Skip to content

chore(deps): update non-major github actions - #19

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-github-actions

Conversation

@renovate

@renovate renovate Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
actions/attest-build-provenance action minor v4.1.0 → v4.2.2
actions/checkout action minor v6.0.3 → v6.1.0
actions/download-artifact action patch v8.0.1 → v8.0.2
actions/upload-artifact action patch v7.0.1 → v7.0.2
astral-sh/setup-uv action minor v8.2.0 → v8.3.2
docker/build-push-action action minor v7.2.0 → v7.4.0
docker/login-action action minor v4.2.0 → v4.6.0
docker/setup-buildx-action action minor v4.1.0 → v4.4.1
github/codeql-action action minor v4.36.2 → v4.38.3

Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v4.2.2

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.1...v4.2.2

v4.1.1

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.0...v4.1.1

actions/checkout (actions/checkout)

v6.1.0

Compare Source

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

actions/download-artifact (actions/download-artifact)

v8.0.2

Compare Source

What's Changed
New Contributors

Full Changelog: actions/download-artifact@v8.0.1...v8.0.2

actions/upload-artifact (actions/upload-artifact)

v7.0.2

Compare Source

What's Changed
  • Improves artifact download retries when the service returns HTTP 429 (rate limiting), including honoring valid Retry-After headers.
  • Updates @​actions/artifact to v6.3.1.
New Contributors

Full Changelog: actions/upload-artifact@v7.0.1...v7.0.2

astral-sh/setup-uv (astral-sh/setup-uv)

v8.3.2: 🌈 update known checksums for 0.11.28

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v8.3.1: 🌈 update known checksums for 0.11.27

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

v8.3.0: 🌈 Support uv.lock as a version-file source

Compare Source

Changes

Thanks to @​somaz94 you can now use the pinned version of uv itself in uv.lock. It gets picked up automatically.
If you have pinned another version of uv in your uv.lock you can use the inputs version or version-source to override this.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

v7.3.0

Compare Source

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

docker/login-action (docker/login-action)

v4.6.0

Compare Source

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Compare Source

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Compare Source

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Compare Source

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Compare Source

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

v4.2.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

github/codeql-action (github/codeql-action)

v4.38.3

Compare Source

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #​4188
  • Update default CodeQL bundle version to 2.27.2. #​4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #​4184

v4.38.2

Compare Source

v4.38.1

Compare Source

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #​4146

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v4.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v4.37.4

Compare Source

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #​4037
  • Update default CodeQL bundle version to 2.26.2. #​4051

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • "before 4am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Aug 5, 2026
@renovate
renovate Bot requested a review from z23 as a code owner August 5, 2026 03:55
@renovate renovate Bot added the dependencies label Aug 5, 2026
@github-actions

github-actions Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Vulnerability Scan: Failed — blocking vulnerabilities detected

Image: netbox-mcp-server:scan

Source Library CVE Severity Installed Fixed Title
netbox-mcp-server:scan (alpine 3.23.4) zlib CVE-2026-85091 🟡 MEDIUM 1.3.2-r0 1.3.2-r1 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...
Python PyJWT CVE-2026-102268 🔴 CRITICAL 2.13.0 2.14.0 PyJWT is a Python implementation of JSON Web Token standards. Prior to ...
Python PyJWT CVE-2026-102266 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Authentication bypass via empty HMAC key acceptance
Python PyJWT CVE-2026-102267 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Verification key substitution via unvalidated JWKS redirects
Python PyJWT CVE-2026-102271 🟠 HIGH 2.13.0 2.14.0 pyjwt: PyJWT: Authentication bypass via acceptance of DER public keys as HMAC se
Python PyJWT CVE-2026-102272 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via improper Unicode byte-order mark handling
Python PyJWT CVE-2026-102273 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via acceptance of public JWK containers as HMAC secr
Python PyJWT CVE-2026-101917 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Denial of Service via outbound request amplification on unknown ke
Python PyJWT CVE-2026-101918 🟡 MEDIUM 2.13.0 2.15.0 pyjwt: PyJWT: Denial of Service via deeply nested JSON token payload
Python PyJWT CVE-2026-102265 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via deeply nested token headers
Python PyJWT CVE-2026-102269 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Token revocation bypass via non-canonical signature decoding
Python PyJWT CVE-2026-102270 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via regular expression backtracking in is_pem_fo
Python PyJWT CVE-2026-102274 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via malformed RSA key in JWK set
Python PyJWT CVE-2026-102275 🟡 MEDIUM 2.13.0 2.15.0 pyjwt: PyJWT: Token verification bypass via mismatched OKP key components
Python anyio CVE-2026-63374 🔴 CRITICAL 4.12.1 4.14.2 anyio: AnyIO: TLS certificate spoofing via improper internationalized domain nam
Python anyio CVE-2026-64847 🟡 MEDIUM 4.12.1 4.14.2 anyio: AnyIO: Denial of Service due to undrained stderr in process-pool workers
Python cryptography CVE-2026-69247 🟠 HIGH 49.0.0 50.0.0 python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption expose
Python pip CVE-2026-13346 🟡 MEDIUM 26.1.2 26.2.0 pip: pip: Arbitrary file installation via malicious package indexes

Commit: 27ae33d

@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from 2271cb1 to 382f14c Compare August 7, 2026 19:53
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from 382f14c to 326b48a Compare August 15, 2026 11:42
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch 2 times, most recently from 8f2ffc7 to fd8806d Compare August 29, 2026 07:52
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from fd8806d to 8116173 Compare September 12, 2026 11:55
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from 8116173 to 9dfc399 Compare September 20, 2026 02:56
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from 9dfc399 to 8ae367b Compare October 2, 2026 04:11
@renovate
renovate Bot force-pushed the renovate/non-major-github-actions branch from 8ae367b to 77eed3e Compare October 9, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants