ci(deps): bump the actions group with 13 updates#35
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
ci(deps): bump the actions group with 13 updates#35dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the actions group with 13 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `5.0.0` | `6.0.1` | | [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) | `2.8.0` | `2.8.2` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.62.46` | `2.62.62` | | [EnricoMi/publish-unit-test-result-action](https://github.com/enricomi/publish-unit-test-result-action) | `2.17.1` | `2.21.0` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.1.1` | `5.5.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.4.1` | `2.5.0` | | [slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml](https://github.com/slsa-framework/slsa-github-generator) | `f701310a334f5d712a8869541c8e19ecb4eefc24` | `a09dd8c05eda63cace134cb7dccd7e019f25e6f3` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.7.1` | `3.11.1` | | [docker/login-action](https://github.com/docker/login-action) | `3.3.0` | `3.6.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.5.1` | `5.10.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.9.0` | `6.18.0` | | [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `2.0.1` | `2.0.14` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `45529485b5eb76184ced07362d2331fd9d26f03f` | `774d14bf50b7a2e2460f9f49e25c52503ecab125` | Updates `actions/checkout` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@08c6903...8e8c483) Updates `Swatinem/rust-cache` from 2.8.0 to 2.8.2 - [Release notes](https://github.com/swatinem/rust-cache/releases) - [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md) - [Commits](Swatinem/rust-cache@98c8021...779680d) Updates `taiki-e/install-action` from 2.62.46 to 2.62.62 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@f535147...493d7f2) Updates `EnricoMi/publish-unit-test-result-action` from 2.17.1 to 2.21.0 - [Release notes](https://github.com/enricomi/publish-unit-test-result-action/releases) - [Commits](EnricoMi/publish-unit-test-result-action@82082da...34d7c95) Updates `codecov/codecov-action` from 5.1.1 to 5.5.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@7f8b4b4...5a10915) Updates `softprops/action-gh-release` from 2.4.1 to 2.5.0 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@6da8fa9...a06a81a) Updates `slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml` from f701310a334f5d712a8869541c8e19ecb4eefc24 to a09dd8c05eda63cace134cb7dccd7e019f25e6f3 - [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases) - [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md) - [Commits](slsa-framework/slsa-github-generator@f701310...a09dd8c) Updates `docker/setup-buildx-action` from 3.7.1 to 3.11.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@c47758b...e468171) Updates `docker/login-action` from 3.3.0 to 3.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...5e57cd1) Updates `docker/metadata-action` from 5.5.1 to 5.10.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@8e5442c...c299e40) Updates `docker/build-push-action` from 6.9.0 to 6.18.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@4f58ea7...2634353) Updates `EmbarkStudios/cargo-deny-action` from 2.0.1 to 2.0.14 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@8371184...76cd80e) Updates `actions/dependency-review-action` from 45529485b5eb76184ced07362d2331fd9d26f03f to 774d14bf50b7a2e2460f9f49e25c52503ecab125 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@4552948...774d14b) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: Swatinem/rust-cache dependency-version: 2.8.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: taiki-e/install-action dependency-version: 2.62.62 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: EnricoMi/publish-unit-test-result-action dependency-version: 2.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: codecov/codecov-action dependency-version: 5.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: softprops/action-gh-release dependency-version: 2.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml dependency-version: a09dd8c05eda63cace134cb7dccd7e019f25e6f3 dependency-type: direct:production dependency-group: actions - dependency-name: docker/setup-buildx-action dependency-version: 3.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/login-action dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/metadata-action dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: docker/build-push-action dependency-version: 6.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 2.0.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: actions/dependency-review-action dependency-version: 774d14bf50b7a2e2460f9f49e25c52503ecab125 dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Dec 4, 2025
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 13 updates:
5.0.06.0.12.8.02.8.22.62.462.62.622.17.12.21.05.1.15.5.12.4.12.5.0f701310a334f5d712a8869541c8e19ecb4eefc24a09dd8c05eda63cace134cb7dccd7e019f25e6f33.7.13.11.13.3.03.6.05.5.15.10.06.9.06.18.02.0.12.0.1445529485b5eb76184ced07362d2331fd9d26f03f774d14bf50b7a2e2460f9f49e25c52503ecab125Updates
actions/checkoutfrom 5.0.0 to 6.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)Updates
Swatinem/rust-cachefrom 2.8.0 to 2.8.2Release notes
Sourced from Swatinem/rust-cache's releases.
Changelog
Sourced from Swatinem/rust-cache's changelog.
... (truncated)
Commits
779680d2.8.22ea64efBump smol-toml from 1.4.2 to 1.5.2 in the prd-minor group (#287)8930d9cBump the actions group with 3 updates (#288)c071727Bump@actions/iofrom 1.1.3 to 2.0.0 in the prd-major group (#281)f2a41b7Bump@types/nodefrom 24.9.0 to 24.10.0 in the dev-minor group (#282)e306f83Don't overwrite env for cargo-metadata call (#285)c911900Merge pull request #284 from Swatinem/dependabot/github_actions/actions-baeb0...3aaed55Bump the actions group with 2 updates972b315Merge pull request #283 from Swatinem/dependabot/github_actions/actions-b360d...07caf06Bump taiki-e/install-action from 2.62.45 to 2.62.49 in the actions groupUpdates
taiki-e/install-actionfrom 2.62.46 to 2.62.62Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
493d7f2Release 2.62.620c6fcb0Updatecargo-deny@latestto 0.18.8e8101c1Tweak docsc8c9b5btools: Update scripts8aeb767ci: Pin create-release reusable workflow4875eb9Updatecargo-shear@latestto 1.7.17cc1b00Update spdx requirement from 0.12 to 0.13 (#1323)112bd4cUpdatetrivy@latestto 0.68.181a8473Updateuv@latestto 0.9.155f588bfUpdateknope@latestto 0.21.6Updates
EnricoMi/publish-unit-test-result-actionfrom 2.17.1 to 2.21.0Release notes
Sourced from EnricoMi/publish-unit-test-result-action's releases.
Commits
34d7c95Releasing v2.21.0 (#699)578fa89Adddocker/action.ymlto allow setting docker registry and image (#688)45cb788Bump actions/download-artifact from 4 to 5 (#683)8c91382Bump actions/checkout from 4 to 5 (#684)694bcebFix@2tag inREADME.mdto@v2(#687)980d9deFix class name matching innunit3-to-junit.xslt(#689)d243703Removemacos-13, andmacos-26github runners (#697)c965d1eBump actions/setup-python from 5 to 6 (#692)c88cf3fAdd Python 3.14 to CI (#694)37526f5Upgrade all Python dependencies to latest version (#695)Updates
codecov/codecov-actionfrom 5.1.1 to 5.5.1Release notes
Sourced from codecov/codecov-action's releases.
... (truncated)
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)a4803c1build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)3139621build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)fdcc847chore(release): 5.5.0 (#1865)Updates
softprops/action-gh-releasefrom 2.4.1 to 2.5.0Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
a06a81arelease 2.5.07da8983feat: mark release as draft until all artifacts are uploaded (#692)8797328chore(deps): bump actions/checkout in the github-actions group (#689)1bfc62achore(deps): bump the npm group across 1 directory with 5 updates (#697)5be0e66release 2.4.2af658b4feat: Ensure generated release notes cannot be over 125000 characters (#684)237aaccchore: bump node to 24.11.000362bechore(deps): bump the npm group with 5 updates (#687)0adea5achore(deps): bump the npm group with 3 updates (#686)aa05f9dchore(deps): bump actions/setup-node from 5.0.0 to 6.0.0 in the github-action...Updates
slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.ymlfrom f701310a334f5d712a8869541c8e19ecb4eefc24 to a09dd8c05eda63cace134cb7dccd7e019f25e6f3Changelog
Sourced from slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml's changelog.
... (truncated)
Commits
a09dd8cchore: Update unsupported v2 of go-jose to supported v4 (#4439)4876e96chore: slsa-verifier v2.7.1 (#4332)a5cc0c3chore: Remove old TODO (#4152)9255e11chore(deps): update github-actions8e3df77chore: verify SLSA token at creation24e3463chore(deps): update github-actions0617b3achore(deps): update github-actions (#4132)9103ac6refs back to main