_check.py @@ -198,7 +198,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -214,7 +214,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -234,7 +234,7 @@ jobs: runs-on: ubuntu-latest needs: [schema-validate, deploy-target-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -250,7 +250,7 @@ jobs: runs-on: ubuntu-latest needs: [deploy-target-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -266,7 +266,7 @@ jobs: runs-on: ubuntu-latest needs: [docs-mirror-validate, component-validate, deploy-target-validate, tool-candidate-validate, constraints-validate, topology-validate, healthcheck-tool-validate, kubernetes-render-validate, kubernetes-proof-workflow-validate] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -283,7 +283,7 @@ jobs: needs: [audit, schema-validate, component-validate, deploy-target-validate, tool-candidate-validate, constraints-validate, topology-validate, healthcheck-tool-validate, kubernetes-render-validate] timeout-minutes: 20 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind + dev @@ -315,7 +315,7 @@ jobs: needs: [audit, constraints-validate] timeout-minutes: 30 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Build base image run: docker build -f docker/Dockerfile.base -t agmind-base:ci . @@ -328,7 +328,7 @@ jobs: matrix: backend: [cpu, vulkan, rocm] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Build base + ${{ matrix.backend }} image (self-contained — GitHub-hosted runners do not share local images) run: | @@ -345,7 +345,7 @@ jobs: needs: [schema-validate, component-validate, deploy-target-validate, tool-candidate-validate, constraints-validate] timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind @@ -404,7 +404,7 @@ jobs: needs: [docker-build, compose-validate] timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install agmind + dev run: | "$HOME/.local/bin/uv" --version @@ -458,7 +458,7 @@ jobs: needs: [schema-validate] timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind + dev @@ -500,7 +500,7 @@ jobs: matrix: backend: [vulkan, rocm] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Build base + ${{ matrix.backend }} image (self-contained on this runner) run: | docker build -f docker/Dockerfile.base -t agmind-base:ci . diff --git a/.github/workflows/kubernetes-proof.yml b/.github/workflows/kubernetes-proof.yml index b5e90215..cfc197a6 100644 --- a/.github/workflows/kubernetes-proof.yml +++ b/.github/workflows/kubernetes-proof.yml @@ -36,7 +36,7 @@ jobs: github.event.pull_request.head.repo.full_name == github.repository) timeout-minutes: 30 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install agmind + dev deps run: | diff --git a/.github/workflows/perf-nightly.yml b/.github/workflows/perf-nightly.yml index 1dbca5df..56e5d4ce 100644 --- a/.github/workflows/perf-nightly.yml +++ b/.github/workflows/perf-nightly.yml @@ -39,7 +39,7 @@ jobs: runs-on: [self-hosted, linux, x64, strix-halo] timeout-minutes: 20 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — no dependency on a pre-provisioned runner) run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Install agmind + dev deps diff --git a/.github/workflows/promote.yml b/.github/workflows/promote.yml index 431f9a16..7ac864df 100644 --- a/.github/workflows/promote.yml +++ b/.github/workflows/promote.yml @@ -48,7 +48,7 @@ jobs: checks: read # read check-runs for the target SHA actions: read # read workflow runs (for check-run context) steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: fetch-depth: 0 # Do NOT set `ref:` to the input SHA. actions/checkout@v6 resolves `ref` as a diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index c549607c..f025c486 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -28,6 +28,6 @@ jobs: # SHA-pinned (review LOW ci-actions-mutable-tag-pins): this job runs on # pull_request_target with contents+pull-requests write — a force-moved tag would inject # code into a token-bearing job. Dependabot (github-actions) bumps the pin via the # v7. - - uses: release-drafter/release-drafter@693d20e7c1ce1a81d3a41962f85914253b518449 # v7 + - uses: release-drafter/release-drafter@34d80673e067bdc0c24568d3af899c216adcfaa9 # v7 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 787539fa..6e5d24e9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -49,7 +49,7 @@ jobs: version: ${{ steps.v.outputs.version }} tag: ${{ github.ref_name }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install package (version check only) run: | python -m pip install --quiet --no-deps -e . @@ -130,16 +130,16 @@ jobs: outputs: digest: ${{ steps.build.outputs.digest }} steps: - - uses: actions/checkout@v6 - - uses: docker/setup-buildx-action@v3 - - uses: docker/login-action@v3 + - uses: actions/checkout@v7 + - uses: docker/setup-buildx-action@v4 + - uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - id: build name: Build (and push if PUBLISH) - uses: docker/build-push-action@v6 + uses: docker/build-push-action@v7 with: context: . file: docker/Dockerfile.base @@ -154,7 +154,7 @@ jobs: - name: Generate SPDX SBOM for base # SHA-pinned (review LOW ci-actions-mutable-tag-pins); Dependabot bumps via the # v0.22.0. - uses: anchore/sbom-action@62ad5284b8ced813296287a0b63906cb364b73ee # v0.22.0 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: image: ${{ env.IMAGE_NS }}-base@${{ steps.build.outputs.digest }} format: spdx-json @@ -168,7 +168,7 @@ jobs: # transitive critical CVE. Tightening to fail-build later is a deliberate follow-up, not a # silent default. # SHA-pinned (review LOW ci-actions-mutable-tag-pins); Dependabot bumps via the # v7.4.0. - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0 + uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2 with: sbom: sbom-base.spdx.json fail-build: false @@ -177,7 +177,7 @@ jobs: - name: Attest base image provenance (SLSA) if: vars.PUBLISH == 'true' - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-name: ${{ env.IMAGE_NS }}-base subject-digest: ${{ steps.build.outputs.digest }} @@ -211,16 +211,16 @@ jobs: matrix: backend: [cpu, vulkan, rocm] steps: - - uses: actions/checkout@v6 - - uses: docker/setup-buildx-action@v3 - - uses: docker/login-action@v3 + - uses: actions/checkout@v7 + - uses: docker/setup-buildx-action@v4 + - uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - id: build name: Build ${{ matrix.backend }} (and push if PUBLISH) - uses: docker/build-push-action@v6 + uses: docker/build-push-action@v7 with: context: . file: docker/Dockerfile.${{ matrix.backend }} @@ -236,7 +236,7 @@ jobs: - name: Generate SPDX SBOM for ${{ matrix.backend }} # SHA-pinned (review LOW ci-actions-mutable-tag-pins); Dependabot bumps via the # v0.22.0. - uses: anchore/sbom-action@62ad5284b8ced813296287a0b63906cb364b73ee # v0.22.0 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: image: ${{ env.IMAGE_NS }}-${{ matrix.backend }}@${{ steps.build.outputs.digest }} format: spdx-json @@ -250,7 +250,7 @@ jobs: # transitive critical CVE. Tightening to fail-build later is a deliberate follow-up, not a # silent default. # SHA-pinned (review LOW ci-actions-mutable-tag-pins); Dependabot bumps via the # v7.4.0. - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0 + uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2 with: sbom: sbom-${{ matrix.backend }}.spdx.json fail-build: false @@ -259,7 +259,7 @@ jobs: - name: Attest ${{ matrix.backend }} image provenance (SLSA) if: vars.PUBLISH == 'true' - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-name: ${{ env.IMAGE_NS }}-${{ matrix.backend }} subject-digest: ${{ steps.build.outputs.digest }} @@ -289,8 +289,8 @@ jobs: id-token: write attestations: write steps: - - uses: actions/checkout@v6 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - name: Build wheel + sdist @@ -306,7 +306,7 @@ jobs: -p . agmind/__main__.py mv dist/agmind dist/agmind-linux-amd64 - name: Attest wheel + binary provenance (SLSA) - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-path: | dist/*.whl @@ -329,14 +329,14 @@ jobs: id-token: write attestations: write steps: - - uses: actions/checkout@v6 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - name: Install agmind run: pip install -e . - name: Download backend digest + SBOM artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: pattern: backend-* path: backends @@ -366,7 +366,7 @@ jobs: sha256sum * > checksums-${VER}.txt - name: Attest catalog provenance (SLSA) - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-path: release/catalog-${{ needs.meta.outputs.version }}.json @@ -387,12 +387,12 @@ jobs: contents: write # create the GitHub Release steps: - name: Download all release artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: path: all - name: Publish GitHub Release # SHA-pinned (review LOW ci-actions-mutable-tag-pins); Dependabot bumps via the # v2. - uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2 + uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2 with: tag_name: ${{ needs.meta.outputs.tag }} generate_release_notes: true diff --git a/.github/workflows/rendered-diff.yml b/.github/workflows/rendered-diff.yml index 1f4f6d36..6cd28dd5 100644 --- a/.github/workflows/rendered-diff.yml +++ b/.github/workflows/rendered-diff.yml @@ -26,12 +26,12 @@ jobs: timeout-minutes: 15 steps: - name: Checkout head tree - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: path: head ref: ${{ github.event.pull_request.head.sha }} - name: Checkout base tree - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: path: base ref: ${{ github.event.pull_request.base.sha }} @@ -68,7 +68,7 @@ jobs: cat "$GITHUB_WORKSPACE/rendered-diff.md" - name: Post/update sticky PR comment continue-on-error: true - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: REPORT_PATH: ${{ github.workspace }}/rendered-diff.md with: diff --git a/.github/workflows/version-check.yml b/.github/workflows/version-check.yml index 934aa099..3293f356 100644 --- a/.github/workflows/version-check.yml +++ b/.github/workflows/version-check.yml @@ -30,7 +30,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Install uv (fresh — ubuntu-latest has no pre-provisioned uv) run: curl -LsSf https://astral.sh/uv/install.sh | sh