Skip to content

chore(deps): Bump the minor-patch group across 1 directory with 18 updates - #1996

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/minor-patch-0a3be6456b
Open

chore(deps): Bump the minor-patch group across 1 directory with 18 updates#1996
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/minor-patch-0a3be6456b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-patch group with 18 updates in the / directory:

Package From To
actions/checkout 7.0.0 7.0.1
ko-build/setup-ko 0.9 0.10
chainguard-dev/actions/goimports 1.6.21 1.6.29
github/codeql-action/init 4.36.1 4.37.4
github/codeql-action/analyze 4.36.1 4.37.4
chainguard-dev/actions/donotsubmit 1.6.21 1.6.29
mikefarah/yq 4.53.2 4.53.3
chainguard-dev/actions/setup-mirror 1.6.21 1.6.29
chainguard-dev/actions/kind-diag 1.6.21 1.6.29
chainguard-dev/actions/setup-kind 1.6.21 1.6.29
golangci/golangci-lint-action 9.2.1 9.3.0
goreleaser/goreleaser-action 7.2.2 7.2.3
ossf/scorecard-action 2.4.3 2.4.4
github/codeql-action/upload-sarif 4.36.1 4.37.4
chainguard-dev/actions/gofmt 1.6.21 1.6.29
chainguard-dev/actions/nodiff 1.6.21 1.6.29
chainguard-dev/actions/trailing-space 1.6.21 1.6.29
chainguard-dev/actions/eof-newline 1.6.21 1.6.29

Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates ko-build/setup-ko from 0.9 to 0.10

Release notes

Sourced from ko-build/setup-ko's releases.

v0.10

What's Changed

New Contributors

Full Changelog: ko-build/setup-ko@v0.9...v0.10

Commits
  • 61b4d1d Merge pull request #66 from ko-build/copilot/address-findings-report
  • 92951cd Harden composite action shell input handling
  • 369dc1f Merge pull request #64 from ko-build/dependabot/github_actions/actions/checko...
  • aa4f2f2 Bump actions/checkout from 6.0.3 to 7.0.0
  • 2e5f3a9 Merge pull request #62 from ko-build/dependabot/github_actions/all-22d6a8b472
  • fefb89f Update use-action.yaml
  • 074c423 Update Go version from 1.25 to 1.26 in CI workflow
  • d43b839 Bump the all group across 1 directory with 2 updates
  • 8719e8e Merge pull request #60 from ko-build/dependabot/github_actions/all-2c6e677ddc
  • 9beb6ab Bump actions/setup-go from 6.2.0 to 6.3.0 in the all group
  • Additional commits viewable in compare view

Updates chainguard-dev/actions/goimports from 1.6.21 to 1.6.29

Release notes

Sourced from chainguard-dev/actions/goimports's releases.

v1.6.29

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.28...v1.6.29

v1.6.28

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.27...v1.6.28

v1.6.27

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.26...v1.6.27

v1.6.26

What's Changed

... (truncated)

Commits
  • b2555de build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#999)
  • 9df4e69 build(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#1000)
  • eb4d05a build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /boilerplate (#1001)
  • 39afab0 build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /release-notes (#1002)
  • d15291b fix(release): create GitHub releases with gh instead of GoReleaser (#1006)
  • 009bbcd build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /setup-melange (#1003)
  • ab35760 build(deps): bump github.com/sethvargo/go-envconfig in /hugo2confluence (#1005)
  • fabe4ed build(deps): bump the actions group across 8 directories with 8 updates (#996)
  • 0190770 build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#997)
  • 3d777f8 build(deps): bump actions/setup-node in /githubapp-token (#998)
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.36.1 to 4.37.4

Release notes

Sourced from github/codeql-action/init's releases.

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

v4.37.0

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

v4.36.3

No user facing changes.

v4.36.2

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

... (truncated)

Commits
  • f205ea1 Merge pull request #4053 from github/update-v4.37.4-9130ce0f7
  • e40d079 Update changelog for v4.37.4
  • 9130ce0 Merge pull request #4051 from github/update-bundle/codeql-bundle-v2.26.2
  • c62d824 Add changelog note
  • da0c190 Update default bundle to codeql-bundle-v2.26.2
  • 18420e3 Merge pull request #4043 from github/mbg/ts/changelog
  • 7e8d897 Merge pull request #4046 from github/mbg/repo-prop/code-quality
  • 2d4c474 Log !analysisKindSupported case
  • 98c05a1 Fix argument validation in rollback-changelog.ts
  • 8289a49 Ignore repository property for unsupported analysis kinds
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.36.1 to 4.37.4

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v4.37.3

No user facing changes.

v4.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v4.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

v4.37.0

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

v4.36.3

No user facing changes.

v4.36.2

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

... (truncated)

Commits
  • f205ea1 Merge pull request #4053 from github/update-v4.37.4-9130ce0f7
  • e40d079 Update changelog for v4.37.4
  • 9130ce0 Merge pull request #4051 from github/update-bundle/codeql-bundle-v2.26.2
  • c62d824 Add changelog note
  • da0c190 Update default bundle to codeql-bundle-v2.26.2
  • 18420e3 Merge pull request #4043 from github/mbg/ts/changelog
  • 7e8d897 Merge pull request #4046 from github/mbg/repo-prop/code-quality
  • 2d4c474 Log !analysisKindSupported case
  • 98c05a1 Fix argument validation in rollback-changelog.ts
  • 8289a49 Ignore repository property for unsupported analysis kinds
  • Additional commits viewable in compare view

Updates chainguard-dev/actions/donotsubmit from 1.6.21 to 1.6.29

Release notes

Sourced from chainguard-dev/actions/donotsubmit's releases.

v1.6.29

What's Changed

New Contributors

Full Changelog: chainguard-dev/actions@v1.6.28...v1.6.29

v1.6.28

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.27...v1.6.28

v1.6.27

What's Changed

Full Changelog: chainguard-dev/actions@v1.6.26...v1.6.27

v1.6.26

What's Changed

... (truncated)

Commits
  • b2555de build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#999)
  • 9df4e69 build(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#1000)
  • eb4d05a build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /boilerplate (#1001)
  • 39afab0 build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /release-notes (#1002)
  • d15291b fix(release): create GitHub releases with gh instead of GoReleaser (#1006)
  • 009bbcd build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 in /setup-melange (#1003)
  • ab35760 build(deps): bump github.com/sethvargo/go-envconfig in /hugo2confluence (#1005)
  • fabe4ed build(deps): bump the actions group across 8 directories with 8 updates (#996)
  • 0190770 build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#997)
  • 3d777f8 build(deps): bump actions/setup-node in /githubapp-token (#998)
  • Additional commits viewable in compare view

Updates mikefarah/yq from 4.53.2 to 4.53.3

Release notes

Sourced from mikefarah/yq's releases.

v4.53.3

  • Add --ini-preserve-quotes flag for INI round-trip quote preservation (#2728) Thanks @​toller892!
  • Fix: reset INI decoder state on init (

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/minor-patch-0a3be6456b branch from 8a933b1 to 5dbf920 Compare July 30, 2026 22:52
…dates

Bumps the minor-patch group with 18 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` |
| [ko-build/setup-ko](https://github.com/ko-build/setup-ko) | `0.9` | `0.10` |
| [chainguard-dev/actions/goimports](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.36.1` | `4.37.4` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.36.1` | `4.37.4` |
| [chainguard-dev/actions/donotsubmit](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [mikefarah/yq](https://github.com/mikefarah/yq) | `4.53.2` | `4.53.3` |
| [chainguard-dev/actions/setup-mirror](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [chainguard-dev/actions/kind-diag](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [chainguard-dev/actions/setup-kind](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) | `9.2.1` | `9.3.0` |
| [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `7.2.2` | `7.2.3` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.36.1` | `4.37.4` |
| [chainguard-dev/actions/gofmt](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [chainguard-dev/actions/nodiff](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [chainguard-dev/actions/trailing-space](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |
| [chainguard-dev/actions/eof-newline](https://github.com/chainguard-dev/actions) | `1.6.21` | `1.6.29` |



Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `ko-build/setup-ko` from 0.9 to 0.10
- [Release notes](https://github.com/ko-build/setup-ko/releases)
- [Commits](ko-build/setup-ko@d006021...61b4d1d)

Updates `chainguard-dev/actions/goimports` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `github/codeql-action/init` from 4.36.1 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@87557b9...f205ea1)

Updates `github/codeql-action/analyze` from 4.36.1 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@87557b9...f205ea1)

Updates `chainguard-dev/actions/donotsubmit` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `mikefarah/yq` from 4.53.2 to 4.53.3
- [Release notes](https://github.com/mikefarah/yq/releases)
- [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt)
- [Commits](mikefarah/yq@751d8ad...1b9b4ac)

Updates `chainguard-dev/actions/setup-mirror` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `chainguard-dev/actions/kind-diag` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `chainguard-dev/actions/setup-kind` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `golangci/golangci-lint-action` from 9.2.1 to 9.3.0
- [Release notes](https://github.com/golangci/golangci-lint-action/releases)
- [Commits](golangci/golangci-lint-action@82606bf...ba0d7d2)

Updates `goreleaser/goreleaser-action` from 7.2.2 to 7.2.3
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)
- [Commits](goreleaser/goreleaser-action@5daf1e9...f06c13b)

Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@4eaacf0...2d11466)

Updates `github/codeql-action/upload-sarif` from 4.36.1 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@87557b9...f205ea1)

Updates `chainguard-dev/actions/gofmt` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `chainguard-dev/actions/nodiff` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `chainguard-dev/actions/trailing-space` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

Updates `chainguard-dev/actions/eof-newline` from 1.6.21 to 1.6.29
- [Release notes](https://github.com/chainguard-dev/actions/releases)
- [Commits](chainguard-dev/actions@05fbd38...b2555de)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/donotsubmit
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/eof-newline
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/gofmt
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/goimports
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/kind-diag
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/nodiff
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/setup-kind
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/setup-mirror
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: chainguard-dev/actions/trailing-space
  dependency-version: 1.6.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
- dependency-name: golangci/golangci-lint-action
  dependency-version: 9.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
- dependency-name: goreleaser/goreleaser-action
  dependency-version: 7.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: ko-build/setup-ko
  dependency-version: '0.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch
- dependency-name: mikefarah/yq
  dependency-version: 4.53.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/minor-patch-0a3be6456b branch from 5dbf920 to 7823076 Compare August 3, 2026 17:32
@dependabot
dependabot Bot requested a review from a team as a code owner August 3, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants