Skip to content

chore(deps): bump Kong/public-shared-actions from 3fde0182f188f1cc12b5e84c34289d2e1d15e408 to a92df3beb1e69e27d86be56346488f15fecaf0de - #4525

Merged
chrisgacsal merged 1 commit into
mainfrom
dependabot/github_actions/Kong/public-shared-actions-a92df3beb1e69e27d86be56346488f15fecaf0de
Jun 17, 2026
Merged

chore(deps): bump Kong/public-shared-actions from 3fde0182f188f1cc12b5e84c34289d2e1d15e408 to a92df3beb1e69e27d86be56346488f15fecaf0de#4525
chrisgacsal merged 1 commit into
mainfrom
dependabot/github_actions/Kong/public-shared-actions-a92df3beb1e69e27d86be56346488f15fecaf0de

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps Kong/public-shared-actions from 3fde0182f188f1cc12b5e84c34289d2e1d15e408 to a92df3beb1e69e27d86be56346488f15fecaf0de.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [Kong/public-shared-actions](https://github.com/kong/public-shared-actions) from 3fde0182f188f1cc12b5e84c34289d2e1d15e408 to a92df3beb1e69e27d86be56346488f15fecaf0de.
- [Release notes](https://github.com/kong/public-shared-actions/releases)
- [Commits](Kong/public-shared-actions@3fde018...a92df3b)

---
updated-dependencies:
- dependency-name: Kong/public-shared-actions
  dependency-version: a92df3beb1e69e27d86be56346488f15fecaf0de
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area/dependencies Pull requests that update a dependency file dependency/github_actions Pull requests that update GitHub Actions code release-note/ignore Ignore this change when generating release notes labels Jun 15, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 15, 2026 05:03
@dependabot dependabot Bot added area/dependencies Pull requests that update a dependency file dependency/github_actions Pull requests that update GitHub Actions code release-note/ignore Ignore this change when generating release notes labels Jun 15, 2026
@greptile-apps

greptile-apps Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This is a dependabot-generated bump of the pinned commit SHA for Kong/public-shared-actions in the security workflow, moving from 3fde0182 to a92df3be. The upstream change includes a Node.js 24 upgrade and a release publish commit.

  • Updates the SHA reference for three security scan actions (secret-scan, sca, scan-gh-workflows) to the new commit.
  • The version comment annotations (# 1.1.1, # 6.0.0, # 5.0.2) are left unchanged, which is consistent with a patch/internal update rather than a semantic version bump of the actions themselves.

Confidence Score: 5/5

Safe to merge — this is a minimal, automated SHA pin update for three security scan actions with no logic changes.

The only change is updating a pinned commit SHA for Kong/public-shared-actions across three steps in the security workflow. The upstream commits are a Node.js version bump and a release publish, both low-risk. No workflow logic, permissions, secrets handling, or step configuration was altered.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/security.yaml Bumps the pinned SHA for Kong/public-shared-actions from 3fde0182 to a92df3be across three security scan steps (secret-scan, sca, scan-gh-workflows). The version comment annotations (1.1.1, 6.0.0, 5.0.2) are unchanged — the upstream bump includes a Node.js 24 upgrade and a release publish but no apparent semantic version change for these actions.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[security.yaml workflow] --> B[secret-scan step]
    A --> C[sca step]
    A --> D[scan-gh-workflows step]
    B --> E["Kong/public-shared-actions/security-actions/secret-scan\n@ a92df3be (was 3fde0182)\n# 1.1.1"]
    C --> F["Kong/public-shared-actions/security-actions/sca\n@ a92df3be (was 3fde0182)\n# 6.0.0"]
    D --> G["Kong/public-shared-actions/security-actions/scan-gh-workflows\n@ a92df3be (was 3fde0182)\n# 5.0.2"]
Loading

Reviews (1): Last reviewed commit: "chore(deps): bump Kong/public-shared-act..." | Re-trigger Greptile

@chrisgacsal
chrisgacsal merged commit f1c9185 into main Jun 17, 2026
26 of 28 checks passed
@chrisgacsal
chrisgacsal deleted the dependabot/github_actions/Kong/public-shared-actions-a92df3beb1e69e27d86be56346488f15fecaf0de branch June 17, 2026 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependencies Pull requests that update a dependency file dependency/github_actions Pull requests that update GitHub Actions code release-note/ignore Ignore this change when generating release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant