-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): bump the github-actions group with 9 updates#484
chore(deps): bump the github-actions group with 9 updates#484mergify[bot] merged 1 commit intomainfrom
Conversation
Bumps the github-actions group with 9 updates:
| Package | From | To |
|---|---|---|
| actions/checkout | 6.0.0 |
6.0.1 |
| actions/setup-java | 5.0.0 |
5.1.0 |
| graalvm/setup-graalvm | 1.4.3 |
1.4.4 |
| softprops/action-gh-release | 2.4.2 |
2.5.0 |
| github/codeql-action | 4.31.5 |
4.31.7 |
| peter-evans/create-pull-request | 7.0.9 |
7.0.11 |
| ruby/setup-ruby | 1.268.0 |
1.269.0 |
| updatecli/updatecli-action | 2.96.0 |
2.97.0 |
| actions/setup-node | 6.0.0 |
6.1.0 |
Updates actions/checkout from 6.0.0 to 6.0.1
Release notes
Sourced from actions/checkout's releases.
v6.0.1
What's Changed
- Update all references from v5 and v4 to v6 by
@ ericsciplein actions/checkout#2314- Add worktree support for persist-credentials includeIf by
@ ericsciplein actions/checkout#2327- Clarify v6 README by
@ ericsciplein actions/checkout#2328Full Changelog: actions/checkout@v6...v6.0.1
Commits
Updates actions/setup-java from 5.0.0 to 5.1.0
Release notes
Sourced from actions/setup-java's releases.
v5.1.0
What's Changed
New Features
- Add support for
.sdkmanrcfile injava-version-fileparameter by@ guicamestin actions/setup-java#736- Add support for Microsoft OpenJDK 25 builds by
@ the-modin actions/setup-java#927Bug Fixes & Improvements
- Update Regex to Support All ASDF Versions for the supported distributions in tool-versions File by
@ aparnajyothi-yin actions/setup-java#767- Enhance error logging for network failures to include endpoint/IP details, add retry mechanism and update workflows to use macos-15-intel by
@ priya-kinthaliin actions/setup-java#946- Update SapMachine URLs by
@ RealCLangerin actions/setup-java#955- Add GitHub Token Support for GraalVM and Refactor Code by
@ mahabaleshwarsin actions/setup-java#849Documentation changes
- Update documentation to use checkout and Java v5 by
@ lmvysakhin actions/setup-java#903- Clarify JAVA_HOME and PATH setup in README by
@ chiranjib-swainin actions/setup-java#841Dependency updates
- Upgrade prettier from 2.8.8 to 3.6.2 and document breaking changes in v5 by
@ dependabotin actions/setup-java#873- Upgrade actions/publish-action from 0.3.0 to 0.4.0 by
@ dependabotin actions/setup-java#912New Contributors
@ lmvysakhmade their first contribution in actions/setup-java#903@ chiranjib-swainmade their first contribution in actions/setup-java#841@ the-modmade their first contribution in actions/setup-java#927@ priya-kinthalimade their first contribution in actions/setup-java#946@ guicamestmade their first contribution in actions/setup-java#736Full Changelog: actions/setup-java@v5...v5.1.0
Commits
f2beeb2Bump actions/publish-action from 0.3.0 to 0.4.0 (#912)4e7e684feat: Add support for.sdkmanrcfile injava-version-fileparameter (#736)46c56d6Add GitHub Token Support for GraalVM and Refactor Code (#849)66b9457Update SapMachine URLs (#955)6ba5449Enhance error logging for network failures to include endpoint/IP details, ad...de5a937adds microsoft openjdk25 builds (#927)ead9eaaUpdate Regex to Support All ASDF Versions for the supported distributions in ...8c57fa3Clarify JAVA_HOME and PATH setup in README (#841)a7ab372Bump prettier from 2.8.8 to 3.6.2 (#873)d0351b4Update documentation to use checkout and Java v5 (#903)- See full diff in compare view
Updates graalvm/setup-graalvm from 1.4.3 to 1.4.4
Release notes
Sourced from graalvm/setup-graalvm's releases.
v1.4.4
What's Changed
- Bump actions/checkout from 5.0.0 to 6.0.0 in the github-actions-updates group by
@ dependabot[bot] in graalvm/setup-graalvm#198- Bump the npm-updates group with 10 updates by
@ dependabot[bot] in graalvm/setup-graalvm#197Full Changelog: graalvm/setup-graalvm@v1.4.3...v1.4.4
Commits
Updates softprops/action-gh-release from 2.4.2 to 2.5.0
Release notes
Sourced from softprops/action-gh-release's releases.
v2.5.0
What's Changed
Exciting New Features
- feat: mark release as draft until all artifacts are uploaded by
@ dumbmoronin softprops/action-gh-release#692Other Changes
- chore(deps): bump the npm group across 1 directory with 5 updates by
@ dependabot[bot] in softprops/action-gh-release#697- chore(deps): bump actions/checkout from 5.0.0 to 5.0.1 in the github-actions group by
@ dependabot[bot] in softprops/action-gh-release#689New Contributors
@ dumbmoronmade their first contribution in softprops/action-gh-release#692Full Changelog: softprops/action-gh-release@v2.4.2...v2.5.0
Changelog
Sourced from softprops/action-gh-release's changelog.
2.5.0
What's Changed
Exciting New Features
- feat: mark release as draft until all artifacts are uploaded by
@ dumbmoronin softprops/action-gh-release#692Other Changes
- dependency updates
2.4.2
What's Changed
Exciting New Features
- feat: Ensure generated release notes cannot be over 125000 characters by
@ BeryJuin softprops/action-gh-release#684Other Changes
- dependency updates
2.4.1
What's Changed
Other Changes
- fix(util): support brace expansion globs containing commas in parseInputFiles by
@ Copilotin softprops/action-gh-release#672- fix: gracefully fallback to body when body_path cannot be read by
@ Copilotin softprops/action-gh-release#6712.4.0
What's Changed
Exciting New Features
- feat(action): respect working_directory for files globs by
@ stephenwayin softprops/action-gh-release#6672.3.4
What's Changed
Bug fixes
- fix(action): handle 422 already_exists race condition by
@ stephenwayin softprops/action-gh-release#665Other Changes
... (truncated)
Commits
Updates github/codeql-action from 4.31.5 to 4.31.7
Release notes
Sourced from github/codeql-action's releases.
v4.31.7
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.7 - 05 Dec 2025
- Update default CodeQL bundle version to 2.23.7. #3343
See the full CHANGELOG.md for more information.
v4.31.6
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.6 - 01 Dec 2025
No user facing changes.
See the full CHANGELOG.md for more information.
Changelog
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.31.7 - 05 Dec 2025
- Update default CodeQL bundle version to 2.23.7. #3343
4.31.6 - 01 Dec 2025
No user facing changes.
4.31.5 - 24 Nov 2025
- Update default CodeQL bundle version to 2.23.6. #3321
4.31.4 - 18 Nov 2025
No user facing changes.
4.31.3 - 13 Nov 2025
- CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
- Update default CodeQL bundle version to 2.23.5. #3288
4.31.2 - 30 Oct 2025
No user facing changes.
4.31.1 - 30 Oct 2025
- The
add-snippetsinput has been removed from theanalyzeaction. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.4.31.0 - 24 Oct 2025
- Bump minimum CodeQL bundle version to 2.17.6. #3223
- When SARIF files are uploaded by the
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #32224.30.9 - 17 Oct 2025
- Update default CodeQL bundle version to 2.23.3. #3205
- Experimental: A new
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #32044.30.8 - 10 Oct 2025
No user facing changes.
... (truncated)
Commits
cf1bb45Merge pull request #3344 from github/update-v4.31.7-f5c63faddf4ebe95Update changelog for v4.31.7f5c63faMerge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7a2c01e7Add changelog noteac34c13Update default bundle to codeql-bundle-v2.23.7267c467Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d264...aeabef7Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b078357d3Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-testsd61a6faUpdate CLI config test to account for overlay db changes on PRsce27e95Rebuild- Additional commits viewable in compare view
Updates peter-evans/create-pull-request from 7.0.9 to 7.0.11
Release notes
Sourced from peter-evans/create-pull-request's releases.
Create Pull Request v7.0.11
What's Changed
- fix: restrict remote prune to self-hosted runners by
@ peter-evansin peter-evans/create-pull-request#4250Full Changelog: peter-evans/create-pull-request@v7.0.10...v7.0.11
Create Pull Request v7.0.10
Fixes an issue where updating a pull request failed when targeting a forked repository with the same owner as its parent.
What's Changed
- build(deps): bump the github-actions group with 2 updates by
@ dependabot[bot] in peter-evans/create-pull-request#4235- build(deps-dev): bump prettier from 3.6.2 to 3.7.3 in the npm group by
@ dependabot[bot] in peter-evans/create-pull-request#4240- fix: provider list pulls fallback for multi fork same owner by
@ peter-evansin peter-evans/create-pull-request#4245New Contributors
@ obnyismade their first contribution in peter-evans/create-pull-request#4064Full Changelog: peter-evans/create-pull-request@v7.0.9...v7.0.10
Commits
22a9089fix: restrict remote prune to self-hosted runners (#4250)d4f3be6fix: provider list pulls fallback for multi fork same owner (#4245)bc8a47fbuild(deps-dev): bump prettier from 3.6.2 to 3.7.3 in the npm group (#4240)a67ef28build(deps): bump the github-actions group with 2 updates (#4235)- See full diff in compare view
Updates ruby/setup-ruby from 1.268.0 to 1.269.0
Release notes
Sourced from ruby/setup-ruby's releases.
v1.269.0
What's Changed
- Account for Bundler 4 by
@ eregonin ruby/setup-ruby#832Full Changelog: ruby/setup-ruby@v1.268.0...v1.269.0
Commits
d697be2Account for Bundler 4- See full diff in compare view
Updates updatecli/updatecli-action from 2.96.0 to 2.97.0
Release notes
Sourced from updatecli/updatecli-action's releases.
v2.97.0
Changes
- deps: update updatecli version to v0.111.0 @updateclibot[bot] (#986)
- deps(updatecli/policies): bump all policies @updateclibot[bot] (#985)
Maintenance
- deps: bump Updatecli GH action to v2.96.0 @updateclibot[bot] (#982)
Contributors
@ updateclibot[bot] and updateclibot[bot]
Commits
Updates actions/setup-node from 6.0.0 to 6.1.0
Release notes
Sourced from actions/setup-node's releases.
v6.1.0
What's Changed
Enhancement:
- Remove always-auth configuration handling by
@ priyagupta108in actions/setup-node#1436Dependency updates:
- Upgrade
@ actions/cachefrom 4.0.3 to 4.1.0 by@ dependabot[bot] in actions/setup-node#1384- Upgrade actions/checkout from 5 to 6 by
@ dependabot[bot] in actions/setup-node#1439- Upgrade js-yaml from 3.14.1 to 3.14.2 by
@ dependabot[bot] in actions/setup-node#1435Documentation update:
- Add example for restore-only cache in documentation by
@ aparnajyothi-yin actions/setup-node#1419Full Changelog: actions/setup-node@v6...v6.1.0
Commits
395ad32Bump js-yaml from 3.14.1 to 3.14.2 (#1435)a4d2e2bBump actions/checkout from 5 to 6 (#1439)b9b25d4Remove always-auth configuration handling from action (#1436)633bb92Bump@ actions/cachefrom 4.0.3 to 4.1.0 (#1384)dda4788Add example for restore-only cache in documentation (#1419)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot showwill show all of the ignore conditions of the specified dependencyignore conditions @dependabot ignorewill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)major version @dependabot ignorewill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)minor version @dependabot ignorewill close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignorewill remove all of the ignore conditions of the specified dependency@dependabot unignorewill remove the ignore condition of the specified dependency and ignore conditions
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.0` | `6.0.1` |
| [actions/setup-java](https://github.com/actions/setup-java) | `5.0.0` | `5.1.0` |
| [graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm) | `1.4.3` | `1.4.4` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.4.2` | `2.5.0` |
| [github/codeql-action](https://github.com/github/codeql-action) | `4.31.5` | `4.31.7` |
| [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.9` | `7.0.11` |
| [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.268.0` | `1.269.0` |
| [updatecli/updatecli-action](https://github.com/updatecli/updatecli-action) | `2.96.0` | `2.97.0` |
| [actions/setup-node](https://github.com/actions/setup-node) | `6.0.0` | `6.1.0` |
Updates `actions/checkout` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@1af3b93...8e8c483)
Updates `actions/setup-java` from 5.0.0 to 5.1.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@dded088...f2beeb2)
Updates `graalvm/setup-graalvm` from 1.4.3 to 1.4.4
- [Release notes](https://github.com/graalvm/setup-graalvm/releases)
- [Commits](graalvm/setup-graalvm@dec5790...790e289)
Updates `softprops/action-gh-release` from 2.4.2 to 2.5.0
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@5be0e66...a06a81a)
Updates `github/codeql-action` from 4.31.5 to 4.31.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@fdbfb4d...cf1bb45)
Updates `peter-evans/create-pull-request` from 7.0.9 to 7.0.11
- [Release notes](https://github.com/peter-evans/create-pull-request/releases)
- [Commits](peter-evans/create-pull-request@84ae59a...22a9089)
Updates `ruby/setup-ruby` from 1.268.0 to 1.269.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@8aeb6ff...d697be2)
Updates `updatecli/updatecli-action` from 2.96.0 to 2.97.0
- [Release notes](https://github.com/updatecli/updatecli-action/releases)
- [Commits](updatecli/updatecli-action@5ca3636...9a21b69)
Updates `actions/setup-node` from 6.0.0 to 6.1.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@2028fbc...395ad32)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: actions/setup-java
dependency-version: 5.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: graalvm/setup-graalvm
dependency-version: 1.4.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: softprops/action-gh-release
dependency-version: 2.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action
dependency-version: 4.31.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: peter-evans/create-pull-request
dependency-version: 7.0.11
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: ruby/setup-ruby
dependency-version: 1.269.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: updatecli/updatecli-action
dependency-version: 2.97.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/setup-node
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot]
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.12.0 to 4.0.0.
Release notes
*Sourced from [docker/setup-buildx-action's releases](https://github.com/docker/setup-buildx-action/releases).*
> v4.0.0
> ------
>
> * Node 24 as default runtime (requires [Actions Runner v2.327.1](https://github.com/actions/runner/releases/tag/v2.327.1) or later) by [`@ crazy-max`](https://github.com/crazy-max) in [docker/setup-buildx-action#483](https://redirect.github.com/docker/setup-buildx-action/pull/483)
> * Remove deprecated inputs/outputs by [`@ crazy-max`](https://github.com/crazy-max) in [docker/setup-buildx-action#464](https://redirect.github.com/docker/setup-buildx-action/pull/464)
> * Switch to ESM and update config/test wiring by [`@ crazy-max`](https://github.com/crazy-max) in [docker/setup-buildx-action#481](https://redirect.github.com/docker/setup-buildx-action/pull/481)
> * Bump `@ actions/core` from 1.11.1 to 3.0.0 in [docker/setup-buildx-action#475](https://redirect.github.com/docker/setup-buildx-action/pull/475)
> * Bump `@ docker/actions-toolkit` from 0.63.0 to 0.79.0 in [docker/setup-buildx-action#482](https://redirect.github.com/docker/setup-buildx-action/pull/482) [docker/setup-buildx-action#485](https://redirect.github.com/docker/setup-buildx-action/pull/485)
> * Bump js-yaml from 4.1.0 to 4.1.1 in [docker/setup-buildx-action#452](https://redirect.github.com/docker/setup-buildx-action/pull/452)
> * Bump lodash from 4.17.21 to 4.17.23 in [docker/setup-buildx-action#472](https://redirect.github.com/docker/setup-buildx-action/pull/472)
> * Bump minimatch from 3.1.2 to 3.1.5 in [docker/setup-buildx-action#480](https://redirect.github.com/docker/setup-buildx-action/pull/480)
>
> **Full Changelog**: <docker/setup-buildx-action@v3.12.0...v4.0.0>
Commits
* [`4d04d5d`](docker/setup-buildx-action@4d04d5d) Merge pull request [#485](https://redirect.github.com/docker/setup-buildx-action/issues/485) from docker/dependabot/npm\_and\_yarn/docker/actions-to...
* [`cd74e05`](docker/setup-buildx-action@cd74e05) chore: update generated content
* [`eee38ec`](docker/setup-buildx-action@eee38ec) build(deps): bump `@ docker/actions-toolkit` from 0.77.0 to 0.79.0
* [`7a83f65`](docker/setup-buildx-action@7a83f65) Merge pull request [#484](https://redirect.github.com/docker/setup-buildx-action/issues/484) from docker/dependabot/github\_actions/docker/setup-qe...
* [`a5aa967`](docker/setup-buildx-action@a5aa967) Merge pull request [#464](https://redirect.github.com/docker/setup-buildx-action/issues/464) from crazy-max/rm-deprecated
* [`e73d53f`](docker/setup-buildx-action@e73d53f) build(deps): bump docker/setup-qemu-action from 3 to 4
* [`28a438e`](docker/setup-buildx-action@28a438e) Merge pull request [#483](https://redirect.github.com/docker/setup-buildx-action/issues/483) from crazy-max/node24
* [`034e9d3`](docker/setup-buildx-action@034e9d3) chore: update generated content
* [`b4664d8`](docker/setup-buildx-action@b4664d8) remove deprecated inputs/outputs
* [`a8257de`](docker/setup-buildx-action@a8257de) node 24 as default runtime
* Additional commits viewable in [compare view](docker/setup-buildx-action@8d2750c...4d04d5d)
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)