Skip to content

ci(deps): bump the github-actions-patch-minor group with 5 updates - #540

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-patch-minor-b905baefa9
Open

ci(deps): bump the github-actions-patch-minor group with 5 updates#540
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-patch-minor-b905baefa9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown

Bumps the github-actions-patch-minor group with 5 updates:

Package From To
awalsh128/cache-apt-pkgs-action 1.5.3 1.6.3
taiki-e/install-action 2.75.18 2.83.2
EmbarkStudios/cargo-deny-action 2.0.17 2.1.1
useblacksmith/setup-docker-builder 1.7.0 1.10.0
astral-sh/setup-uv 8.1.0 8.3.2

Updates awalsh128/cache-apt-pkgs-action from 1.5.3 to 1.6.3

Release notes

Sourced from awalsh128/cache-apt-pkgs-action's releases.

v.1.6.3

What's Changed

New Contributors

Full Changelog: awalsh128/cache-apt-pkgs-action@v1.6.2...v1.6.3

v1.6.1

What's Changed

New Contributors

Full Changelog: awalsh128/cache-apt-pkgs-action@v1.5.4...v1.6.1

v1.6.0

What's Changed

New Contributors

Full Changelog: awalsh128/cache-apt-pkgs-action@v1.5.2...v1.5.4

Commits
  • 553a35b Refactor: extract ARCH_DIRS array to eliminate duplication in consolidate-rel...
  • aecf4c4 Fix create-release CI failure: consolidate release artifacts and restrict to ...
  • 9f817f3 Merge branch 'master' of https://github.com/awalsh128/cache-apt-pkgs-action
  • c107d98 Bump all action dependency versions and pin them
  • b3b266d fix: ensure create-release job is skipped in dry-run (workflow_call) mode
  • 5602509 fix: address code review feedback in distribute.sh
  • a50a475 fix: create scripts/distribute.sh for build-distribute workflow
  • 869c1d6 Revert "add shellcheck linting"
  • 22ad28f Update README with deprecation notice for 'latest'
  • b9c7b1c Fix version labels and update action version references
  • Additional commits viewable in compare view

Updates taiki-e/install-action from 2.75.18 to 2.83.2

Release notes

Sourced from taiki-e/install-action's releases.

2.83.2

  • Update parse-dockerfile@latest to 0.1.8.

  • Update mise@latest to 2026.7.5.

  • Update just@latest to 1.56.0.

  • Update gungraun-runner@latest to 0.19.4.

  • Update cargo-neat@latest to 0.4.1.

2.83.1

  • Update rclone@latest to 1.74.4.

  • Update mise@latest to 2026.7.4.

  • Update cargo-deny@latest to 0.20.2.

2.83.0

  • Support cargo-about. (#1924, thanks @​ruffsl)

  • Update uv@latest to 0.11.28.

  • Update martin@latest to 1.12.0.

  • Update kingfisher@latest to 1.106.0.

  • Update biome@latest to 2.5.3.

2.82.11

  • Update wasm-tools@latest to 1.253.0.

  • Update uv@latest to 0.11.27.

  • Update mise@latest to 2026.7.2.

  • Update mdbook@latest to 0.5.4.

2.82.10

  • Update tombi@latest to 1.2.0.

  • Update cargo-nextest@latest to 0.9.140.

2.82.9

  • Update vacuum@latest to 0.29.9.

  • Update prek@latest to 0.4.8.

  • Update cargo-tarpaulin@latest to 0.37.0.

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.85.3] - 2026-07-28

  • Update xh@latest to 0.26.2.

  • Update ubi@latest to 0.10.0.

  • Update mise@latest to 2026.7.14.

  • Update martin@latest to 1.13.0.

  • Update cargo-shear@latest to 1.13.3.

  • Update cargo-binstall@latest to 1.21.1.

[2.85.2] - 2026-07-26

  • Update prek@latest to 0.4.11.

  • Update mise@latest to 2026.7.13.

  • Update kingfisher@latest to 1.109.0.

[2.85.1] - 2026-07-25

  • Update vacuum@latest to 0.30.0.

  • Update uv@latest to 0.11.32.

  • Update mise@latest to 2026.7.12.

  • Update cyclonedx@latest to 0.33.1.

  • Update cargo-neat@latest to 0.5.2.

[2.85.0] - 2026-07-23

  • Support wild (alias: wild-linker). (#1949)

... (truncated)

Commits
  • 43aecc8 Release 2.83.2
  • fca4789 Update prek manifest
  • b41cc1f Update parse-dockerfile@latest to 0.1.8
  • 8d866f8 Update mise@latest to 2026.7.5
  • 7ebe462 Update just@latest to 1.56.0
  • 01ab563 Update gungraun-runner@latest to 0.19.4
  • f164a68 Update cargo-neat@latest to 0.4.1
  • 2ca9b94 Release 2.83.1
  • 8598f86 Update parse-dockerfile manifest
  • 76cfe4d Update rclone@latest to 1.74.4
  • Additional commits viewable in compare view

Updates EmbarkStudios/cargo-deny-action from 2.0.17 to 2.1.1

Commits

Updates useblacksmith/setup-docker-builder from 1.7.0 to 1.10.0

Release notes

Sourced from useblacksmith/setup-docker-builder's releases.

v1.10.0

What's Changed

Other Changes

New Contributors

Full Changelog: useblacksmith/setup-docker-builder@v1.9.0...v1.10.0

v1.9.0

What's Changed

Other Changes

Full Changelog: useblacksmith/setup-docker-builder@v1.8.0...v1.9.0

v1.8.0

What's Changed

Fixes

Other Changes

New Contributors

Full Changelog: useblacksmith/setup-docker-builder@v1.7.0...v1.8.0

Commits
  • 5fe3b77 improve observability and readiness timeout for buildkitd startup (#112)
  • ab5c1da fix: keep docker mirror on local builder fallback (#105)
  • 722e97d fix: prevent ~30s hangs in setup and post steps (#99)
  • 86ab255 Update GitHub Action versions to latest majors (#96)
  • See full diff in compare view

Updates astral-sh/setup-uv from 8.1.0 to 8.3.2

Release notes

Sourced from astral-sh/setup-uv's releases.

v8.2.0 🌈 New inputs quiet and download-from-astral-mirror

Changes

This release brings two new inputs and a few bug fixes.

New inputs

Lets talk about the new inputs first.

quiet

Pretty simple. It turns of all info loggings. Useful if you use this in a composite action and are not interested in all the details. In the upcoming releases we will add log groups to fully implement support for "less noise"

[!NOTE]
Warnings and errors are always logged.

download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting download-from-astral-mirror: false allows you to do that.

Bugfixes

When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token. All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

... (truncated)

Commits
  • 11f9893 chore: roll up Dependabot updates (#948)
  • f798556 docs: update version references to v8.3.1 (#946)
  • e80544d chore: update known checksums for 0.11.28 (#947)
  • f98e069 Change update-docs PR labels from 'update-docs' to 'documentation' (#945)
  • cd46263 chore: update known checksums for 0.11.27 (#944)
  • 11245c7 docs: update version references to v8.3.0 (#939)
  • d31148d Strip environment markers from detected uv dependency pins (#938)
  • 17c3989 Fix cache keys for Python version ranges (#937)
  • 3cc3c11 chore(deps): roll up Dependabot updates (#936)
  • 9225f84 chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (#924)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-patch-minor group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action) | `1.5.3` | `1.6.3` |
| [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.75.18` | `2.83.2` |
| [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `2.0.17` | `2.1.1` |
| [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder) | `1.7.0` | `1.10.0` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.1.0` | `8.3.2` |


Updates `awalsh128/cache-apt-pkgs-action` from 1.5.3 to 1.6.3
- [Release notes](https://github.com/awalsh128/cache-apt-pkgs-action/releases)
- [Commits](awalsh128/cache-apt-pkgs-action@2c09a5e...553a35b)

Updates `taiki-e/install-action` from 2.75.18 to 2.83.2
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@055f5df...43aecc8)

Updates `EmbarkStudios/cargo-deny-action` from 2.0.17 to 2.1.1
- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)
- [Commits](EmbarkStudios/cargo-deny-action@91bf2b6...3c63498)

Updates `useblacksmith/setup-docker-builder` from 1.7.0 to 1.10.0
- [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases)
- [Commits](useblacksmith/setup-docker-builder@ac083cc...5fe3b77)

Updates `astral-sh/setup-uv` from 8.1.0 to 8.3.2
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@0880764...11f9893)

---
updated-dependencies:
- dependency-name: awalsh128/cache-apt-pkgs-action
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-patch-minor
- dependency-name: taiki-e/install-action
  dependency-version: 2.83.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-patch-minor
- dependency-name: EmbarkStudios/cargo-deny-action
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-patch-minor
- dependency-name: useblacksmith/setup-docker-builder
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-patch-minor
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.3.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@covenant-talos

Copy link
Copy Markdown

Walkthrough

This Dependabot PR bumps five third-party GitHub Actions used across the CI workflow to their latest patch/minor releases. All changes are version-pinning updates in .github/workflows/ci.yml, touching the apt package cache, cargo-nextest installer, cargo-deny action, Blacksmith Docker builder setup, and uv installer steps. No application code or workflow logic is altered.

Changes

Cohort / File(s) Change Summary
CI dependency bumps — .github/workflows/ci.yml Updates pinned SHAs for awalsh128/cache-apt-pkgs-action (1.5.3→1.6.3), taiki-e/install-action (2.75.18→2.83.2), EmbarkStudios/cargo-deny-action (2.0.17→2.1.1), useblacksmith/setup-docker-builder (1.7.0→1.10.0), and astral-sh/setup-uv (8.1.0→8.3.2) across all jobs that reference them.

Estimated review effort: 1/5 (routine Dependabot version bumps with no logic changes)

Instant overview - a deep technical review follows as a separate comment.

@covenant-talos

Copy link
Copy Markdown

PR #540: ci(deps): bump the github-actions-patch-minor group with 5 updates (by dependabot[bot])

Summary

Dependabot bumps five third-party GitHub Actions used in .github/workflows/ci.yml: awalsh128/cache-apt-pkgs-action (1.5.3 → 1.6.3), taiki-e/install-action (2.75.18 → 2.83.2), EmbarkStudios/cargo-deny-action (2.0.17 → 2.1.1), useblacksmith/setup-docker-builder (1.7.0 → 1.10.0), and astral-sh/setup-uv (8.1.0 → 8.3.2). All references remain pinned to full commit SHAs, and every duplicate occurrence across the six CI jobs is updated consistently — no stale pins remain in the diff. The bumps pull in useful fixes, notably a ~30s hang fix in setup-docker-builder and a token-scoping security fix in setup-uv.

Architecture

No structural impact. The change is confined to uses: lines in the existing CI workflow; no jobs, steps, data flows, or trust boundaries are added or removed.

Issues Found

CRITICAL Issues (Must Fix Before Merge)

None found.

HIGH Severity Issues (Advised to Fix Before Merge)

None found.

MEDIUM Severity Issues (Optional to Fix Before Merge)

None found.

LOW Severity Issues (Minor Improvements)

  1. Replace the misleading # latest trailing comments on the cache-apt-pkgs-action pins with the resolved version
    Maintainability & Coherency | LOW | Effort: quick win

    • Why: All six updated lines read uses: awalsh128/cache-apt-pkgs-action@553a35bb8ebd9fcabcb1c9451aa4c98e1b4ca8a9 # latest. For a SHA-pinned action, # latest is meaningless and inconsistent with sibling pins that carry exact versions (cargo-deny-action ... # v2.1.1, setup-uv ... # v8.3.2). Accurate version comments are what make SHA-pinned supply-chain diffs auditable at review time. This is pre-existing, but this PR rewrites those exact lines, so it is the natural moment to fix it.
    • How: Update the comment on each of the six occurrences:
              uses: awalsh128/cache-apt-pkgs-action@553a35bb8ebd9fcabcb1c9451aa4c98e1b4ca8a9 # v1.6.3
      
  2. Confirm runner images support the Node 24 runtime now required by cache-apt-pkgs-action
    Stability & Availability | LOW | Effort: quick win

    • Why: The 1.6.1 release notes state "fix: upgrade actions/cache v4→v5 and upload-artifact v4→v7 (Node 24)". actions/cache v5 executes on the Node 24 runtime, which requires actions-runner ≥ 2.327.1. The workflow runs on Blacksmith infrastructure (evidenced by useblacksmith/setup-docker-builder usage), and I cannot see runner labels or image versions in this diff, so I cannot confirm the runner fleet is new enough. If it lags, the "Cache and install system dependencies" step fails in all six jobs.
    • How: Verify the cache step is green on this PR's own CI run before merging; if it passes, no further action is needed.
  3. Watch the cargo-deny lint job: the action bump also upgrades cargo-deny itself (0.19.x → 0.20.2)
    Testing & Docs | LOW | Effort: quick win

    • Why: The new pin EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 ships cargo-deny 0.20.2 (upstream commits "Bump to 0.20.2", "Deprecate use-git-cli"). A 0.x tool upgrade can enable new lints or deprecate config keys, so command: check may newly fail against the existing deny.toml for reasons unrelated to this repository's code. Confidence in the pin itself is high; the behavior delta is the uncertainty.
    • How: Confirm the lint job passes on this PR; if new findings appear, triage them against the cargo-deny 0.20 changelog rather than reverting the bump.

Security Review

Supply chain is the only meaningful surface in this diff, and it was swept as follows:

  • Action pinning: All five actions remain pinned to full-length commit SHAs, and the new SHAs match the head commits of the claimed releases per Dependabot's commit listings (e.g., 43aecc8 = "Release 2.83.2", 5fe3b77 = v1.10.0 head). Tag-mutation risk is therefore not introduced by this change.
  • Privilege of bumped actions: cache-apt-pkgs-action is the highest-privilege of the five — it runs shell scripts with sudo to install apt packages and writes to the GitHub Actions cache, and it is a single-maintainer project with some Copilot-authored commits. The SHA pin contains this to the reviewed code, but it remains the action to watch in future bumps.
  • Token handling: The setup-uv 8.2.0 bump is a net security improvement — it stops sending the GitHub token to the astral.sh mirror and limits tokens to github.com download URLs ("Limit GitHub tokens to github.com download URLs").
  • Secrets/injection: No secrets are passed to any bumped step in the visible hunks; no run: blocks or expression interpolations were added or modified, so no new injection surface exists.
  • Resource exhaustion: The setup-uv bump adds fetch timeouts ("fix: add timeout to fetch to prevent silent hangs"), and setup-docker-builder 1.8.0 fixes ~30s gRPC session hangs — both reduce CI DoS-by-hang exposure.

No security findings beyond the LOW items above.

Suggestions for Improvements

  • Adopt exact-version trailing comments (# vX.Y.Z) as a convention for all SHA-pinned actions repo-wide, so future Dependabot diffs are self-auditing; Dependabot preserves and updates comments it recognizes as versions.
  • Let this PR's own CI run serve as the validation gate for the two runtime-sensitive bumps (cache-apt-pkgs-action Node 24, cargo-deny 0.20.2) before merging.

Positive Observations

  • SHA pinning is retained for every bumped action — the supply-chain posture is unchanged or improved.
  • Version comments that existed were correctly updated (# v2.1.1, # v8.3.2), and all duplicate occurrences across jobs were bumped in lockstep — no version drift between jobs.
  • The bump set is coherent and conservative (patch/minor only, grouped), and the commit message ci(deps): bump the github-actions-patch-minor group with 5 updates follows Conventional Commits.
  • The update pulls in genuine reliability and security fixes (hang fixes in setup-docker-builder and setup-uv, token scoping in setup-uv) rather than being churn for its own sake.

Recommendation and Next Steps

APPROVE — this is a low-risk, consistently applied, SHA-pinned patch/minor CI dependency bump whose own CI run will validate the two runtime-sensitive changes; the only findings are cosmetic comment inaccuracies and verification reminders.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants