Skip to content

Comments

Update GitHub Actions#106

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/github-actions
Open

Update GitHub Actions#106
renovate[bot] wants to merge 1 commit intomainfrom
renovate/github-actions

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 31, 2026

This PR contains the following updates:

Package Type Update Change Pending
actions/attest-build-provenance action minor v3.1.0v3.2.0
actions/cache action patch v5.0.2v5.0.3
aquasecurity/trivy-action action minor v0.33.10.34.0 0.34.1
docker/build-push-action action minor v6.18.0v6.19.2
docker/login-action action minor v3.6.0v3.7.0
github/codeql-action action minor v4.31.11v4.32.3 v4.32.4
hoverkraft-tech/compose-action action minor v2.4.3v2.5.0
zizmorcore/zizmor-action action minor v0.4.1v0.5.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v3.2.0

Compare Source

What's Changed

Full Changelog: actions/attest-build-provenance@v3.1.0...v3.2.0

actions/cache (actions/cache)

v5.0.3

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

aquasecurity/trivy-action (aquasecurity/trivy-action)

v0.34.0

Compare Source

What's Changed

Full Changelog: aquasecurity/trivy-action@0.33.1...0.34.0

docker/build-push-action (docker/build-push-action)

v6.19.2

Compare Source

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Compare Source

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Compare Source

  • Scope default git auth token to github.com by @​crazy-max in #​1451
  • Bump brace-expansion from 1.1.11 to 1.1.12 in #​1396
  • Bump form-data from 2.5.1 to 2.5.5 in #​1391
  • Bump js-yaml from 3.14.1 to 3.14.2 in #​1429
  • Bump lodash from 4.17.21 to 4.17.23 in #​1446
  • Bump tmp from 0.2.3 to 0.2.4 in #​1398
  • Bump undici from 5.28.4 to 5.29.0 in #​1397

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

docker/login-action (docker/login-action)

v3.7.0

Compare Source

Full Changelog: docker/login-action@v3.6.0...v3.7.0

github/codeql-action (github/codeql-action)

v4.32.3

Compare Source

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #​3466

v4.32.2

Compare Source

v4.32.1

Compare Source

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #​3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #​3421

v4.32.0

Compare Source

hoverkraft-tech/compose-action (hoverkraft-tech/compose-action)

v2.5.0

Compare Source

Release Summary

Fix ensures docker-compose is installed when a compose-version is specified, improving reliability, and documentation for actions and workflows has been updated.

Internal: deps scope updates (actions/checkout, docker/setup-docker-action, docker-compose, npm/actions groups) and minor refactoring.

Breaking change(s)

No breaking changes.

What's Changed

New Contributors

Full Changelog: hoverkraft-tech/compose-action@v2...v2.5.0

zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.5.0

Compare Source

What's Changed

New Contributors

Full Changelog: zizmorcore/zizmor-action@v0.4.1...v0.5.0


Configuration

📅 Schedule: Branch creation - "every weekend" in timezone UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@greptile-apps
Copy link

greptile-apps bot commented Jan 31, 2026

Greptile Overview

Greptile Summary

This PR updates the github/codeql-action from v4.31.10 to v4.31.11, a routine patch version update that brings improved error handling and stability improvements.

  • Updated SHA hash for github/codeql-action/upload-sarif action in the Trivy security scanning job
  • No breaking changes or behavioral modifications
  • Patch version includes improved error handling throughout the action

Confidence Score: 5/5

  • This PR is safe to merge with minimal risk - it's a routine patch update from a trusted GitHub action
  • This is a standard automated dependency update for a trusted GitHub-maintained action. The change is minimal (single SHA hash update), the version increment is a patch release with no breaking changes, and the release notes indicate only improvements (error handling, artifact naming). The action is pinned to a specific SHA for security, and the workflow permissions are already properly scoped.
  • No files require special attention

Important Files Changed

Filename Overview
.github/workflows/regular.yaml Updated github/codeql-action/upload-sarif from v4.31.10 to v4.31.11 (patch version bump with improved error handling)

@renovate renovate bot force-pushed the renovate/github-actions branch from 027a066 to 528e3e1 Compare January 31, 2026 10:39
@codecov
Copy link

codecov bot commented Jan 31, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@renovate renovate bot force-pushed the renovate/github-actions branch from 528e3e1 to 27342f4 Compare February 2, 2026 18:10
@renovate renovate bot changed the title Update github/codeql-action action to v4.31.11 Update actions/attest-build-provenance action to v3.2.0 Feb 2, 2026
@renovate renovate bot force-pushed the renovate/github-actions branch from 27342f4 to 3fda48c Compare February 2, 2026 23:14
@renovate renovate bot changed the title Update actions/attest-build-provenance action to v3.2.0 Update GitHub Actions Feb 2, 2026
@renovate renovate bot force-pushed the renovate/github-actions branch 4 times, most recently from 82c475a to 05fdac3 Compare February 9, 2026 18:45
@renovate renovate bot force-pushed the renovate/github-actions branch 2 times, most recently from f1e69a0 to fea666f Compare February 12, 2026 23:29
@renovate renovate bot force-pushed the renovate/github-actions branch 4 times, most recently from 7c2f2b5 to c54dd85 Compare February 19, 2026 22:00
@renovate renovate bot force-pushed the renovate/github-actions branch from c54dd85 to fab9bee Compare February 20, 2026 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants