chore(deps): bump the github-actions group with 15 updates#305
Merged
Nick2bad4u merged 1 commit intomainfrom Nov 2, 2025
Merged
Conversation
Bumps the github-actions group with 15 updates: | Package | From | To | | --- | --- | --- | | [github/codeql-action](https://github.com/github/codeql-action) | `3.30.5` | `4.31.2` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.0` | `4.8.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `5.0.0` | | [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action) | `6.0.1` | `7.0.0` | | [actions/first-interaction](https://github.com/actions/first-interaction) | `3.0.0` | `3.1.0` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `9.0.1` | `9.1.0` | | [google/osv-scanner-action](https://github.com/google/osv-scanner-action) | `2.2.3` | `2.2.4` | | [actions/setup-node](https://github.com/actions/setup-node) | `5.0.0` | `6.0.0` | | [cicirello/generate-sitemap](https://github.com/cicirello/generate-sitemap) | `1.10.3` | `1.10.4` | | [sobelow/action](https://github.com/sobelow/action) | `1.0.0` | `1.1.0` | | [rojopolis/spellcheck-github-actions](https://github.com/rojopolis/spellcheck-github-actions) | `0.52.0` | `0.53.0` | | [actions/stale](https://github.com/actions/stale) | `10.0.0` | `10.1.0` | | [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.2.0` | `8.2.1` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.90.8` | `3.90.12` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.37.0` | `1.39.0` | Updates `github/codeql-action` from 3.30.5 to 4.31.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@3599b3b...0499de3) Updates `actions/dependency-review-action` from 4.8.0 to 4.8.1 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@56339e5...40c09b7) Updates `actions/upload-artifact` from 4.6.2 to 5.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...330a01c) Updates `stefanzweifel/git-auto-commit-action` from 6.0.1 to 7.0.0 - [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases) - [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md) - [Commits](stefanzweifel/git-auto-commit-action@778341a...28e16e8) Updates `actions/first-interaction` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/actions/first-interaction/releases) - [Commits](actions/first-interaction@753c925...1c46889) Updates `oxsecurity/megalinter` from 9.0.1 to 9.1.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@0dcbedd...62c799d) Updates `google/osv-scanner-action` from 2.2.3 to 2.2.4 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@e92b5d0...9bb6957) Updates `actions/setup-node` from 5.0.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@a0853c2...2028fbc) Updates `cicirello/generate-sitemap` from 1.10.3 to 1.10.4 - [Release notes](https://github.com/cicirello/generate-sitemap/releases) - [Changelog](https://github.com/cicirello/generate-sitemap/blob/master/CHANGELOG.md) - [Commits](cicirello/generate-sitemap@19e2228...6a56a20) Updates `sobelow/action` from 1.0.0 to 1.1.0 - [Release notes](https://github.com/sobelow/action/releases) - [Commits](sobelow/action@1afd6d2...a9bf221) Updates `rojopolis/spellcheck-github-actions` from 0.52.0 to 0.53.0 - [Release notes](https://github.com/rojopolis/spellcheck-github-actions/releases) - [Changelog](https://github.com/rojopolis/spellcheck-github-actions/blob/master/CHANGELOG.md) - [Commits](rojopolis/spellcheck-github-actions@739a1e3...336d2b4) Updates `actions/stale` from 10.0.0 to 10.1.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@3a9db7e...5f858e3) Updates `super-linter/super-linter` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/super-linter/super-linter/releases) - [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md) - [Commits](super-linter/super-linter@7bba2ee...2bdd90e) Updates `trufflesecurity/trufflehog` from 3.90.8 to 3.90.12 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Changelog](https://github.com/trufflesecurity/trufflehog/blob/main/.goreleaser.yml) - [Commits](trufflesecurity/trufflehog@466da5b...b84c3d1) Updates `crate-ci/typos` from 1.37.0 to 1.39.0 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@6d35b83...07d900b) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.31.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: stefanzweifel/git-auto-commit-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/first-interaction dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-version: 9.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: google/osv-scanner-action dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: cicirello/generate-sitemap dependency-version: 1.10.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: sobelow/action dependency-version: 1.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: rojopolis/spellcheck-github-actions dependency-version: 0.53.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/stale dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: super-linter/super-linter dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.90.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: crate-ci/typos dependency-version: 1.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Owner
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the github-actions group with 15 updates:
3.30.54.31.24.8.04.8.14.6.25.0.06.0.17.0.03.0.03.1.09.0.19.1.02.2.32.2.45.0.06.0.01.10.31.10.41.0.01.1.00.52.00.53.010.0.010.1.08.2.08.2.13.90.83.90.121.37.01.39.0Updates
github/codeql-actionfrom 3.30.5 to 4.31.2Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
0499de3Merge pull request #3261 from github/henrymercer/setup-python3b96745Set up Python in mergeback workflow8a06050Merge pull request #3259 from github/update-v4.31.2-9576b5cbe752a642Update changelog for v4.31.29576b5cMerge pull request #3258 from github/mbg/enablement-errors/case-insensitivecc88437Merge pull request #3257 from github/henrymercer/ubuntu-slimf0e9bf0MakeisEnablementErrorcase-insensitive2a3599cRun lightweight workflows onubuntu-slim514ff4dMerge pull request #3256 from github/henrymercer/resolve-bad-mergeaab1c2fMerge pull request #3253 from github/mergeback/v4.31.1-to-main-5fe9434cUpdates
actions/dependency-review-actionfrom 4.8.0 to 4.8.1Release notes
Sourced from actions/dependency-review-action's releases.
Commits
40c09b7Merge pull request #1001 from actions/ahpook/v4.8.1-release4552948Bump version for 4.8.1 releasee63da9aMerge pull request #1000 from actions/ahpook/deprecation-redux71365c7(bug) Fix spamming link test in deprecation warning (again)Updates
actions/upload-artifactfrom 4.6.2 to 5.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
330a01cMerge pull request #734 from actions/danwkennedy/prepare-5.0.003f2824Updategithub.dep.yml905a1ecPreparev5.0.02d9f9cdMerge pull request #725 from patrikpolyak/patch-19687587Merge branch 'main' into patch-12848b2cMerge pull request #727 from danwkennedy/patch-19b51177Spell out the first use of GHEScd231caUpdate GHES guidance to include reference to Node 20 versionde65e23Merge pull request #712 from actions/nebuk89-patch-18747d8cUpdate README.mdUpdates
stefanzweifel/git-auto-commit-actionfrom 6.0.1 to 7.0.0Release notes
Sourced from stefanzweifel/git-auto-commit-action's releases.
Changelog
Sourced from stefanzweifel/git-auto-commit-action's changelog.
... (truncated)
Commits
28e16e8Release preparations for v7 (#394)698fd76Merge pull request #391 from EliasBoulharts/custom-tag-messagec40819aUpdate READMEd7ee275Change internal variable namese8684ebFix Tests1949701Merge branch 'master' into pr/391a88dc49Merge pull request #388 from stefanzweifel/v7-nexta531decMerge pull request #386 from stefanzweifel/dependabot/github_actions/actions/...acbe8b1Merge pull request #393 from stefanzweifel/v7-warn-detached-headd185485Enable Detached State CheckUpdates
actions/first-interactionfrom 3.0.0 to 3.1.0Release notes
Sourced from actions/first-interaction's releases.
Commits
1c46889Merge pull request #363 from actions/dependabot/npm_and_yarn/npm-development-...76a99ddDisable checks for dist2ead13cBump the npm-development group across 1 directory with 10 updates2e8e200Merge pull request #361 from actions/dependabot/npm_and_yarn/rollup/rollup-li...df55979Merge pull request #357 from actions/dependabot/npm_and_yarn/octokit/types-15...c056c18Bump@rollup/rollup-linux-x64-gnufrom 4.50.2 to 4.52.3dac371dBump@octokit/typesfrom 14.1.0 to 15.0.033689d3Merge pull request #354 from actions/ncalteen/event8e69b57Merge branch 'main' into ncalteen/event69c5373Merge pull request #351 from actions/dependabot/npm_and_yarn/github/local-act...Updates
oxsecurity/megalinterfrom 9.0.1 to 9.1.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
62c799dRelease MegaLinter v9.1.06158659[automation] Auto-update linters version, help and documentation (#6299)013588achore(deps): update dependency lightning-flow-scanner to v5.6.2 (#6301)ee69172chore(deps): update dependency isort to v6.1.0 (#6300)49e1637chore(deps): update dependency eslint-plugin-jsonc to v2.21.0 (#6298)1db8d0fchore(deps): update dependency eslint to v9.37.0 (#6297)f26af91[automation] Auto-update linters version, help and documentation (#6296)9786a83chore(deps): update dependency cfn-lint to v1.40.0 (#6295)69457fcchore(deps): update dependency azure/bicep to v0.38.33 (#6294)4ae0e6fchore(deps): update dependency npm-groovy-lint to v15.2.2 (#6293)Updates
google/osv-scanner-actionfrom 2.2.3 to 2.2.4Release notes
Sourced from google/osv-scanner-action's releases.
Commits
9bb6957Merge pull request #103 from google/update-to-v2.2.474121baUpdate unified workflow example to point to v2.2.4 reusable workflowsef6f278Update reusable workflows to point to v2.2.4 actionsd510e7d"Update actions to use v2.2.4 osv-scanner image"88da6c4Merge pull request #102 from renovate-bot/renovate/major-workflowsbd508adchore(deps): update github/codeql-action action to v4Updates
actions/setup-nodefrom 5.0.0 to 6.0.0Release notes
Sourced from actions/setup-node's releases.
Commits
2028fbcLimit automatic caching to npm, update workflows and documentation (#1374)1342781Bump actions/publish-action from 0.3.0 to 0.4.0 (#1362)89d709dBump prettier from 2.8.8 to 3.6.2 (#1334)cd2651cBump ts-jest from 29.1.2 to 29.4.1 (#1336)Updates
cicirello/generate-sitemapfrom 1.10.3 to 1.10.4Release notes
Sourced from cicirello/generate-sitemap's releases.
Changelog
Sourced from cicirello/generate-sitemap's changelog.
... (truncated)
Commits
6a56a20Prepare release (#147)73720f8Bump Python to 3.14 (#146)7b922c5Update CHANGELOG.mdc0be12fBump cicirello/pyaction from 3.13.6-gh-2.76.2 to 3.13.7-gh-2.81.0 (#145)5e6dadaupdate python to 3.14 (#144)8b5af0eBump github/codeql-action from 3 to 4 (#143)239c072Bump actions/stale from 9 to 10 (#141)a0631e8Bump actions/setup-python from 5 to 6 (#142)Updates
sobelow/actionfrom 1.0.0 to 1.1.0Release notes
Sourced from sobelow/action's releases.
Commits
a9bf221Merge pull request #2 from quangngd/feature/sobelow-0.1423fd5a6Update elixir version to handle sobelow 0.14.085a7af5Update usage documentationUpdates
rojopolis/spellcheck-github-actionsfrom 0.52.0 to 0.53.0Release notes
Sourced from rojopolis/spellcheck-github-actions's releases.
Changelog
Sourced from rojopolis/spellcheck-github-actions's changelog.
... (truncated)
Commits
336d2b4Bumped version in action.yml and documentation (README)4492229Merge pull request #274 from rojopolis/dependabot/docker/python-e3a6ccbe44d9c...141ebdaMore words in local dictionary9434b6fUpdate to Docker image to use Trixie (slim) instead of Bookwork (also slim) a...84bd099Added cython to local dictionaryd126a3cResolved issue with cython and lxml when building based on this PR2b2d5bfBump python from5fa2567toe3a6ccbfaa1652Merge pull request #271 from rojopolis/dependabot/github_actions/docker/login...eef18eeBump docker/login-action from 3.5.0 to 3.6.019bf2a1Merge pull request #268 from rojopolis/dependabot/github_actions/rojopolis/sp...Updates
actions/stalefrom 10.0.0 to 10.1.0Release notes
Sourced from action...
Description has been truncated