Skip to content

chore(deps): bump the actions group with 2 updates - #44

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-531acb4541
Jul 13, 2026
Merged

chore(deps): bump the actions group with 2 updates#44
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-531acb4541

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates: hyperpolymath/a2ml-validate-action and hyperpolymath/k9-validate-action.

Updates hyperpolymath/a2ml-validate-action from 59145c7d1039fa3059b3ecacdb50ee23d7505898 to 05bcb78917c09702e90ed18004298a6728753914

Changelog

Sourced from hyperpolymath/a2ml-validate-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[1.0.0] - 2026-05-29

Added

  • Initial Marketplace-ready composite action for validating .a2ml manifests.
  • Configurable path, strict, and paths-ignore inputs.
  • GitHub Actions outputs for scanned files, validation errors, and warnings.

Fixed

  • Allow local smoke runs outside GitHub Actions by defaulting missing GITHUB_OUTPUT to /dev/null.
Commits
  • 05bcb78 ci: Secret Scanner caller must grant the reusable's job permissions (#56)
  • e558e79 fix(ci): clear OSSF Scorecard startup_failure (#55)
  • a1898b7 Revert #53: TOML is not canonical A2ML (spec is S-expr/Djot-like) (#54)
  • db22cd5 feat: canonical A2ML dialect = TOML (warn-by-default, enforce flag) (#53)
  • 7e1cd7e chore(deps): bump the actions group with 3 updates (#52)
  • c14a51a chore(deps): bump the actions group with 2 updates (#51)
  • abcc1a0 fix(clade): correct CLADE uuid (deterministic v5, was template residue) (#50)
  • 4ae6b48 docs: post-canon reference + factual fixes (#49)
  • ac1392a chore(hooks): version-controlled pre-commit + SPDX split by file-type (#48)
  • e8b8079 ci: refresh standards reusable pins to current HEAD (d7c2271) (#47)
  • Additional commits viewable in compare view

Updates hyperpolymath/k9-validate-action from 2d96f43c538964b097d159ed3a56ba5b5ceca227 to bddcd9109ee96f9ea3fdb4bf51084fe9cd0909ce

Changelog

Sourced from hyperpolymath/k9-validate-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[1.0.0] - 2026-05-29

Added

  • Initial Marketplace-ready composite action for validating .k9 and .k9.ncl files.
  • Configurable path, strict, and paths-ignore inputs.
  • GitHub Actions outputs for scanned files, validation errors, and warnings.

Fixed

  • Allow local smoke runs outside GitHub Actions by defaulting missing GITHUB_OUTPUT to /dev/null.
Commits
  • bddcd91 ci: Secret Scanner caller must grant the reusable's job permissions (#35)
  • 3e091a3 chore(deps): bump the actions group with 4 updates (#34)
  • 91e2b6b fix(clade): correct identity uuid (deterministic v5) (#33)
  • b9acd2a chore(deps): bump the actions group with 2 updates (#32)
  • eea3a84 docs(readme): convert README.adoc -> Markdown (renders on Glama/profile/commu...
  • 9f95614 chore(ci): add dormant push-email notification workflow (#30)
  • 90ac96b chore(clade): backfill [status] lifecycle block (#29)
  • 8149729 chore(licence): normalise to MPL-2.0 + CC-BY-SA-4.0 (canonical pair) (#28)
  • 4a64df7 chore(ci): bump standards reusable workflow pins (#27)
  • a842be6 chore(nix->guix): remove flake.nix (Guix-only) (#26)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 2 updates: [hyperpolymath/a2ml-validate-action](https://github.com/hyperpolymath/a2ml-validate-action) and [hyperpolymath/k9-validate-action](https://github.com/hyperpolymath/k9-validate-action).


Updates `hyperpolymath/a2ml-validate-action` from 59145c7d1039fa3059b3ecacdb50ee23d7505898 to 05bcb78917c09702e90ed18004298a6728753914
- [Release notes](https://github.com/hyperpolymath/a2ml-validate-action/releases)
- [Changelog](https://github.com/hyperpolymath/a2ml-validate-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/hyperpolymath/a2ml-validate-action/compare/59145c7d1039fa3059b3ecacdb50ee23d7505898...05bcb78917c09702e90ed18004298a6728753914)

Updates `hyperpolymath/k9-validate-action` from 2d96f43c538964b097d159ed3a56ba5b5ceca227 to bddcd9109ee96f9ea3fdb4bf51084fe9cd0909ce
- [Release notes](https://github.com/hyperpolymath/k9-validate-action/releases)
- [Changelog](https://github.com/hyperpolymath/k9-validate-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/hyperpolymath/k9-validate-action/compare/2d96f43c538964b097d159ed3a56ba5b5ceca227...bddcd9109ee96f9ea3fdb4bf51084fe9cd0909ce)

---
updated-dependencies:
- dependency-name: hyperpolymath/a2ml-validate-action
  dependency-version: 05bcb78917c09702e90ed18004298a6728753914
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: hyperpolymath/k9-validate-action
  dependency-version: bddcd9109ee96f9ea3fdb4bf51084fe9cd0909ce
  dependency-type: direct:production
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 13, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner July 13, 2026 03:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 13, 2026
@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 68 issues detected

Severity Count
🔴 Critical 1
🟠 High 37
🟡 Medium 30

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Issue in scorecard.yml",
    "type": "missing_workflow",
    "file": "scorecard.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit d98625a into main Jul 13, 2026
27 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-531acb4541 branch July 13, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant