Skip to content

action-allowlist-review: bump carabiner-dev/actions from 1.2.0 to 1.2.1 in /.github/actions/for-dependabot-triggered-reviews#911

Merged
potiuk merged 1 commit into
mainfrom
dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/carabiner-dev/actions-1.2.1
Jun 5, 2026
Merged

action-allowlist-review: bump carabiner-dev/actions from 1.2.0 to 1.2.1 in /.github/actions/for-dependabot-triggered-reviews#911
potiuk merged 1 commit into
mainfrom
dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/carabiner-dev/actions-1.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Bumps carabiner-dev/actions from 1.2.0 to 1.2.1.

Release notes

Sourced from carabiner-dev/actions's releases.

v1.2.1

What's Changed

New Contributors

Full Changelog: carabiner-dev/actions@v1.2.0...v1.2.1

Commits
  • 94f2939 Merge pull request #61 from carabiner-dev/update-readme-pins-c4545a008638
  • 6940873 Pin README action examples to latest releases
  • b3ca9f4 Merge pull request #60 from carabiner-dev/zizmor-fixes
  • 50602df Set read permissions on installer tests
  • a009a1f Disable dependabot cooldown
  • 1e967e0 Sanitize directory inputs and handle zizmor messages
  • 90be4db Pin experimental drop image (for zizmor)
  • dae8c5c Merge pull request #59 from TomHennen/fix/actions-template-injection
  • b7cfcb4 ci: add zizmor workflow to guard against template injection
  • c81491e actions: env-thread inputs to fix template injection across composite actions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [carabiner-dev/actions](https://github.com/carabiner-dev/actions) from 1.2.0 to 1.2.1.
- [Release notes](https://github.com/carabiner-dev/actions/releases)
- [Commits](carabiner-dev/actions@v1.2.0...v1.2.1)

---
updated-dependencies:
- dependency-name: carabiner-dev/actions
  dependency-version: 1.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 4, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 4, 2026
@potiuk
Copy link
Copy Markdown
Member

potiuk commented Jun 5, 2026

Safe to merge: Dependabot SHA bump of carabiner actions on if: false steps in the dependabot-review composite. No executable change. All checks green, including verify.

Copy link
Copy Markdown
Member

@potiuk potiuk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed: green CI, low-risk change as described in the merge note. Approving to merge.

@potiuk potiuk merged commit 2b04b6b into main Jun 5, 2026
9 checks passed
@potiuk potiuk deleted the dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/carabiner-dev/actions-1.2.1 branch June 5, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant