Bump the github-actions group with 5 updates - #3612
Conversation
Bumps the github-actions group with 5 updates: | Package | From | To | | --- | --- | --- | | [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.195` | `1.0.228` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.0.1` | `10.1.0` | | [actions/deploy-pages](https://github.com/actions/deploy-pages) | `5.0.0` | `5.0.1` | | [re-actors/alls-green](https://github.com/re-actors/alls-green) | `1.2.2` | `1.3.0` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.6.2` | `0.6.4` | Updates `anthropics/claude-code-action` from 1.0.195 to 1.0.228 - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@d40ddef...2261fcf) Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@20cfd1b...bec219d) Updates `actions/deploy-pages` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/actions/deploy-pages/releases) - [Commits](actions/deploy-pages@cd2ce8f...368f825) Updates `re-actors/alls-green` from 1.2.2 to 1.3.0 - [Release notes](https://github.com/re-actors/alls-green/releases) - [Commits](re-actors/alls-green@05ac938...b5b5b37) Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@3dc1ecc...cc914d7) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.228 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: astral-sh/setup-uv dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/deploy-pages dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: re-actors/alls-green dependency-version: 1.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, mechanical Dependabot SHA bump across eight workflow files with no other changes.
What was reviewed:
- Confirmed every hunk only swaps a
uses:SHA and its# vX.Y.Zcomment; all step inputs (uvversion:0.9.5/0.12.5,enable-cache,persist-credentials: false, alls-greenjobs:) are untouched, and the CI matrix in shared.yml is unchanged. - docs-preview.yml still passes
enable-cache: falseto the untrusted pull_request_target build, so the cache-isolation comment there still holds with setup-uv v10.1.0 (that release adds apython-runtime-idoutput and NO_PROXY support, no default changes). - alls-green v1.3.0 and claude-code-action v1.0.228 were looked at as candidate behaviour changes and ruled out: neither workflow relies on new or renamed inputs, and the claude-code-action range is routine Claude Code/Agent SDK version bumps.
- Tag-to-SHA resolution was not independently re-verified from this environment (no network); the pins are Dependabot-generated and the claude-code-action SHA matches the commit listed in the PR's compare link.
Extended reasoning...
The diff touches only uses: lines in .github/workflows (claude, conformance, deploy-docs, docs-preview, main, publish-pypi, shared, zizmor), bumping five pinned actions to newer full-SHA pins with matching version comments; 13 lines changed, no code or step inputs. It touches CI/supply-chain surface only, and preserves the repo's existing hygiene (full SHA pins, persist-credentials: false, cache disabled for the untrusted docs-preview build). The change is a small, mechanical Dependabot version bump with no CODEOWNERS file in the repo and no outstanding reviewer objections, which is what decided approve; the one caveat is that tag-to-SHA mapping could not be re-resolved here because network access was unavailable.
One part of this review's analysis that stopped early was run once more. It did not finish.


Bumps the github-actions group with 5 updates:
1.0.1951.0.22810.0.110.1.05.0.05.0.11.2.21.3.00.6.20.6.4Updates
anthropics/claude-code-actionfrom 1.0.195 to 1.0.228Release notes
Sourced from anthropics/claude-code-action's releases.
... (truncated)
Commits
2261fcfchore: bump Claude Code to 2.1.275 and Agent SDK to 0.3.2753b8197dchore: bump Claude Code to 2.1.274 and Agent SDK to 0.3.2747b0b255chore: bump Claude Code to 2.1.273 and Agent SDK to 0.3.273bf38e86chore: bump Claude Code to 2.1.272 and Agent SDK to 0.3.27251db78achore: bump Claude Code to 2.1.271 and Agent SDK to 0.3.2719cdae7fchore: bump Claude Code to 2.1.270 and Agent SDK to 0.3.27056cf60fchore: bump Claude Code to 2.1.269 and Agent SDK to 0.3.2690a8d3c9chore: bump Claude Code to 2.1.268 and Agent SDK to 0.3.26819dda84chore: bump Claude Code to 2.1.267 and Agent SDK to 0.3.2675ccc3a3chore: bump Claude Code to 2.1.266 and Agent SDK to 0.3.266Updates
astral-sh/setup-uvfrom 10.0.1 to 10.1.0Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
bec219dchore(deps-dev): roll up Dependabot updates (#1043)b90ec40fix: respect no proxy directive (#1037)421feb6chore: update known checksums for 0.12.12 (#1041)f634bf4Expose a Python "identity" output (#1036)a6772c8chore: update known checksums for 0.12.10/0.12.11 (#1038)e105c8fchore: update known checksums for 0.12.9 (#1035)cd13f92Verify downloads with astral-sh/versions checksums (#1033)3aef7b9chore: update known checksums for 0.12.7/0.12.8 (#1031)d08d816chore: update known checksums for 0.12.6 (#1030)19b4d1eHarden npm install defaults (#1026)Updates
actions/deploy-pagesfrom 5.0.0 to 5.0.1Release notes
Sourced from actions/deploy-pages's releases.
Commits
368f825Merge pull request #444 from actions/yoannchaudet-deployment-polling-backoff7e97763Validate deployment polling intervals0143e11Add backoff and jitter to deployment polling5e98f10Merge pull request #440 from actions/user/adwitiya8b0625aImprove deployment request test coverageUpdates
re-actors/alls-greenfrom 1.2.2 to 1.3.0Release notes
Sourced from re-actors/alls-green's releases.
Commits
b5b5b37Merge pull request #38 from re-actors/pre-commit-ci-update-configbd6edd6[pre-commit.ci] pre-commit autoupdate3967c81💅 Make the output easier to scane68df08💅 Style job statuses title with a 🔮62d37b2🧪 Unxfail 'success-of-some-allowed-to-skip-or-fail'7b5df6d💅 Add a Codecov badge to README2410c4c🐛 Correct reporting failed skipped jobs6457593💅 Add a GH Sponsors badgea617895💅 Add a pre-commit.ci badge8de05dc🧪 Forcectracecore in coveragepyUpdates
zizmorcore/zizmor-actionfrom 0.6.2 to 0.6.4Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
cc914d7Sync zizmor versions (#166)bae72b7chore(deps): bump the github-actions group with 2 updates (#165)27604f9chore(deps): bump the github-actions group with 2 updates (#164)c41d665README: bump pins (#163)70fb788Sync zizmor versions (#162)7999d8cchore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...2ae1ce9chore(deps): bump github/codeql-action/upload-sarif (#160)951a5eeSkip prerelease versions in sync-zizmor-versions workflow (#158)79f0191chore(deps): bump github/codeql-action/upload-sarif (#156)26a3ae6sync-zizmor-versions: retry up to 5 times (#155)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions