Repository navigation
chore(deps): update non-major github actions - #19
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Vulnerability Scan: Failed — blocking vulnerabilities detectedImage:
Commit: 27ae33d |
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
August 7, 2026 19:53
2271cb1 to
382f14c
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
August 15, 2026 11:42
382f14c to
326b48a
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
2 times, most recently
from
August 29, 2026 07:52
8f2ffc7 to
fd8806d
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
September 12, 2026 11:55
fd8806d to
8116173
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
September 20, 2026 02:56
8116173 to
9dfc399
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
October 2, 2026 04:11
9dfc399 to
8ae367b
Compare
renovate
Bot
force-pushed
the
renovate/non-major-github-actions
branch
from
October 9, 2026 04:11
8ae367b to
77eed3e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.1.0→v4.2.2v6.0.3→v6.1.0v8.0.1→v8.0.2v7.0.1→v7.0.2v8.2.0→v8.3.2v7.2.0→v7.4.0v4.2.0→v4.6.0v4.1.0→v4.4.1v4.36.2→v4.38.3Release Notes
actions/attest-build-provenance (actions/attest-build-provenance)
v4.2.2Compare Source
What's Changed
Full Changelog: actions/attest-build-provenance@v4.1.1...v4.2.2
v4.1.1Compare Source
What's Changed
Full Changelog: actions/attest-build-provenance@v4.1.0...v4.1.1
actions/checkout (actions/checkout)
v6.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v6 by @aiqiaoy in #2500https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: actions/checkout@v6.0.3...v6.1.0
actions/download-artifact (actions/download-artifact)
v8.0.2Compare Source
What's Changed
New Contributors
Full Changelog: actions/download-artifact@v8.0.1...v8.0.2
actions/upload-artifact (actions/upload-artifact)
v7.0.2Compare Source
What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v7.0.1...v7.0.2
astral-sh/setup-uv (astral-sh/setup-uv)
v8.3.2: 🌈 update known checksums for 0.11.28Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.3.1: 🌈 update known checksums for 0.11.27Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
v8.3.0: 🌈 Support uv.lock as a version-file sourceCompare Source
Changes
Thanks to @somaz94 you can now use the pinned version of uv itself in
uv.lock. It gets picked up automatically.If you have pinned another version of uv in your
uv.lockyou can use the inputsversionorversion-sourceto override this.🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
docker/build-push-action (docker/build-push-action)
v7.4.0Compare Source
Full Changelog: docker/build-push-action@v7.3.0...v7.4.0
v7.3.0Compare Source
Full Changelog: docker/build-push-action@v7.2.0...v7.3.0
docker/login-action (docker/login-action)
v4.6.0Compare Source
Full Changelog: docker/login-action@v4.5.2...v4.6.0
v4.5.2Compare Source
Full Changelog: docker/login-action@v4.5.1...v4.5.2
v4.5.1Compare Source
dhi.ioas Docker Hub OIDC registry by @crazy-max in #1054Full Changelog: docker/login-action@v4.5.0...v4.5.1
v4.5.0Compare Source
Full Changelog: docker/login-action@v4.4.0...v4.5.0
v4.4.0Compare Source
registry-authsecret mask by @crazy-max in #1035Full Changelog: docker/login-action@v4.3.0...v4.4.0
v4.3.0Compare Source
Full Changelog: docker/login-action@v4.2.0...v4.3.0
docker/setup-buildx-action (docker/setup-buildx-action)
v4.4.1Compare Source
Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1
v4.4.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0
v4.3.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0
v4.2.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0
github/codeql-action (github/codeql-action)
v4.38.3Compare Source
v4.38.2Compare Source
v4.38.1Compare Source
v4.38.0Compare Source
linux-arm64CodeQL bundle when available. #4072v4.37.9Compare Source
v4.37.8Compare Source
No user facing changes.
v4.37.7Compare Source
v4.37.6Compare Source
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #4070v4.37.5Compare Source
initAction instead of falling back to downloading the bundle before extracting it. #4061v4.37.4Compare Source
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037v4.37.3Compare Source
No user facing changes.
v4.37.2Compare Source
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023v4.37.1Compare Source
v4.37.0Compare Source
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3Compare Source
No user facing changes.
Configuration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.