Skip to content

chore(deps): bump the github-actions group across 1 directory with 2 updates - #2931

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-f552c382ba
Closed

chore(deps): bump the github-actions group across 1 directory with 2 updates#2931
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-f552c382ba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates in the / directory: actions/github-script and cachix/install-nix-action.

Updates actions/github-script from 7.1.0 to 9.0.0

Commits
  • 3a2844b Merge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...
  • ca10bbd fix: use @​octokit/core/types import for v7 compatibility
  • 86e48e2 merge: incorporate main branch changes
  • c108472 chore: rebuild dist for v9 upgrade and getOctokit factory
  • afff112 Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...
  • ff8117e ci: fix user-agent test to handle orchestration ID
  • 81c6b78 ci: use deployment: false to suppress deployment noise from integration tests
  • 3953caf docs: update README examples from @​v8 to @​v9, add getOctokit docs and v9 brea...
  • c17d55b ci: add getOctokit integration test job
  • a047196 test: add getOctokit integration tests via callAsyncFunction
  • Additional commits viewable in compare view

Updates cachix/install-nix-action from 31.11.0 to 31.11.1

Commits
  • 13d8dd5 fix(ci): skip latest installer on x86_64-darwin
  • 875018f Merge pull request #281 from cachix/create-pull-request/patch
  • 6624a11 nix: 2.35.1 -> 2.35.2
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 2 updates in the / directory: [actions/github-script](https://github.com/actions/github-script) and [cachix/install-nix-action](https://github.com/cachix/install-nix-action).


Updates `actions/github-script` from 7.1.0 to 9.0.0
- [Commits](actions/github-script@f28e40c...3a2844b)

Updates `cachix/install-nix-action` from 31.11.0 to 31.11.1
- [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md)
- [Commits](cachix/install-nix-action@630ae54...13d8dd5)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: cachix/install-nix-action
  dependency-version: 31.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown
Contributor

Glass Cockpit

Base: origin/main
Head: HEAD

Change Surface:

  • Files: 3
  • Insertions: 3
  • Deletions: 3

Composition:

  • Code: 0.0%
  • Test: 0.0%
  • Docs: 0.0%
  • Config: 100.0%

Contracts:

  • API: No
  • CLI: No
  • Schema: No

Health: 100/100 (A)
Risk: low (0/100)

Review Plan

  • .github/workflows/promote-release-aliases.yml (priority: 1)
  • .github/workflows/release-consumer-smoke.yml (priority: 1)
  • .github/workflows/release.yml (priority: 1)

Receipts

Full receipt data available in JSON format.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

UB Review

  • Shared context: 13d972bcbbb30e8d1a72d9ebf6673aa497922a888db3d4fff1eaec0e197b76b4
  • Profile: gh-runner
  • Changed files: 3
  • Inline comments: 0

Decision

  • No review findings were produced in this degraded pass; unavailable evidence is listed below.

Review result

  • No validated code findings or verification questions survived this run.

Residual risk

  • A human should still inspect unsafe/native seams, test-oracle strength, and any unavailable evidence before relying on this review.

Missing evidence

  • Review confidence is reduced: 1 sensor evidence item(s) and 11 model evidence item(s) were unavailable. Full setup diagnostics are in the review artifacts.
  • Sensor actionlint unavailable: missing - command not found
  • Model lane ub-memory-lifetime unavailable: missing_key - UB_REVIEW_MINIMAX_API_KEY not provided; minimax lane output unavailable
  • Model lane ub-active-view unavailable: missing_key - UB_REVIEW_MINIMAX_API_KEY not provided; minimax lane output unavailable
  • Model lane ub-worker-handoff unavailable: missing_key - UB_REVIEW_MINIMAX_API_KEY not provided; minimax lane output unavailable
  • Model lane tests-red-green unavailable: missing_key - UB_REVIEW_MINIMAX_API_KEY not provided; minimax lane output unavailable
  • 7 additional model evidence item(s) omitted from the PR body.

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 7, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-f552c382ba branch September 7, 2026 15:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants