chore(deps): bump the github-actions group with 18 updates#309
Merged
Nick2bad4u merged 1 commit intomainfrom Dec 1, 2025
Merged
Conversation
Bumps the github-actions group with 18 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.13.1` | `2.13.2` | | [actions/checkout](https://github.com/actions/checkout) | `5.0.0` | `6.0.0` | | [devops-actions/actionlint](https://github.com/devops-actions/actionlint) | `0.1.9` | `0.1.10` | | [Platane/snk](https://github.com/platane/snk) | `3.3.0` | `3.4.1` | | [psf/black](https://github.com/psf/black) | `25.9.0` | `25.11.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.31.2` | `4.31.6` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.1` | `4.8.2` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.0.0` | `6.1.0` | | [nick2bad4u/generate-repo-file-list](https://github.com/nick2bad4u/generate-repo-file-list) | `6de1b736f4684d3a8a4260f0bc3aea4ce1493f3f` | `4b742561166c6eafcf23fbb0c79ff8869bbceb27` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `9.1.0` | `9.2.0` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action) | `2.2.4` | `2.3.0` | | [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action) | `2.2.4` | `2.3.0` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.8` | `7.0.9` | | [rojopolis/spellcheck-github-actions](https://github.com/rojopolis/spellcheck-github-actions) | `0.53.0` | `0.55.0` | | [actions/ai-inference](https://github.com/actions/ai-inference) | `2.0.1` | `2.0.4` | | [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.2.1` | `8.3.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.90.12` | `3.91.1` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.39.0` | `1.40.0` | Updates `step-security/harden-runner` from 2.13.1 to 2.13.2 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@f4a75cf...95d9a5d) Updates `actions/checkout` from 5.0.0 to 6.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@08c6903...1af3b93) Updates `devops-actions/actionlint` from 0.1.9 to 0.1.10 - [Release notes](https://github.com/devops-actions/actionlint/releases) - [Commits](devops-actions/actionlint@c6744a3...467e2ce) Updates `Platane/snk` from 3.3.0 to 3.4.1 - [Release notes](https://github.com/platane/snk/releases) - [Commits](Platane/snk@a69d1db...e2cedf7) Updates `psf/black` from 25.9.0 to 25.11.0 - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@af0ba72...05f0a8c) Updates `github/codeql-action` from 4.31.2 to 4.31.6 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@0499de3...fe4161a) Updates `actions/dependency-review-action` from 4.8.1 to 4.8.2 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@40c09b7...3c4e3dc) Updates `actions/setup-python` from 6.0.0 to 6.1.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@e797f83...83679a8) Updates `nick2bad4u/generate-repo-file-list` from 6de1b736f4684d3a8a4260f0bc3aea4ce1493f3f to 4b742561166c6eafcf23fbb0c79ff8869bbceb27 - [Release notes](https://github.com/nick2bad4u/generate-repo-file-list/releases) - [Commits](Nick2bad4u/Generate-Repo-File-List@6de1b73...4b74256) Updates `oxsecurity/megalinter` from 9.1.0 to 9.2.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@62c799d...55a59b2) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from 2.2.4 to 2.3.0 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@9bb6957...b77c075) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from 2.2.4 to 2.3.0 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@9bb6957...b77c075) Updates `peter-evans/create-pull-request` from 7.0.8 to 7.0.9 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@271a8d0...84ae59a) Updates `rojopolis/spellcheck-github-actions` from 0.53.0 to 0.55.0 - [Release notes](https://github.com/rojopolis/spellcheck-github-actions/releases) - [Changelog](https://github.com/rojopolis/spellcheck-github-actions/blob/master/CHANGELOG.md) - [Commits](rojopolis/spellcheck-github-actions@336d2b4...16d0338) Updates `actions/ai-inference` from 2.0.1 to 2.0.4 - [Release notes](https://github.com/actions/ai-inference/releases) - [Commits](actions/ai-inference@a1c1182...334892b) Updates `super-linter/super-linter` from 8.2.1 to 8.3.0 - [Release notes](https://github.com/super-linter/super-linter/releases) - [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md) - [Commits](super-linter/super-linter@2bdd90e...502f4fe) Updates `trufflesecurity/trufflehog` from 3.90.12 to 3.91.1 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@b84c3d1...aade3bf) Updates `crate-ci/typos` from 1.39.0 to 1.40.0 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@07d900b...2d0ce56) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: devops-actions/actionlint dependency-version: 0.1.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: Platane/snk dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: psf/black dependency-version: 25.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.31.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 4.8.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: nick2bad4u/generate-repo-file-list dependency-version: 4b742561166c6eafcf23fbb0c79ff8869bbceb27 dependency-type: direct:production dependency-group: github-actions - dependency-name: oxsecurity/megalinter dependency-version: 9.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: peter-evans/create-pull-request dependency-version: 7.0.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: rojopolis/spellcheck-github-actions dependency-version: 0.55.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/ai-inference dependency-version: 2.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: super-linter/super-linter dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.91.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: crate-ci/typos dependency-version: 1.40.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Owner
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the github-actions group with 18 updates:
2.13.12.13.25.0.06.0.00.1.90.1.103.3.03.4.125.9.025.11.04.31.24.31.64.8.14.8.26.0.06.1.06de1b736f4684d3a8a4260f0bc3aea4ce1493f3f4b742561166c6eafcf23fbb0c79ff8869bbceb279.1.09.2.02.2.42.3.02.2.42.3.07.0.87.0.90.53.00.55.02.0.12.0.48.2.18.3.03.90.123.91.11.39.01.40.0Updates
step-security/harden-runnerfrom 2.13.1 to 2.13.2Release notes
Sourced from step-security/harden-runner's releases.
Commits
95d9a5dMerge pull request #606 from step-security/rc-2887e429dUpdate limitations.mdef891c3feat: add support for custom vm image1fa8c8aupdate agent92c522aMerge pull request #593 from step-security/ak-readme-updates4719ad5README updates4fde639Merge pull request #591 from eromosele-stepsecurity/Updf682f2fUpdate README.mdUpdates
actions/checkoutfrom 5.0.0 to 6.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)Updates
devops-actions/actionlintfrom 0.1.9 to 0.1.10Release notes
Sourced from devops-actions/actionlint's releases.
... (truncated)
Commits
467e2ceUpdate actionlint version to 1.7.9 (#121)5e11a36Bump step-security/harden-runner from 2.13.1 to 2.13.2 (#119)666c887Bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#113)a17659aBump actions/checkout from 4.2.2 to 5.0.0 (#101)21c0ee2Update actionlint version to 1.7.8 (#114)78d8915Bump actions/dependency-review-action from 4.8.0 to 4.8.1 (#115)6b74735Bump github/codeql-action from 3.30.5 to 4.31.2 (#120)b37d855Bump github/codeql-action from 3.30.3 to 3.30.5 (#110)ecd00d8Bump actions/dependency-review-action from 4.7.3 to 4.8.0 (#111)a923f5dBump github/codeql-action from 3.29.8 to 3.30.3 (#108)Updates
Platane/snkfrom 3.3.0 to 3.4.1Release notes
Sourced from Platane/snk's releases.
Commits
e2cedf7📦 3.4.1af8374a🔧 fix gif colormap651a2bc📦 3.4.004ad071↑ update dependencies1474e54📓4364e44✨ add gif implementation benchmarka89ad4c👷 add gif generation tests777a5ccrename animation options + add backgroundColor option for gifa865fcc📓257490f📓Updates
psf/blackfrom 25.9.0 to 25.11.0Release notes
Sourced from psf/black's releases.
Changelog
Sourced from psf/black's changelog.
... (truncated)
Commits
05f0a8cPrepare for 25.11.0 release (#4825)ae17c61Fix tests on pytest 9 (#4835)138745eInclude Windows and Python 3.14 in PR wheel build matrix, fix Windows build (...18170d6ci: add label for running all builds on a pull request (#4833)0e793e3fix windows wheels (#4830)b71f36cUse build[uv] as cibuildwheel frontend (#4831)a7bd594Skip free threaded builds in cibuildwheel (#4829)862dee9Update cibuildwheel (#4828)b5f354cbuild: restrict to pytest 9.0 due to breakage in custom pytest_configure (#4827)f705197t-string support (#4805)Updates
github/codeql-actionfrom 4.31.2 to 4.31.6Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
fe4161aMerge pull request #3336 from github/update-v4.31.6-ecec1f88788c2ab5Update changelog for v4.31.6ecec1f8Merge pull request #3335 from github/mbg/ci/run-codeql-on-all-prs23da732Merge pull request #3334 from github/kaspersv/overlay-minor-commentsf7abc74Remove branch filter for PR event in CodeQL workflow32ada5eMerge branch 'main' into kaspersv/overlay-minor-comments75b2f49Merge pull request #3333 from github/kaspersv/overlay-no-resource-checks-optionf036b1cMerge branch 'main' into kaspersv/overlay-no-resource-checks-option58c5954Add comment to runnerSupportsOverlayAnalysisb02fa13Order feature flags alphabeticallyUpdates
actions/dependency-review-actionfrom 4.8.1 to 4.8.2Release notes
Sourced from actions/dependency-review-action's releases.
Commits
3c4e3dcMerge pull request #1016 from actions/dra-release02930b2Update CONTRIBUTING to reflect new guidelines49ffd9fUpdate CONTRIBUTING to reflect the need to build70cb25e4.8.2 releaseebabd31Merge pull request #1008 from danielhardej/danielhardej-patch-2025102319f9360Update package-lock.json5fd2f98Bump@types/jestto version 29.5.1428647f4Fix PURL parsing by removing encodeURIf620fd1Merge pull request #1013 from actions/dangoor/token-fix9b42b7eRemove bad token referenceUpdates
actions/setup-pythonfrom 6.0.0 to 6.1.0Release notes
Sourced from actions/setup-python's releases.
Commits
83679a8Bump@types/nodefrom 24.1.0 to 24.9.1 and update macos-13 to macos-15-intel ...bfc4944Bump prettier from 3.5.3 to 3.6.2 (#1234)97aeb3eBump requests from 2.32.2 to 2.32.4 in /tests/data (#1130)443da59Bump actions/publish-action from 0.3.0 to 0.4.0 & Documentation update for pi...cfd55cagraalpy: add graalpy early-access and windows builds (#880)bba65e5Bump typescript from 5.4.2 to 5.9.3 and update docs/advanced-usage.md (#1094)18566f8Improve wording and "fix example" (remove 3.13) on testing against pre-releas...2e3e4b1Add support for pip-install input (#1201)4267e28Bump urllib3 from 1.26.19 to 2.5.0 in /tests/data and document breaking c...Updates
nick2bad4u/generate-repo-file-listfrom 6de1b736f4684d3a8a4260f0bc3aea4ce1493f3f to 4b742561166c6eafcf23fbb0c79ff8869bbceb27Commits
4b74256📝 [docs] Update CODE_OF_CONDUCT and add LICENSE fileea827acMerge pull request #36 from Nick2bad4u/dependabot/pip/github-actions-85b6f7c93c78c63b7Merge pull request #37 from Nick2bad4u/dependabot/github_actions/github-actio...06f2895🎨 [style] Remove unnecessary blank line in auto-release workflow0a319d8✨ [feat] Enable manual triggering of auto-release workflow9423e43✨ [feat] Enhance auto-release workflow for version bumping and changelog gene...625f8cfBump the github-actions group with 2 updates8ca785bUpdate pytest requirement in the github-actions groupde6e8c4🧪 [test] Add comprehensive tests for file list generation and configurationac06e0aMerge pull request #35 from Nick2bad4u/dependabot/github_actions/github-actio...Updates
oxsecurity/megalinterfrom 9.1.0 to 9.2.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.