Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 21, 2025

Bumps NVIDIA/holodeck from 0.2.13 to 0.2.17.

Release notes

Sourced from NVIDIA/holodeck's releases.

v0.2.17

What's Changed

New Contributors

Full Changelog: NVIDIA/holodeck@v0.2.16...v0.2.17

v0.2.16

What's Changed

Full Changelog: NVIDIA/holodeck@v0.2.15...v0.2.16

... (truncated)

Commits
  • 91536fb Merge pull request #522 from NVIDIA/main
  • 8a44398 Merge pull request #519 from NVIDIA/dependabot/go_modules/main/github.com/aws...
  • 4a42d4f Bump github.com/aws/aws-sdk-go-v2/service/ssm from 1.64.3 to 1.65.1
  • fa0c8bf Merge pull request #520 from NVIDIA/dependabot/go_modules/main/golang.org/x/c...
  • 04372f8 Bump golang.org/x/crypto from 0.42.0 to 0.43.0
  • 7d09ce0 Merge pull request #521 from NVIDIA/dependabot/go_modules/main/github.com/aws...
  • 25ddd9d Bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.251.0 to 1.254.1
  • 8bf6e8c Merge pull request #518 from NVIDIA/dependabot/github_actions/main/aws-action...
  • 496df33 Bump aws-actions/configure-aws-credentials from 5 to 6
  • a6ca8f4 Merge pull request #516 from NVIDIA/dependabot/docker/main/golang-1.25.2-book...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [NVIDIA/holodeck](https://github.com/nvidia/holodeck) from 0.2.13 to 0.2.17.
- [Release notes](https://github.com/nvidia/holodeck/releases)
- [Commits](NVIDIA/holodeck@v0.2.13...v0.2.17)

---
updated-dependencies:
- dependency-name: NVIDIA/holodeck
  dependency-version: 0.2.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Issue/PR Pull about a dependency file maintenance Issue/PR to create or address a team project management need labels Oct 21, 2025
@copy-pr-bot
Copy link

copy-pr-bot bot commented Oct 21, 2025

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ArangoGutierrez ArangoGutierrez self-requested a review November 4, 2025 15:49
@ArangoGutierrez
Copy link
Collaborator

@elezar do we want to update .github related things for maintenance branches?

@elezar
Copy link
Member

elezar commented Nov 6, 2025

Which workflows are branch specific? Dependabot is main only, for example.

@ArangoGutierrez
Copy link
Collaborator

Which workflows are branch specific? Dependabot is main only, for example.

I mean PR's like #1390 and #1391 (as examples)
Workflows that are on maintenance branches, and dependabot updates them from time to time

@elezar
Copy link
Member

elezar commented Nov 12, 2025

Whether we need to update them depends on what the updates are for. In the case of action updates that are involved in producing the release artifacts, I would argue that we should update them but we may want to limit these updates to security relevant updates. (Note that in the case of some actions, it's less overhead to just update them regardless).

@elezar elezar merged commit ccac343 into release-1.18 Nov 12, 2025
3 checks passed
@dependabot dependabot bot deleted the dependabot/github_actions/release-1.18/NVIDIA/holodeck-0.2.17 branch November 12, 2025 09:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Issue/PR Pull about a dependency file maintenance Issue/PR to create or address a team project management need

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants