Skip to content

[TON-706] dependabot consolidation#200

Open
g3co wants to merge 23 commits intomasterfrom
feature/dependabot-consolidation
Open

[TON-706] dependabot consolidation#200
g3co wants to merge 23 commits intomasterfrom
feature/dependabot-consolidation

Conversation

@g3co
Copy link
Copy Markdown
Contributor

@g3co g3co commented Apr 10, 2026

Consolidated Dependabot Updates

This PR combines the following Dependabot dependency updates:

GitHub Actions

  • #204 — Bump actions/github-script from 7 to 9
  • #203 — Bump actions/upload-artifact from 4 to 7
  • #202 — Bump actions/download-artifact from 4 to 8
  • #201 — Bump actions/attest-build-provenance from 3 to 4
  • #190 — Bump actions/checkout from 4 to 6

Go

  • #189 — Bump github.com/sirupsen/logrus from 1.9.3 to 1.9.4
  • #186 — Bump golang.org/x/crypto from 0.45.0 to 0.47.0
  • #174 — Bump github.com/redis/go-redis/v9 from 9.16.0 to 9.17.2
  • #173 — Bump github.com/golang-migrate/migrate/v4 from 4.19.0 to 4.19.1

dependabot Bot and others added 15 commits December 2, 2025 01:50
Bumps [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) from 9.16.0 to 9.17.2.
- [Release notes](https://github.com/redis/go-redis/releases)
- [Changelog](https://github.com/redis/go-redis/blob/v9.17.2/RELEASE-NOTES.md)
- [Commits](redis/go-redis@v9.16.0...v9.17.2)

---
updated-dependencies:
- dependency-name: github.com/redis/go-redis/v9
  dependency-version: 9.17.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/golang-migrate/migrate/v4](https://github.com/golang-migrate/migrate) from 4.19.0 to 4.19.1.
- [Release notes](https://github.com/golang-migrate/migrate/releases)
- [Commits](golang-migrate/migrate@v4.19.0...v4.19.1)

---
updated-dependencies:
- dependency-name: github.com/golang-migrate/migrate/v4
  dependency-version: 4.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v5...v6)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.45.0 to 0.47.0.
- [Commits](golang/crypto@v0.45.0...v0.47.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/github-script](https://github.com/actions/github-script) from 7 to 8.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](actions/github-script@v7...v8)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus) from 1.9.3 to 1.9.4.
- [Release notes](https://github.com/sirupsen/logrus/releases)
- [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md)
- [Commits](sirupsen/logrus@v1.9.3...v1.9.4)

---
updated-dependencies:
- dependency-name: github.com/sirupsen/logrus
  dependency-version: 1.9.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…s/download-artifact-7' into feature/dependabot-consolidation
…s/github-script-8' into feature/dependabot-consolidation
…/x/crypto-0.47.0' into feature/dependabot-consolidation
…s/upload-artifact-6' into feature/dependabot-consolidation
…/redis/go-redis/v9-9.17.2' into feature/dependabot-consolidation
…/golang-migrate/migrate/v4-4.19.1' into feature/dependabot-consolidation
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 10, 2026

📊 Performance Metrics

Performance Metrics (memory storage)

  • CPU: 0.77s (4 cores) • Goroutines: 8 • Threads: 7
  • Memory: 7.5MB heap • 37.3MB RAM • 35.2MB total • 241625 allocs
  • GC: 11 cycles (0.45ms avg)
  • FDs: 9/65536 (0.0%)

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 10, 2026

📊 Performance Metrics

Performance Metrics (postgres storage)

  • CPU: 0.89s (4 cores) • Goroutines: 10 • Threads: 7
  • Memory: 17.1MB heap • 46.8MB RAM • 37.6MB total • 261829 allocs
  • GC: 10 cycles (0.44ms avg)
  • FDs: 35/65536 (0.1%)

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 10, 2026

📊 Performance Metrics

Performance Metrics (cluster-valkey storage)

  • CPU: 0.63s (4 cores) • Goroutines: 11 • Threads: 11
  • Memory: 14.5MB heap • 50.8MB RAM • 34.8MB total • 282062 allocs
  • GC: 9 cycles (0.38ms avg)
  • FDs: 71/65536 (0.1%)

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 10, 2026

📊 Performance Metrics

Performance Metrics (nginx storage)

  • CPU: 0.08s (4 cores) • Goroutines: 6 • Threads: 6
  • Memory: 1.3MB heap • 19.4MB RAM • 1.3MB total • 6099 allocs
  • GC: 0 cycles (0ms avg)
  • FDs: 15/65536 (0.0%)

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 10, 2026

📊 Performance Metrics

Performance Metrics (dnsmasq storage)

  • CPU: 0.23s (4 cores) • Goroutines: 11 • Threads: 6
  • Memory: 1.9MB heap • 21.9MB RAM • 9.5MB total • 48911 allocs
  • GC: 6 cycles (0.04ms avg)
  • FDs: 16/65536 (0.0%)

@g3co g3co changed the title dependabot consolidation [TON-706] dependabot consolidation Apr 10, 2026
dependabot Bot and others added 8 commits April 10, 2026 23:44
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@v3...v4)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/github-script](https://github.com/actions/github-script) from 7 to 9.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](actions/github-script@v7...v9)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: '9'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…s/github-script-9' into feature/dependabot-consolidation
…s/upload-artifact-7' into feature/dependabot-consolidation
…s/download-artifact-8' into feature/dependabot-consolidation
…s/attest-build-provenance-4' into feature/dependabot-consolidation
@g3co g3co requested a review from TrueCarry April 14, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant