Skip to content

ci(deps): bump pnpm/action-setup from 4 to 6 - #29

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/action-setup-6
Open

ci(deps): bump pnpm/action-setup from 4 to 6#29
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/action-setup-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown

Bumps pnpm/action-setup from 4 to 6.

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.0

Added support for pnpm v11.

v5.0.0

Updated the action to use Node.js 24.

v4.4.0

Updated the action to use Node.js 24.

v4.3.0

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v4.2.0...v4.3.0

v4.2.0

When there's a .npmrc file at the root of the repository, pnpm will be fetched from the registry that is specified in that .npmrc file #179

v4.1.0

Add support for package.yaml #156.

Commits
  • 0977fd9 docs: Update README to include devEngines.packageManager (#273)
  • 48261ac fix: update pnpm to v11.19.0 (#283)
  • 75677f7 ci: use pnpm 11 for pr-check (#284)
  • 769ae71 refactor: introduce restore keys for cache (#280)
  • 6fed91f docs(README): point users to the successor pnpm/setup action (#282)
  • 0ebf471 fix: update pnpm to v11.7.0 (#267)
  • 0e279bb fix: update pnpm to 11.1.1 (#248)
  • 3e83581 fix: drop patchPnpmEnv so standalone+self-update works on Windows (#258)
  • 551b42e docs(README): fix cache_dependency_path type (#257)
  • 739bfe4 fix: self-update bootstrap to packageManager-pinned version (#233) (#256)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4 to 6.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@v4...v6)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown

bulwark

  • scan — 2 semgrep findings
error output
typescript: using ambient node 22.23.2 (no version declared by this repo)
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
From https://github.com/wardnet/wardnet-status
 * branch            main       -> FETCH_HEAD
e9206f428a184ff01f1e7993d2e718ac16c18e12
creating virtual environment...
installing semgrep from spec 'semgrep==1.168.0'...
done! ✨ 🌟 ✨
  installed package semgrep 1.168.0, installed using Python 3.12.3
  These apps are now available
    - pysemgrep
    - semgrep
               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 3 files tracked by git with 1074 Code rules:
                                                                                                                        
  Language      Rules   Files          Origin      Rules                                                                
 ─────────────────────────────        ───────────────────                                                               
  <multilang>      47       3          Community    1074                                                                
  yaml             35       3                                                                                           
                                                                                                                        
  Current version has 6 findings.

Creating git worktree from 'e9206f428a184ff01f1e7993d2e718ac16c18e12' to scan baseline.
  Will report findings introduced by these commits (may be incomplete for shallow checkouts):
    * 8c9c02e Merge a37cddcd9b4e96f9bf7a62f629b691725e820e5b into e9206f428a184ff01f1e7993d2e718ac16c18e12
    * a37cddc ci(deps): bump pnpm/action-setup from 4 to 6

               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 1 file tracked by git with 1 Code rule:
  Scanning 1 file.
                   
                   
┌─────────────────┐
│ 2 Code Findings │
└─────────────────┘
                                
    .github/workflows/deploy.yml
    ❯❱ yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
          ❰❰ Blocking ❱❱
          GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently   
          repointed by the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-
          github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. `uses: 
          actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`.                                         
          Details: https://sg.run/2LgAL                                                                       
                                                                                                              
           28┆ - uses: pnpm/action-setup@v6
            ⋮┆----------------------------------------
           48┆ - uses: pnpm/action-setup@v6

                
                
┌──────────────┐
│ Scan Summary │
└──────────────┘
✅ Scan completed successfully.
 • Findings: 2 (2 blocking)
 • Rules run: 82
 • Targets scanned: 3
 • Parsed lines: ~100.0%
 • Scan was limited to files changed since baseline commit.
 • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
Ran 82 rules on 3 files: 2 findings.
[PASS] biome(.)
[PASS] biome(./page)
[PASS] biome(./worker)
[FAIL] semgrep
Error: 1 check(s) failed
bulwark: 1 check(s) failed
  • coverage — see error output below

📦 Full bulwark output — complete scan and coverage logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants