Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 18, 2025

Bumps the github-actions-dependencies group with 6 updates in the / directory:

Package From To
hoverkraft-tech/ci-github-publish/.github/workflows/release-actions.yml 0.17.3 0.18.2
hoverkraft-tech/ci-github-nodejs/.github/workflows/continuous-integration.yml 0.20.6 0.21.0
hoverkraft-tech/ci-github-nodejs 0.20.6 0.21.0
github/codeql-action 4.31.7 4.31.9
tj-actions/changed-files 47.0.0 47.0.1

Updates hoverkraft-tech/ci-github-publish/.github/workflows/release-actions.yml from 0.17.3 to 0.18.2

Release notes

Sourced from hoverkraft-tech/ci-github-publish/.github/workflows/release-actions.yml's releases.

0.18.2

Release Summary

Actions and workflows documentation has been refreshed for clarity and accuracy.

Internal: GitHub Actions dependencies were updated in one directory (2 updates) via Dependabot to keep the pipeline current.

Breaking change(s)

No breaking changes.

What's Changed

Full Changelog: hoverkraft-tech/ci-github-publish@0.18.1...0.18.2

0.18.1

Release Summary

Fix (deploy/jenkins): escape Liquid tags in Markdown during Jenkins deploy to avoid misrendering.

Internal: documentation for actions/workflows was refreshed; GitHub Actions dependencies were bumped across multiple directories.

Breaking changes

No breaking changes.

What's Changed

Full Changelog: hoverkraft-tech/ci-github-publish@0.18.0...0.18.1

0.18.0

Release Summary

deploy/argocd-manifest-files: added ARGOCD_MULTI_SOURCES environment variable to distinguish source types. deploy/jekyll: supports path configuration, additional assets and HTML pages. deploy-chart: set proper permissions. deploy/argocd-manifest-files: fixed to update only chart-related sources.

Internal: documentation refreshed and GitHub Actions dependencies bumped (multiple directories).

... (truncated)

Commits
  • 642cdb5 build(deps): Bump the github-actions-dependencies group across 1 directory wi...
  • 22c3f43 docs: update actions and workflows documentation
  • daee440 build(deps): Bump the github-actions-dependencies group across 4 directories ...
  • 108449f chore: fix lint issues
  • 7fb1bef fix(deploy/jenkins): escape liquid tags for markdown files
  • 817ae62 docs: update actions and workflows documentation
  • 7d2435d chore: fix lint issues
  • bd93fcc Merge pull request #304 from hoverkraft-tech/dependabot/github_actions/github...
  • 887f63e build(deps): Bump the github-actions-dependencies group across 2 directories ...
  • 0c2ad43 docs: update actions and workflows documentation
  • Additional commits viewable in compare view

Updates hoverkraft-tech/ci-github-nodejs/.github/workflows/continuous-integration.yml from 0.20.6 to 0.21.0

Release notes

Sourced from hoverkraft-tech/ci-github-nodejs/.github/workflows/continuous-integration.yml's releases.

0.21.0

Release Summary

setup-node: added support for the registry-url input to configure npm registry resolution.

Internal: refreshed GitHub Actions (8 updates across 4 directories) and npm dependencies (2 updates across 4 directories), aligned container workflow to 0.30.3, and updated actions/workflows documentation.

Breaking changes

No breaking changes.

What's Changed

Full Changelog: hoverkraft-tech/ci-github-nodejs@0.20.6...0.21.0

Commits
  • 25ef8d9 chore(deps): bump hoverkraft-tech/ci-github-container/.github/workflows/docke...
  • 6287902 chore(deps): bump the npm-dependencies group across 4 directories with 2 updates
  • 5c8a917 chore(deps): bump the github-actions-dependencies group across 4 directories ...
  • ccfb260 docs: update actions and workflows documentation
  • 1f9e53e feat(setup-node): add support for registry-url input
  • 01c2471 docs: update actions and workflows documentation
  • See full diff in compare view

Updates hoverkraft-tech/ci-github-nodejs from 0.20.6 to 0.21.0

Release notes

Sourced from hoverkraft-tech/ci-github-nodejs's releases.

0.21.0

Release Summary

setup-node: added support for the registry-url input to configure npm registry resolution.

Internal: refreshed GitHub Actions (8 updates across 4 directories) and npm dependencies (2 updates across 4 directories), aligned container workflow to 0.30.3, and updated actions/workflows documentation.

Breaking changes

No breaking changes.

What's Changed

Full Changelog: hoverkraft-tech/ci-github-nodejs@0.20.6...0.21.0

Commits
  • 25ef8d9 chore(deps): bump hoverkraft-tech/ci-github-container/.github/workflows/docke...
  • 6287902 chore(deps): bump the npm-dependencies group across 4 directories with 2 updates
  • 5c8a917 chore(deps): bump the github-actions-dependencies group across 4 directories ...
  • ccfb260 docs: update actions and workflows documentation
  • 1f9e53e feat(setup-node): add support for registry-url input
  • 01c2471 docs: update actions and workflows documentation
  • See full diff in compare view

Updates github/codeql-action from 4.31.7 to 4.31.9

Release notes

Sourced from github/codeql-action's releases.

v4.31.9

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.9 - 16 Dec 2025

No user facing changes.

See the full CHANGELOG.md for more information.

v4.31.8

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.8 - 11 Dec 2025

  • Update default CodeQL bundle version to 2.23.8. #3354

See the full CHANGELOG.md for more information.

Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.31.9 - 16 Dec 2025

No user facing changes.

4.31.8 - 11 Dec 2025

  • Update default CodeQL bundle version to 2.23.8. #3354

4.31.7 - 05 Dec 2025

  • Update default CodeQL bundle version to 2.23.7. #3343

4.31.6 - 01 Dec 2025

No user facing changes.

4.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #3321

4.31.4 - 18 Nov 2025

No user facing changes.

4.31.3 - 13 Nov 2025

  • CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
  • Update default CodeQL bundle version to 2.23.5. #3288

4.31.2 - 30 Oct 2025

No user facing changes.

4.31.1 - 30 Oct 2025

  • The add-snippets input has been removed from the analyze action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

4.31.0 - 24 Oct 2025

  • Bump minimum CodeQL bundle version to 2.17.6. #3223
  • When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #3222

... (truncated)

Commits
  • 5d4e8d1 Merge pull request #3371 from github/update-v4.31.9-998798e34
  • 1dc115f Update changelog for v4.31.9
  • 998798e Merge pull request #3352 from github/nickrolfe/jar-min-ff-cleanup
  • 5eb7519 Merge pull request #3358 from github/henrymercer/database-upload-telemetry
  • d29eddb Extract version number to constant
  • e962687 Merge branch 'main' into henrymercer/database-upload-telemetry
  • 19c7f96 Rename isOverlayBase
  • ae5de9a Use getErrorMessage in log too
  • 0cb8633 Prefer performance.now()
  • c07cc0d Merge pull request #3351 from github/henrymercer/ghec-dr-determine-tools-vers...
  • Additional commits viewable in compare view

Updates tj-actions/changed-files from 47.0.0 to 47.0.1

Release notes

Sourced from tj-actions/changed-files's releases.

v47.0.1

What's Changed

Full Changelog: tj-actions/changed-files@v47...v47.0.1

Commits
  • e002140 chore(deps): bump actions/checkout from 6.0.0 to 6.0.1 (#2729)
  • 01ddfae chore(deps): bump @​actions/core from 1.11.1 to 2.0.0 (#2736)
  • a364493 chore(deps-dev): bump prettier from 3.7.1 to 3.7.4 (#2731)
  • 45a2aae chore(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#2730)
  • a4f6de3 chore(deps): bump github/codeql-action from 4.31.5 to 4.31.7 (#2732)
  • 95fbe9b chore(deps): bump peter-evans/create-pull-request from 7.0.9 to 8.0.0 (#2735)
  • b3b9724 chore(deps-dev): bump ts-jest from 29.4.5 to 29.4.6 (#2727)
  • 503bc3e chore(deps): bump @​actions/exec from 1.1.1 to 2.0.0 (#2737)
  • 3e9e5a2 chore(deps-dev): bump @​types/node from 24.10.1 to 25.0.0 (#2738)
  • 2b6c719 chore(deps): bump yaml from 2.8.1 to 2.8.2 (#2724)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Dec 18, 2025
@github-actions
Copy link
Contributor

Hi, thank you for creating your PR, we will check it out very soon

@neilime neilime force-pushed the dependabot/github_actions/github-actions-dependencies-e62c7c4520 branch from 3377609 to a8fd89c Compare December 18, 2025 12:10
…ctory with 5 updates

Bumps the github-actions-dependencies group with 5 updates in the / directory:

---
updated-dependencies:
- dependency-name: hoverkraft-tech/ci-github-publish/.github/workflows/release-actions.yml
  dependency-version: 0.18.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-dependencies
- dependency-name: hoverkraft-tech/ci-github-nodejs/.github/workflows/continuous-integration.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-dependencies
- dependency-name: hoverkraft-tech/ci-github-nodejs
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-dependencies
- dependency-name: github/codeql-action
  dependency-version: 4.31.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
- dependency-name: tj-actions/changed-files
  dependency-version: 47.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Emilien Escalle <emilien.escalle@escemi.com>
@neilime neilime force-pushed the dependabot/github_actions/github-actions-dependencies-e62c7c4520 branch from a8fd89c to 9d57e40 Compare December 18, 2025 12:11
@neilime neilime changed the title chore(deps): bump the github-actions-dependencies group across 1 directory with 6 updates chore(deps): bump the github-actions-dependencies group across 1 directory with 5 updates Dec 18, 2025
@neilime neilime merged commit 89a9a4d into main Dec 18, 2025
34 checks passed
@neilime neilime deleted the dependabot/github_actions/github-actions-dependencies-e62c7c4520 branch December 18, 2025 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants