Skip to content

[Repo Assist] chore(deps): bundle Dependabot updates β€” trusted-signing-action v2, gh-aw-actions 0.74.4Β #449

@github-actions

Description

@github-actions

πŸ€– This PR was created by Repo Assist, an automated AI assistant.

Summary

Bundles two open Dependabot PRs into a single update to reduce reviewer overhead. Both are minor/non-breaking CI action version bumps.

Dependency From To Dependabot PR
azure/trusted-signing-action v1 v2 #445
github/gh-aw-actions 0.72.1 0.74.4 #446

After merging this PR, maintainers can close #445 and #446.

Changes

  • .github/workflows/ci.yml: update 5 uses of azure/trusted-signing-action from v1 β†’ v2
  • .github/workflows/copilot-setup-steps.yml, localization-audit.lock.yml, repo-assist.lock.yml: update github/gh-aw-actions SHA pin from 0.72.1 β†’ 0.74.4

Test Status

CI workflow changes only β€” no application code changed. These are action version updates that will be exercised by CI on this PR.


Warning

Protected Files

This was originally intended as a pull request, but the patch modifies protected files. These files may affect project dependencies, CI/CD pipelines, or agent behaviour. Please review the changes carefully before creating the pull request.

Click here to create the pull request once you have reviewed the changes

Protected files

To route changes like this to a review issue instead of blocking, configure protected-files: fallback-to-issue in your workflow configuration.

Generated by 🌈 Repo Assist, see workflow run. Learn more.

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-assist.md@97143ac59cb3a13ef2a77581f929f06719c7402a

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions