Skip to content

ci(deps): bump actions/deploy-pages from 4 to 5 - #13

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/deploy-pages-5
Open

ci(deps): bump actions/deploy-pages from 4 to 5#13
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/deploy-pages-5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/deploy-pages from 4 to 5.

Release notes

Sourced from actions/deploy-pages's releases.

v5.0.0

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.5

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.4

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.3

Changelog

... (truncated)

Commits
  • cd2ce8f Merge pull request #404 from salmanmkc/node24
  • bbe2a95 Update Node.js version to 24.x
  • 854d7aa Merge pull request #374 from actions/Jcambass-patch-1
  • 306bb81 Add workflow file for publishing releases to immutable action package
  • b742728 Merge pull request #360 from actions/dependabot/npm_and_yarn/npm_and_yarn-513...
  • 7273294 Bump braces in the npm_and_yarn group across 1 directory
  • 963791f Merge pull request #361 from actions/dependabot-friendly
  • 51bb29d Make the rebuild dist workflow safer for Dependabot
  • 89f3d10 Merge pull request #358 from actions/dependabot/npm_and_yarn/non-breaking-cha...
  • bce7355 Merge branch 'main' into dependabot/npm_and_yarn/non-breaking-changes-99c12deb21
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4 to 5.
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@v4...v5)

---
updated-dependencies:
- dependency-name: actions/deploy-pages
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown

bulwark

  • scan — 1 semgrep findings
error output
typescript: using ambient node 22.23.2 (no version declared by this repo)
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
From https://github.com/wardnet/wardnet-design-system
 * branch            main       -> FETCH_HEAD
afa28d43ec403f9868fa7c3d066df26cd179b236
creating virtual environment...
installing semgrep from spec 'semgrep==1.173.0'...
done! ✨ 🌟 ✨
  installed package semgrep 1.173.0, installed using Python 3.12.3
  These apps are now available
    - pysemgrep
    - semgrep
               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 1 file tracked by git with 1074 Code rules:
                                                                                                                        
  Language      Rules   Files          Origin      Rules                                                                
 ─────────────────────────────        ───────────────────                                                               
  <multilang>      47       1          Community    1074                                                                
  yaml             35       1                                                                                           
                                                                                                                        
  Current version has 5 findings.

Creating git worktree from 'afa28d43ec403f9868fa7c3d066df26cd179b236' to scan baseline.
  Will report findings introduced by these commits (may be incomplete for shallow checkouts):
    * 6c16293 Merge 5081f729de5cfea320d95c6f0fd0b8df3ce5d064 into afa28d43ec403f9868fa7c3d066df26cd179b236
    * 5081f72 ci(deps): bump actions/deploy-pages from 4 to 5

               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 1 file tracked by git with 1 Code rule:
  Scanning 1 file.
                  
                  
┌────────────────┐
│ 1 Code Finding │
└────────────────┘
                                   
    .github/workflows/storybook.yml
    ❯❱ yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
          ❰❰ Blocking ❱❱
          GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently   
          repointed by the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-
          github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. `uses: 
          actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`.                                         
          Details: https://sg.run/2LgAL                                                                       
                                                                                                              
           41┆ uses: actions/deploy-pages@v5

                
                
┌──────────────┐
│ Scan Summary │
└──────────────┘
✅ Scan completed successfully.
 • Findings: 1 (1 blocking)
 • Rules run: 82
 • Targets scanned: 1
 • Parsed lines: ~100.0%
 • Scan was limited to files changed since baseline commit.
 • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
Ran 82 rules on 1 file: 1 finding.
[PASS] biome(.)
[PASS] biome(./packages/brand)
[PASS] biome(./packages/styles)
[PASS] biome(./packages/ui)
[FAIL] semgrep
Error: 1 check(s) failed
bulwark: 1 check(s) failed

📦 Full bulwark output — complete scan and coverage logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants