ci(deps): bump the github-actions-patch-minor group with 5 updates - #540
ci(deps): bump the github-actions-patch-minor group with 5 updates#540dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions-patch-minor group with 5 updates: | Package | From | To | | --- | --- | --- | | [awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action) | `1.5.3` | `1.6.3` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.75.18` | `2.83.2` | | [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `2.0.17` | `2.1.1` | | [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder) | `1.7.0` | `1.10.0` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.1.0` | `8.3.2` | Updates `awalsh128/cache-apt-pkgs-action` from 1.5.3 to 1.6.3 - [Release notes](https://github.com/awalsh128/cache-apt-pkgs-action/releases) - [Commits](awalsh128/cache-apt-pkgs-action@2c09a5e...553a35b) Updates `taiki-e/install-action` from 2.75.18 to 2.83.2 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@055f5df...43aecc8) Updates `EmbarkStudios/cargo-deny-action` from 2.0.17 to 2.1.1 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@91bf2b6...3c63498) Updates `useblacksmith/setup-docker-builder` from 1.7.0 to 1.10.0 - [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases) - [Commits](useblacksmith/setup-docker-builder@ac083cc...5fe3b77) Updates `astral-sh/setup-uv` from 8.1.0 to 8.3.2 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@0880764...11f9893) --- updated-dependencies: - dependency-name: awalsh128/cache-apt-pkgs-action dependency-version: 1.6.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-patch-minor - dependency-name: taiki-e/install-action dependency-version: 2.83.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-patch-minor - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-patch-minor - dependency-name: useblacksmith/setup-docker-builder dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-patch-minor - dependency-name: astral-sh/setup-uv dependency-version: 8.3.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-patch-minor ... Signed-off-by: dependabot[bot] <support@github.com>
WalkthroughThis Dependabot PR bumps five third-party GitHub Actions used across the CI workflow to their latest patch/minor releases. All changes are version-pinning updates in Changes
Estimated review effort: 1/5 (routine Dependabot version bumps with no logic changes) Instant overview - a deep technical review follows as a separate comment. |
PR #540: ci(deps): bump the github-actions-patch-minor group with 5 updates (by dependabot[bot])SummaryDependabot bumps five third-party GitHub Actions used in ArchitectureNo structural impact. The change is confined to Issues FoundCRITICAL Issues (Must Fix Before Merge)None found. HIGH Severity Issues (Advised to Fix Before Merge)None found. MEDIUM Severity Issues (Optional to Fix Before Merge)None found. LOW Severity Issues (Minor Improvements)
Security ReviewSupply chain is the only meaningful surface in this diff, and it was swept as follows:
No security findings beyond the LOW items above. Suggestions for Improvements
Positive Observations
Recommendation and Next StepsAPPROVE — this is a low-risk, consistently applied, SHA-pinned patch/minor CI dependency bump whose own CI run will validate the two runtime-sensitive changes; the only findings are cosmetic comment inaccuracies and verification reminders. |
Bumps the github-actions-patch-minor group with 5 updates:
1.5.31.6.32.75.182.83.22.0.172.1.11.7.01.10.08.1.08.3.2Updates
awalsh128/cache-apt-pkgs-actionfrom 1.5.3 to 1.6.3Release notes
Sourced from awalsh128/cache-apt-pkgs-action's releases.
Commits
553a35bRefactor: extract ARCH_DIRS array to eliminate duplication in consolidate-rel...aecf4c4Fix create-release CI failure: consolidate release artifacts and restrict to ...9f817f3Merge branch 'master' of https://github.com/awalsh128/cache-apt-pkgs-actionc107d98Bump all action dependency versions and pin themb3b266dfix: ensure create-release job is skipped in dry-run (workflow_call) mode5602509fix: address code review feedback in distribute.sha50a475fix: create scripts/distribute.sh for build-distribute workflow869c1d6Revert "add shellcheck linting"22ad28fUpdate README with deprecation notice for 'latest'b9c7b1cFix version labels and update action version referencesUpdates
taiki-e/install-actionfrom 2.75.18 to 2.83.2Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
43aecc8Release 2.83.2fca4789Update prek manifestb41cc1fUpdateparse-dockerfile@latestto 0.1.88d866f8Updatemise@latestto 2026.7.57ebe462Updatejust@latestto 1.56.001ab563Updategungraun-runner@latestto 0.19.4f164a68Updatecargo-neat@latestto 0.4.12ca9b94Release 2.83.18598f86Update parse-dockerfile manifest76cfe4dUpdaterclone@latestto 1.74.4Updates
EmbarkStudios/cargo-deny-actionfrom 2.0.17 to 2.1.1Commits
3c63498Fix use-git-cli deprecation (#116)6f99e34Bump to 0.20.28b229e2Deprecate use-git-clibb137d7Bump to 0.19.8a531616Bump to 0.19.76c8f9faBump to 0.19.5f28dad7Remove mergifye4d1338Add xray to the list of repositories using this action (#105)Updates
useblacksmith/setup-docker-builderfrom 1.7.0 to 1.10.0Release notes
Sourced from useblacksmith/setup-docker-builder's releases.
Commits
5fe3b77improve observability and readiness timeout for buildkitd startup (#112)ab5c1dafix: keep docker mirror on local builder fallback (#105)722e97dfix: prevent ~30s hangs in setup and post steps (#99)86ab255Update GitHub Action versions to latest majors (#96)Updates
astral-sh/setup-uvfrom 8.1.0 to 8.3.2Release notes
Sourced from astral-sh/setup-uv's releases.
... (truncated)
Commits
11f9893chore: roll up Dependabot updates (#948)f798556docs: update version references to v8.3.1 (#946)e80544dchore: update known checksums for 0.11.28 (#947)f98e069Change update-docs PR labels from 'update-docs' to 'documentation' (#945)cd46263chore: update known checksums for 0.11.27 (#944)11245c7docs: update version references to v8.3.0 (#939)d31148dStrip environment markers from detected uv dependency pins (#938)17c3989Fix cache keys for Python version ranges (#937)3cc3c11chore(deps): roll up Dependabot updates (#936)9225f84chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (#924)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions