chore(deps): bump the github-actions group with 4 updates#186
chore(deps): bump the github-actions group with 4 updates#186dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the github-actions group with 4 updates: [github/gh-aw](https://github.com/github/gh-aw), [softprops/action-gh-release](https://github.com/softprops/action-gh-release), [taiki-e/install-action](https://github.com/taiki-e/install-action) and [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer). Updates `github/gh-aw` from 0.56.2 to 0.58.3 - [Release notes](https://github.com/github/gh-aw/releases) - [Commits](github/gh-aw@v0.56.2...v0.58.3) Updates `softprops/action-gh-release` from 2.5.0 to 2.6.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@a06a81a...153bb8e) Updates `taiki-e/install-action` from 2.68.25 to 2.68.34 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@a37010d...de6bbd1) Updates `sigstore/cosign-installer` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@faadad0...ba7bc0a) --- updated-dependencies: - dependency-name: github/gh-aw dependency-version: 0.58.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 2.6.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: taiki-e/install-action dependency-version: 2.68.34 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: sigstore/cosign-installer dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
|
@dependabot rebase |
1 similar comment
|
@dependabot rebase |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Pull request was closed
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #186 +/- ##
=======================================
Coverage 94.93% 94.93%
=======================================
Files 25 25
Lines 10183 10183
=======================================
Hits 9667 9667
Misses 516 516 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Bumps the github-actions group with 4 updates: github/gh-aw, softprops/action-gh-release, taiki-e/install-action and sigstore/cosign-installer.
Updates
github/gh-awfrom 0.56.2 to 0.58.3Release notes
Sourced from github/gh-aw's releases.
... (truncated)
Commits
08a903bdocs: add aria-live enhancement for search results accessibility (#issue) (#2...1cb4a5aRemove copilot-preflight script and associated step generation (#21016)47ab8ddfix: use artifact prefix in conclusion job and script step downloads for work...c87077eperf: optimizeextractWorkflowNameFromFileby eliminating unnecessary YAML ...1a426d0Addgofirewall allowed set toshared/go-make.md(#21014)50e4991feat: add write-sink guard policy to all non-GitHub MCP servers configured by...4e2b550docs: condense intro and remove duplicate cross-repo notes in central-repo-op...1333b4adocs: add action-tag feature flag to github-agentic-workflows.md (#21001)5a8a60afix: emit GH_HOST: github.com on Install GitHub Copilot CLI step to prevent G...4173449feat: update action-tag to use action pins mode (gh-aw-actions) with v0 (#20991)Updates
softprops/action-gh-releasefrom 2.5.0 to 2.6.1Release notes
Sourced from softprops/action-gh-release's releases.
... (truncated)
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
153bb8erelease 2.6.1569deb8fix: preserve discussion category when publishing releases (#765)26e8ad2release 2.6.0b959f31fix: clarify immutable prerelease uploads (#763)8a8510eci: verify dist bundle freshness (#762)438c15ddocs: clarify working_directory input (#761)6ca3b5dfix: recover concurrent asset metadata 404s (#760)11f9176chore: add RELEASE.md1f3f350feat: add AGENTS.md37819cbdocs: clarify reused draft release behavior (#759)Updates
taiki-e/install-actionfrom 2.68.25 to 2.68.34Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
de6bbd1Release 2.68.341118ed9ci: Update config7e92ca6Updateprek@latestto 0.3.666ef0c0Updatevacuum@latestto 0.25.2cbb1dcaRelease 2.68.3357531b2Updatedprint@latestto 0.53.0f916cfaRelease 2.68.32f48a693Updatetombi@latestto 0.9.649eda53Updatemartin@latestto 1.4.0a57ddfbRelease 2.68.31Updates
sigstore/cosign-installerfrom 4.0.0 to 4.1.0Release notes
Sourced from sigstore/cosign-installer's releases.
Commits
ba7bc0afix: add retry to curl downloads for transient network failures (#210)5a292e1Bump cosign to 3.0.5 (#220)351ea76Bump actions/checkout from 6.0.1 to 6.0.2 (#217)c17565ftest with go 1.26 too (#221)a6fdd19Bump actions/setup-go from 6.1.0 to 6.3.0 (#218)430b6a7docs: fix registry from gcr.io to ghcr.io (#213)4d14d7ffeat: update to v3.0.3 (#212)f148005fix: use env vars for template expansions; show curl errors (#207)c3f2d79Bump actions/checkout from 6.0.0 to 6.0.1 (#208)b9a9af4drop tests with go1.24 as it cant build (#211)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions