Skip to content

chore(ci): bump the actions-patch-minor group across 1 directory with 2 updates - #1157

Open
dependabot[bot] wants to merge 1 commit into
unstablefrom
dependabot/github_actions/unstable/actions-patch-minor-56d28b13c4
Open

chore(ci): bump the actions-patch-minor group across 1 directory with 2 updates#1157
dependabot[bot] wants to merge 1 commit into
unstablefrom
dependabot/github_actions/unstable/actions-patch-minor-56d28b13c4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown

Bumps the actions-patch-minor group with 2 updates in the / directory: anthropics/claude-code-action and rojopolis/spellcheck-github-actions.

Updates anthropics/claude-code-action from 1.0.127 to 1.0.187

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.187

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.187

v1.0.186

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.186

v1.0.185

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.185

v1.0.184

Full Changelog: anthropics/claude-code-action@v1...v1.0.184

v1.0.183

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Full Changelog: anthropics/claude-code-action@v1...v1.0.182

v1.0.181

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.181

v1.0.180

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Full Changelog: anthropics/claude-code-action@v1...v1.0.179

... (truncated)

Commits
  • 1623c36 chore: bump Claude Code to 2.1.224 and Agent SDK to 0.3.224
  • 96e281f Run checkout auth cleanup when API commit signing is enabled (#1597)
  • e1fc925 Scope the config snapshot to files inside the working tree (#1596)
  • 0aee57a Redact common credential patterns from published run output (#1595)
  • c038e4d chore: bump Claude Code to 2.1.223 and Agent SDK to 0.3.223
  • 4c04887 Invoke the formatter directly from the format hook (#1594)
  • 9db594c chore: bump Claude Code to 2.1.222 and Agent SDK to 0.3.222
  • acb0385 Check collaborator permissions for workflow_run events (#1590)
  • b80a0f0 Match downloaded images to their source URLs by asset identifier (#1588)
  • 6fb6bb6 Pin bun config for MCP server processes (#1589)
  • Additional commits viewable in compare view

Updates rojopolis/spellcheck-github-actions from 0.46.0 to 0.64.0

Release notes

Sourced from rojopolis/spellcheck-github-actions's releases.

0.64.0

What's Changed

Full Changelog: rojopolis/spellcheck-github-actions@0.63.1...0.64.0

0.63.1

What's Changed

Full Changelog: rojopolis/spellcheck-github-actions@0.63.0...0.63.1

0.63.0

What's Changed

Full Changelog: rojopolis/spellcheck-github-actions@0.62.0...0.63.0

0.62.0

What's Changed

Full Changelog: rojopolis/spellcheck-github-actions@0.61.0...0.62.0

0.61.0

What's Changed

... (truncated)

Changelog

Sourced from rojopolis/spellcheck-github-actions's changelog.

0.64.0, 2026-07-31, maintenance release, update not required

  • Adopted pip-compile (pip-tools) for Python dependency management via PR #380. requirements.in is now the source of truth for direct dependencies (pyspelling, pymdown-extensions); requirements.txt is generated from it rather than hand-maintained, so transitive pins can no longer silently fall out of sync the way bracex did in issue #378.

    • backrefs and zipp are dropped from requirements.txt. Neither is part of the resolved dependency graph for pyspelling + pymdown-extensions on the Python version this image ships (verified against each package's own declared metadata and the installed package list in the built image) — they were stale manual pins, not active dependencies. In particular, zipp was originally pinned in PR #204 to patch CVE-2024-5569; that dependency chain (pyspellingimportlib-metadatazipp) no longer exists, so removing the pin does not reintroduce the vulnerability — the package simply isn't installed, pinned or not.

    • .github/dependabot.yml's pip ecosystem entry already set versioning-strategy: lockfile-only, which expects exactly this requirements.in/requirements.txt split; this change makes that existing setting apply as intended.

0.63.1, 2026-07-30, bug fix release, update recommended

  • Fixed sources glob patterns that combine brace expansion with the SPLIT/GLOBSTAR flags (e.g. **/*.{c,h}|!build/**) silently matching zero files and causing the action to fail with RuntimeError: None of the source targets from the configuration match any files. The pinned bracex dependency (2.5.post1) predated the version wcmatch requires for correct parsing of such patterns; bumped to 3.0.1 via PR #379. Addresses issue #378, reported by @​arkq.

0.63.0, 2026-07-01, maintenance release, update not required

  • Docker based image updated for Python 3.14.6 slim trixie via PR #364 from Dependabot.

0.62.0, 2026-06-19, security release, update recommended

  • Bumped lxml from 5.3.0 to 5.4.0 to address known CVEs via PR #357.

  • Bumped pymdown-extensions to patched version 10.21.3 via PR #358.

  • Bumped Markdown from 3.7 to 3.8.1 to patched version via PR #359.

  • Cleaned up GitHub Actions workflows using zizmor and removed ratchet annotations via PR #355 and PR #356.

  • Clarified examples in README.

0.61.0, 2026-06-14, minor feature release, update not required

  • Docker based image updated for Python 3.14.5 slim trixie via PR #344 from Dependabot.

0.60, 2026-03-14, minor feature release, update not required

  • Docker based image updated for Python 3.14.3 slim trixie via PR #325 from Dependabot.

  • Cleaned up the error messaging, to address issue #328 from @​akohout-hai, the error message is now more correct, but not improved in general

0.59.0, 2026-03-02, feature release, update recommended

  • Improvements have been added to the docker entrypoint, based on a PR from @​akohout-hai which fixes an issue with handling of spaces in files names and directories, see PR #322 for details. This is his first contribution to the project and I want to thank him for his contribution, which is highly appreciated.

  • Docker based image updated to Python 3.14.3 slim trixie via PR #320 from Dependabot.

0.58.0, 2026-01-20, security release, update not required

... (truncated)

Commits
  • 26a39cd Merge pull request #383 from rojopolis/release/0.64.0
  • 83c2a8a Fix inconsistent steps indentation in Output Artifact example
  • 1096979 Release 0.64.0
  • d4fd16d Merge pull request #380 from rojopolis/chore/pip-compile-dependency-management
  • 7b3ceea Merge remote-tracking branch into chore/pip-compile-dependency-management
  • 2b98dff Add CHANGELOG entry for 0.64.0
  • 6f4f174 Merge origin/master and resolve requirements.txt conflict
  • 8861a59 Merge pull request #377 from rojopolis/dependabot/github_actions/docker/login...
  • b1a70f1 Merge pull request #381 from rojopolis/release/0.63.1
  • 6e33b9e Add arkq to wordlist to fix spellcheck CI failure
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@cla-assistant

cla-assistant Bot commented Jul 21, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@codecov-commenter

codecov-commenter commented Jul 21, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 65.42%. Comparing base (82bac14) to head (2839ae2).

Additional details and impacted files
@@            Coverage Diff            @@
##           unstable    #1157   +/-   ##
=========================================
  Coverage     65.42%   65.42%           
=========================================
  Files           164      164           
  Lines         28075    28075           
=========================================
  Hits          18367    18367           
  Misses         9708     9708           
Flag Coverage Δ
rust 65.42% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dependabot dependabot Bot changed the title chore(ci): bump the actions-patch-minor group with 2 updates chore(ci): bump the actions-patch-minor group across 1 directory with 2 updates Jul 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/unstable/actions-patch-minor-56d28b13c4 branch from b05c3f0 to a388f0f Compare July 27, 2026 06:37
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/unstable/actions-patch-minor-56d28b13c4 branch from a388f0f to f8d8e91 Compare August 3, 2026 06:39
… 2 updates

Bumps the actions-patch-minor group with 2 updates in the / directory: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) and [rojopolis/spellcheck-github-actions](https://github.com/rojopolis/spellcheck-github-actions).


Updates `anthropics/claude-code-action` from 1.0.127 to 1.0.187
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@v1.0.127...v1.0.187)

Updates `rojopolis/spellcheck-github-actions` from 0.46.0 to 0.64.0
- [Release notes](https://github.com/rojopolis/spellcheck-github-actions/releases)
- [Changelog](https://github.com/rojopolis/spellcheck-github-actions/blob/master/CHANGELOG.md)
- [Commits](rojopolis/spellcheck-github-actions@0.46.0...0.64.0)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.179
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-patch-minor
- dependency-name: rojopolis/spellcheck-github-actions
  dependency-version: 0.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/unstable/actions-patch-minor-56d28b13c4 branch from f8d8e91 to 2839ae2 Compare August 10, 2026 06:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant