Skip to content

chore(deps): bump the github-actions group with 12 updates#297

Merged
Nick2bad4u merged 1 commit intomainfrom
dependabot/github_actions/github-actions-9eb93b7899
Sep 2, 2025
Merged

chore(deps): bump the github-actions group with 12 updates#297
Nick2bad4u merged 1 commit intomainfrom
dependabot/github_actions/github-actions-9eb93b7899

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Sep 1, 2025

Bumps the github-actions group with 12 updates:

Package From To
actions/checkout 4.2.2 5.0.0
github/codeql-action 3.29.7 3.30.0
actions/dependency-review-action 4.7.1 4.7.3
actions/cache 4.2.3 4.2.4
actions/first-interaction 2.0.0 3.0.0
actions/upload-pages-artifact 3.0.1 4.0.0
google/osv-scanner-action 2.1.0 2.2.2
cicirello/generate-sitemap 1.10.2 1.10.3
actions/ai-inference 1.2.3 2.0.1
super-linter/super-linter 8.0.0 8.1.0
trufflesecurity/trufflehog 3.90.2 3.90.5
crate-ci/typos 1.34.0 1.35.7

Updates actions/checkout from 4.2.2 to 5.0.0

Release notes

Sourced from actions/checkout's releases.

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v4...v4.3.0

Changelog

Sourced from actions/checkout's changelog.

Changelog

V5.0.0

V4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

v4.1.4

v4.1.3

... (truncated)

Commits

Updates github/codeql-action from 3.29.7 to 3.30.0

Release notes

Sourced from github/codeql-action's releases.

v3.30.0

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.30.0 - 01 Sep 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.29.11

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.29.11 - 21 Aug 2025

  • Update default CodeQL bundle version to 2.22.4. #3044

See the full CHANGELOG.md for more information.

v3.29.10

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.29.10 - 18 Aug 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.29.9

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.29.9 - 12 Aug 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v3.29.8

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.29.8 - 08 Aug 2025

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

3.29.11 - 21 Aug 2025

  • Update default CodeQL bundle version to 2.22.4. #3044

3.29.10 - 18 Aug 2025

No user facing changes.

3.29.9 - 12 Aug 2025

No user facing changes.

3.29.8 - 08 Aug 2025

  • Fix an issue where the Action would autodetect unsupported languages such as HTML. #3015

3.29.7 - 07 Aug 2025

This release rolls back 3.29.6 to address issues with language autodetection. It is identical to 3.29.5.

3.29.6 - 07 Aug 2025

  • The cleanup-level input to the analyze Action is now deprecated. The CodeQL Action has written a limited amount of intermediate results to the database since version 2.2.5, and now automatically manages cleanup. #2999
  • Update default CodeQL bundle version to 2.22.3. #3000

3.29.5 - 29 Jul 2025

  • Update default CodeQL bundle version to 2.22.2. #2986

3.29.4 - 23 Jul 2025

No user facing changes.

3.29.3 - 21 Jul 2025

No user facing changes.

3.29.2 - 30 Jun 2025

  • Experimental: When the quality-queries input for the init action is provided with an argument, separate .quality.sarif files are produced and uploaded for each language with the results of the specified queries. Do not use this in production as it is part of an internal experiment and subject to change at any time. #2935

3.29.1 - 27 Jun 2025

... (truncated)

Commits
  • 2d92b76 Merge pull request #3067 from github/update-v3.30.0-92eada825
  • 390daaf Update changelog for v3.30.0
  • 92eada8 Merge pull request #3033 from github/mbg/ci/rollback-release
  • 872a6a4 Add pull-requests: write permission
  • 9389ce0 Merge remote-tracking branch 'origin/main' into mbg/ci/rollback-release
  • 02ab253 Merge pull request #3054 from github/henrymercer/bundle
  • b06d325 Add draft release URL to job summary
  • 43d629c Use argparse in rollback_changelog.py
  • 8f01f5d Apply suggestions from code review
  • 3e493e7 Remove removeNPMAbsolutePaths
  • Additional commits viewable in compare view

Updates actions/dependency-review-action from 4.7.1 to 4.7.3

Release notes

Sourced from actions/dependency-review-action's releases.

4.7.3

What's Changed

Full Changelog: actions/dependency-review-action@v4...v4.7.3

4.7.2

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v4...v4.7.2

Commits
  • 595b5ae Update package version (#975)
  • fc5fd66 Claire153/fix spamming mentioned issue (#974)
  • d38d1a4 Merge pull request #965 from actions/dependabot/npm_and_yarn/multi-c22e25d29b
  • 8d420b8 Merge branch 'main' into dependabot/npm_and_yarn/multi-c22e25d29b
  • bde0129 Merge pull request #966 from actions/ashelytc/add-permissions
  • ab52490 remove ruby
  • ef00a0a add permissions to workflows
  • 74c8179 Bump brace-expansion
  • bc41886 Cut 4.7.2 version release (#964)
  • 1c73553 Merge pull request #960 from ahpook/ahpook/address-docs-dashes
  • Additional commits viewable in compare view

Updates actions/cache from 4.2.3 to 4.2.4

Release notes

Sourced from actions/cache's releases.

v4.2.4

What's Changed

New Contributors

Full Changelog: actions/cache@v4...v4.2.4

Changelog

Sourced from actions/cache's changelog.

Releases

4.2.4

  • Bump @actions/cache to v4.0.5

4.2.3

  • Bump @actions/cache to v4.0.3 (obfuscates SAS token in debug logs for cache entries)

4.2.2

  • Bump @actions/cache to v4.0.2

4.2.1

  • Bump @actions/cache to v4.0.1

4.2.0

TLDR; The cache backend service has been rewritten from the ground up for improved performance and reliability. actions/cache now integrates with the new cache service (v2) APIs.

The new service will gradually roll out as of February 1st, 2025. The legacy service will also be sunset on the same date. Changes in these release are fully backward compatible.

We are deprecating some versions of this action. We recommend upgrading to version v4 or v3 as soon as possible before February 1st, 2025. (Upgrade instructions below).

If you are using pinned SHAs, please use the SHAs of versions v4.2.0 or v3.4.0

If you do not upgrade, all workflow runs using any of the deprecated actions/cache will fail.

Upgrading to the recommended versions will not break your workflows.

4.1.2

  • Add GitHub Enterprise Cloud instances hostname filters to inform API endpoint choices - #1474
  • Security fix: Bump braces from 3.0.2 to 3.0.3 - #1475

4.1.1

  • Restore original behavior of cache-hit output - #1467

4.1.0

  • Ensure cache-hit output is set when a cache is missed - #1404
  • Deprecate save-always input - #1452

4.0.2

  • Fixed restore fail-on-cache-miss not working.

... (truncated)

Commits
  • 0400d5f Merge pull request #1636 from actions/Link-/release-4.2.4
  • 374a27f Prepare release 4.2.4
  • 358a730 Merge pull request #1634 from actions/Link-/optimise-deps
  • 2ee706e Fix with another approach
  • 94f7b5d Fix bundle exec
  • c36116c Fix the workflow to use licensed from source
  • 320fe7d Update the licensed workflow to use the latest version
  • d81cc47 Add licensed output
  • de24398 Add licensed output
  • e7b6a9c @​protobuf-ts/plugin to dev dependencies
  • Additional commits viewable in compare view

Updates actions/first-interaction from 2.0.0 to 3.0.0

Release notes

Sourced from actions/first-interaction's releases.

v3.0.0

What's Changed

New Contributors

Full Changelog: actions/first-interaction@v2...v3.0.0

Commits

Updates actions/upload-pages-artifact from 3.0.1 to 4.0.0

Release notes

Sourced from actions/upload-pages-artifact's releases.

v4.0.0

What's Changed

Full Changelog: actions/upload-pages-artifact@v3.0.1...v4.0.0

Commits
  • 7b1f4a7 Merge pull request #127 from heavymachinery/pin-sha
  • 4cc19c7 Pin actions/upload-artifact to SHA
  • 2d163be Merge pull request #107 from KittyChiu/main
  • c704843 fix: linted README
  • 9605915 Merge pull request #106 from KittyChiu/kittychiu/update-readme-1
  • e59cdfe Update README.md
  • a2d6704 doc: updated usage section in readme
  • 984864e Merge pull request #105 from actions/Jcambass-patch-1
  • 45dc788 Add workflow file for publishing releases to immutable action package
  • efaad07 Merge pull request #102 from actions/hidden-files
  • Additional commits viewable in compare view

Updates google/osv-scanner-action from 2.1.0 to 2.2.2

Release notes

Sourced from google/osv-scanner-action's releases.

v2.2.2

This updates OSV-Scanner to v2.2.2.

What's Changed

Full Changelog: google/osv-scanner-action@v2.2.1...v2.2.2

v2.2.1

What's Changed

OSV-Scanner now supports all OSV-Scalibr features behind experimental flags (--experimental-plugins, see details here)!

Features:

Fixes:

API Changes:


[!WARNING] This release was originally incorrectly pointing to the bugged v2.2.0 osv-scanner release, it has now been retagged to the correct v2.2.1 release.

Commits
  • 90b209d Merge pull request #95 from google/update-to-v2.2.2
  • 4971fe8 Update unified workflow example to point to v2.2.2 reusable workflows
  • 9d4732e Update reusable workflows to point to v2.2.2 actions
  • 23f8850 "Update actions to use v2.2.2 osv-scanner image"
  • 958b538 Merge pull request #94 from google/another-rex-patch-1
  • 11cd74e Update Automatic install instructions
  • 456ceb7 Merge pull request #91 from google/update-to-v2.2.1
  • 233fa8e Update unified workflow example to point to v2.2.1 reusable workflows
  • 8878e97 Update reusable workflows to point to v2.2.1 actions
  • 6580e6c "Update actions to use v2.2.1 osv-scanner image"
  • Additional commits viewable in compare view

Updates cicirello/generate-sitemap from 1.10.2 to 1.10.3

Release notes

Sourced from cicirello/generate-sitemap's releases.

generate-sitemap, v1.10.3

[1.10.3] - 2025-08-14

Fixed

  • Fixed failure to get last commit dates in case of nested repository checkouts.

Dependencies

  • Bump cicirello/pyaction from 3.13.5-gh-2.75.1 to 3.13.6-gh-2.76.2
Changelog

Sourced from cicirello/generate-sitemap's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased] - 2025-08-14

Added

Changed

Deprecated

Removed

Fixed

CI/CD

Dependencies

[1.10.3] - 2025-08-14

Fixed

  • Fixed failure to get last commit dates in case of nested repository checkouts.

Dependencies

  • Bump cicirello/pyaction from 3.13.5-gh-2.75.1 to 3.13.6-gh-2.76.2

[1.10.2] - 2025-07-15

Dependencies

  • Use the new tag scheme for cicirello/pyaction.
  • Bumps cicirello/pyaction to 3.13.5-gh-2.75.1.

[1.10.1] - 2024-06-08

Fixed

  • Escape characters that must be escaped in XML.

Dependencies

  • Bump cicirello/pyaction from 4.26.0 to 4.30.0

[1.10.0] - 2023-11-15

... (truncated)

Commits

Updates actions/ai-inference from 1.2.3 to 2.0.1

Release notes

Sourced from actions/ai-inference's releases.

v2.0.1

What's Changed

Full Changelog: actions/ai-inference@v2...v2.0.1

v2.0.0

What's Changed

New Contributors

⚠️ Minimum Compatible Runner Version

v2.327.1 Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/ai-inference@v1...v2.0.0

v1.2.8

What's Changed

Full Changelog: actions/ai-inference@v1...v1.2.8

v1.2.7

What's Changed

Full Changelog: actions/ai-inference@v1...v1.2.7

v1.2.6

What's Changed

Full Changelog: actions/ai-inference@v1...v1.2.6

v1.2.5

What's Changed

... (truncated)

Commits
  • a1c1182 Merge pull request #97 from actions/sgoedecke/defensive-parsing
  • dfaa426 Parse inference response format defensively
  • f347eae Merge pull request #91 from JessRudder/secure-tmp-files
  • 07fe2f3 Merge branch 'main' into secure-tmp-files
  • 1843310 Add license info
  • c72cb2e Merge pull request #90 from garman/pin-to-sha
  • a2fd223 Properly clean up tmp files
  • 3ba8e1b Replace manual tmp file creation with tmp library which uses security best pr...
  • 52e5222 pin to a sha
  • a62dfed Merge pull request #79 from salmanmkc/node24
  • Additional commits viewable in compare view

Updates super-linter/super-linter from 8.0.0 to 8.1.0

Release notes

Sourced from super-linter/super-linter's releases.

v8.1.0

8.1.0 (2025-08-20)

🚀 Features

⬆️ Dependency updates

  • bundler: bump rubocop in /dependencies in the rubocop group (#6918) (112c95e)
  • bundler: bump rubocop-rails in /dependencies in the rubocop group (#6947) (bdbef71)
  • bundler: bump the rubocop group in /dependencies with 2 updates (#6929) (f7958f1)
  • docker: bump python in the docker-base-images group (#6937) (fed04a2)
  • docker: bump python in the docker-base-images group (#6952) (8d1d341)
  • docker: bump the docker group with 4 updates (#6933) (8fd087d)
  • docker: bump the docker group with 4 updates (#6948) (95bb9b6)
  • docker: bump the docker group with 5 updates (

Bumps the github-actions group with 12 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` |
| [github/codeql-action](https://github.com/github/codeql-action) | `3.29.7` | `3.30.0` |
| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.7.1` | `4.7.3` |
| [actions/cache](https://github.com/actions/cache) | `4.2.3` | `4.2.4` |
| [actions/first-interaction](https://github.com/actions/first-interaction) | `2.0.0` | `3.0.0` |
| [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) | `3.0.1` | `4.0.0` |
| [google/osv-scanner-action](https://github.com/google/osv-scanner-action) | `2.1.0` | `2.2.2` |
| [cicirello/generate-sitemap](https://github.com/cicirello/generate-sitemap) | `1.10.2` | `1.10.3` |
| [actions/ai-inference](https://github.com/actions/ai-inference) | `1.2.3` | `2.0.1` |
| [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.0.0` | `8.1.0` |
| [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.90.2` | `3.90.5` |
| [crate-ci/typos](https://github.com/crate-ci/typos) | `1.34.0` | `1.35.7` |


Updates `actions/checkout` from 4.2.2 to 5.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@11bd719...08c6903)

Updates `github/codeql-action` from 3.29.7 to 3.30.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@51f7732...2d92b76)

Updates `actions/dependency-review-action` from 4.7.1 to 4.7.3
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@da24556...595b5ae)

Updates `actions/cache` from 4.2.3 to 4.2.4
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@5a3ec84...0400d5f)

Updates `actions/first-interaction` from 2.0.0 to 3.0.0
- [Release notes](https://github.com/actions/first-interaction/releases)
- [Commits](actions/first-interaction@2d4393e...753c925)

Updates `actions/upload-pages-artifact` from 3.0.1 to 4.0.0
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](actions/upload-pages-artifact@56afc60...7b1f4a7)

Updates `google/osv-scanner-action` from 2.1.0 to 2.2.2
- [Release notes](https://github.com/google/osv-scanner-action/releases)
- [Commits](google/osv-scanner-action@b00f71e...90b209d)

Updates `cicirello/generate-sitemap` from 1.10.2 to 1.10.3
- [Release notes](https://github.com/cicirello/generate-sitemap/releases)
- [Changelog](https://github.com/cicirello/generate-sitemap/blob/master/CHANGELOG.md)
- [Commits](cicirello/generate-sitemap@f76c831...19e2228)

Updates `actions/ai-inference` from 1.2.3 to 2.0.1
- [Release notes](https://github.com/actions/ai-inference/releases)
- [Commits](actions/ai-inference@9693b13...a1c1182)

Updates `super-linter/super-linter` from 8.0.0 to 8.1.0
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@5119dcd...ffde3b2)

Updates `trufflesecurity/trufflehog` from 3.90.2 to 3.90.5
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Changelog](https://github.com/trufflesecurity/trufflehog/blob/main/.goreleaser.yml)
- [Commits](trufflesecurity/trufflehog@a05cf08...0f58ae7)

Updates `crate-ci/typos` from 1.34.0 to 1.35.7
- [Release notes](https://github.com/crate-ci/typos/releases)
- [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md)
- [Commits](crate-ci/typos@392b78f...65f69f0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: github/codeql-action
  dependency-version: 3.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/dependency-review-action
  dependency-version: 4.7.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/cache
  dependency-version: 4.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/first-interaction
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/upload-pages-artifact
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: google/osv-scanner-action
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: cicirello/generate-sitemap
  dependency-version: 1.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/ai-inference
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: super-linter/super-linter
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.90.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: crate-ci/typos
  dependency-version: 1.35.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Sep 1, 2025

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@Nick2bad4u
Copy link
Copy Markdown
Owner

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

@github-actions github-actions Bot added AnyChange Assigned to any repo file change GitHub release New Release labels Sep 1, 2025
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Sep 1, 2025

@Nick2bad4u Nick2bad4u merged commit 6b0f9ce into main Sep 2, 2025
77 of 82 checks passed
@Nick2bad4u Nick2bad4u deleted the dependabot/github_actions/github-actions-9eb93b7899 branch September 2, 2025 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AnyChange Assigned to any repo file change GitHub release New Release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant