Skip to content

Bump the github-actions group with 5 updates - #3612

Merged
Kludex merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-708b7d4600
Oct 1, 2026
Merged

Kludex merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-708b7d4600

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 5 updates:

Package From To
anthropics/claude-code-action 1.0.195 1.0.228
astral-sh/setup-uv 10.0.1 10.1.0
actions/deploy-pages 5.0.0 5.0.1
re-actors/alls-green 1.2.2 1.3.0
zizmorcore/zizmor-action 0.6.2 0.6.4

Updates anthropics/claude-code-action from 1.0.195 to 1.0.228

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.228

Full Changelog: anthropics/claude-code-action@v1.0.227...v1.0.228

v1.0.227

Full Changelog: anthropics/claude-code-action@v1.0.226...v1.0.227

v1.0.226

Full Changelog: anthropics/claude-code-action@v1.0.225...v1.0.226

v1.0.225

Full Changelog: anthropics/claude-code-action@v1.0.224...v1.0.225

v1.0.224

Full Changelog: anthropics/claude-code-action@v1.0.223...v1.0.224

v1.0.223

Full Changelog: anthropics/claude-code-action@v1.0.222...v1.0.223

v1.0.222

Full Changelog: anthropics/claude-code-action@v1.0.221...v1.0.222

v1.0.221

Full Changelog: anthropics/claude-code-action@v1.0.220...v1.0.221

v1.0.220

Full Changelog: anthropics/claude-code-action@v1.0.219...v1.0.220

v1.0.219

Full Changelog: anthropics/claude-code-action@v1.0.218...v1.0.219

v1.0.218

Full Changelog: anthropics/claude-code-action@v1.0.217...v1.0.218

v1.0.217

Full Changelog: anthropics/claude-code-action@v1.0.216...v1.0.217

v1.0.216

Full Changelog: anthropics/claude-code-action@v1.0.215...v1.0.216

v1.0.215

Full Changelog: anthropics/claude-code-action@v1.0.214...v1.0.215

v1.0.214

Full Changelog: anthropics/claude-code-action@v1.0.213...v1.0.214

v1.0.213

Full Changelog: anthropics/claude-code-action@v1.0.212...v1.0.213

v1.0.212

Full Changelog: anthropics/claude-code-action@v1.0.211...v1.0.212

... (truncated)

Commits
  • 2261fcf chore: bump Claude Code to 2.1.275 and Agent SDK to 0.3.275
  • 3b8197d chore: bump Claude Code to 2.1.274 and Agent SDK to 0.3.274
  • 7b0b255 chore: bump Claude Code to 2.1.273 and Agent SDK to 0.3.273
  • bf38e86 chore: bump Claude Code to 2.1.272 and Agent SDK to 0.3.272
  • 51db78a chore: bump Claude Code to 2.1.271 and Agent SDK to 0.3.271
  • 9cdae7f chore: bump Claude Code to 2.1.270 and Agent SDK to 0.3.270
  • 56cf60f chore: bump Claude Code to 2.1.269 and Agent SDK to 0.3.269
  • 0a8d3c9 chore: bump Claude Code to 2.1.268 and Agent SDK to 0.3.268
  • 19dda84 chore: bump Claude Code to 2.1.267 and Agent SDK to 0.3.267
  • 5ccc3a3 chore: bump Claude Code to 2.1.266 and Agent SDK to 0.3.266
  • Additional commits viewable in compare view

Updates astral-sh/setup-uv from 10.0.1 to 10.1.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits

Updates actions/deploy-pages from 5.0.0 to 5.0.1

Release notes

Sourced from actions/deploy-pages's releases.

v5.0.1

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

Commits
  • 368f825 Merge pull request #444 from actions/yoannchaudet-deployment-polling-backoff
  • 7e97763 Validate deployment polling intervals
  • 0143e11 Add backoff and jitter to deployment polling
  • 5e98f10 Merge pull request #440 from actions/user/adwitiya
  • 8b0625a Improve deployment request test coverage
  • See full diff in compare view

Updates re-actors/alls-green from 1.2.2 to 1.3.0

Release notes

Sourced from re-actors/alls-green's releases.

v1.3.0

🛡️ What's Unmessed

[!caution]

There was a small command injection risk in prior versions. I consider it very low because of the specifics of the action use case. But still, do upgrade, okay?

@​illera88💰 fixed this template injection bug in #37 by passing inputs via env vars.

See GHSA-gj76-h2ch-5m76 for more detail that was first reported by @​Corbynx010💰 while I was at EuroPython.

✨ What's Improved

I did a bunch of internal refactoring including hints of what @​max-sixty💰 reported in #23. And took a small patch of @​krokofant💰 in. This involved a bunch of preparatory infra work with testing infra.

One notable improvement is that now thanks to @​tomasr8💰's and @​hugovk💰's UX suggestions in #31, the gate status output is colored in the console and should be easier to scan in the log output per line. They entries now have leading ✓/❌ acceptance marks and the actual incoming job outcomes are labeled with 🟢/🔴/⬜/⚫.

🐛 What's Fixed

The job-statuses summary could print "Some of the allowed to be skipped jobs did not succeed" based on the wrong condition — it's now tied to allowed-skips as intended, not allowed-failures.

💪 New Contributors

🪞 Full Diff: re-actors/alls-green@v1.2.2...v1.3.0

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.

GH Sponsors badge

Commits
  • b5b5b37 Merge pull request #38 from re-actors/pre-commit-ci-update-config
  • bd6edd6 [pre-commit.ci] pre-commit autoupdate
  • 3967c81 💅 Make the output easier to scan
  • e68df08 💅 Style job statuses title with a 🔮
  • 62d37b2 🧪 Unxfail 'success-of-some-allowed-to-skip-or-fail'
  • 7b5df6d 💅 Add a Codecov badge to README
  • 2410c4c 🐛 Correct reporting failed skipped jobs
  • 6457593 💅 Add a GH Sponsors badge
  • a617895 💅 Add a pre-commit.ci badge
  • 8de05dc 🧪 Force ctrace core in coveragepy
  • Additional commits viewable in compare view

Updates zizmorcore/zizmor-action from 0.6.2 to 0.6.4

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.4

Sponsorship is appreciated!

zizmor 1.30.1 is now the default version.

Release notes: zizmorcore/zizmor-action#1301

v0.6.3

zizmor 1.30.0 is now the default version.

Release notes: zizmorcore/zizmor-action#1300

Commits
  • cc914d7 Sync zizmor versions (#166)
  • bae72b7 chore(deps): bump the github-actions group with 2 updates (#165)
  • 27604f9 chore(deps): bump the github-actions group with 2 updates (#164)
  • c41d665 README: bump pins (#163)
  • 70fb788 Sync zizmor versions (#162)
  • 7999d8c chore(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 in ...
  • 2ae1ce9 chore(deps): bump github/codeql-action/upload-sarif (#160)
  • 951a5ee Skip prerelease versions in sync-zizmor-versions workflow (#158)
  • 79f0191 chore(deps): bump github/codeql-action/upload-sarif (#156)
  • 26a3ae6 sync-zizmor-versions: retry up to 5 times (#155)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.195` | `1.0.228` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.0.1` | `10.1.0` |
| [actions/deploy-pages](https://github.com/actions/deploy-pages) | `5.0.0` | `5.0.1` |
| [re-actors/alls-green](https://github.com/re-actors/alls-green) | `1.2.2` | `1.3.0` |
| [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.6.2` | `0.6.4` |


Updates `anthropics/claude-code-action` from 1.0.195 to 1.0.228
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@d40ddef...2261fcf)

Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@20cfd1b...bec219d)

Updates `actions/deploy-pages` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@cd2ce8f...368f825)

Updates `re-actors/alls-green` from 1.2.2 to 1.3.0
- [Release notes](https://github.com/re-actors/alls-green/releases)
- [Commits](re-actors/alls-green@05ac938...b5b5b37)

Updates `zizmorcore/zizmor-action` from 0.6.2 to 0.6.4
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@3dc1ecc...cc914d7)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.228
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: re-actors/alls-green
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, mechanical Dependabot SHA bump across eight workflow files with no other changes.

What was reviewed:

  • Confirmed every hunk only swaps a uses: SHA and its # vX.Y.Z comment; all step inputs (uv version: 0.9.5/0.12.5, enable-cache, persist-credentials: false, alls-green jobs:) are untouched, and the CI matrix in shared.yml is unchanged.
  • docs-preview.yml still passes enable-cache: false to the untrusted pull_request_target build, so the cache-isolation comment there still holds with setup-uv v10.1.0 (that release adds a python-runtime-id output and NO_PROXY support, no default changes).
  • alls-green v1.3.0 and claude-code-action v1.0.228 were looked at as candidate behaviour changes and ruled out: neither workflow relies on new or renamed inputs, and the claude-code-action range is routine Claude Code/Agent SDK version bumps.
  • Tag-to-SHA resolution was not independently re-verified from this environment (no network); the pins are Dependabot-generated and the claude-code-action SHA matches the commit listed in the PR's compare link.
Extended reasoning...

The diff touches only uses: lines in .github/workflows (claude, conformance, deploy-docs, docs-preview, main, publish-pypi, shared, zizmor), bumping five pinned actions to newer full-SHA pins with matching version comments; 13 lines changed, no code or step inputs. It touches CI/supply-chain surface only, and preserves the repo's existing hygiene (full SHA pins, persist-credentials: false, cache disabled for the untrusted docs-preview build). The change is a small, mechanical Dependabot version bump with no CODEOWNERS file in the repo and no outstanding reviewer objections, which is what decided approve; the one caveat is that tag-to-SHA mapping could not be re-resolved here because network access was unavailable.

One part of this review's analysis that stopped early was run once more. It did not finish.

@Kludex
Kludex merged commit 17aaf25 into main Oct 1, 2026
37 checks passed
@Kludex
Kludex deleted the dependabot/github_actions/github-actions-708b7d4600 branch October 1, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant