Check out other refs/* by commit if provided, fall back to ref by orhantoy · Pull Request #1924 · actions/checkout

@orhantoy

@orhantoy marked this pull request as ready for review

September 30, 2024 20:13

joshmgross

@orhantoy orhantoy deleted the non-standard-ref-ref-fallback branch

October 2, 2024 07:13

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Oct 8, 2024

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Oct 24, 2024

@oriy oriy mentioned this pull request

Nov 17, 2024

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 16, 2024

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 16, 2024

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 16, 2024

This was referenced

Dec 31, 2024

Kkarwack7

otc-zuul bot pushed a commit to opentelekomcloud-infra/system-config that referenced this pull request

May 19, 2025
Bump the all-actions group with 4 updates

Bumps the all-actions group with 4 updates: actions/checkout, azure/setup-helm, actions/setup-python and peter-evans/create-pull-request.
Updates actions/checkout from 3 to 4

Release notes
Sourced from actions/checkout's releases.

v4.0.0
What's Changed

Update default runtime to node20 by @​takost in actions/checkout#1436
Support fetching without the --progress option by @​simonbaird in actions/checkout#1067
Release 4.0.0 by @​takost in actions/checkout#1447

New Contributors

@​takost made their first contribution in actions/checkout#1436
@​simonbaird made their first contribution in actions/checkout#1067

Full Changelog: actions/checkout@v3...v4.0.0
v3.6.0
What's Changed

Mark test scripts with Bash'isms to be run via Bash by @​dscho in actions/checkout#1377
Add option to fetch tags even if fetch-depth > 0 by @​RobertWieczoreck in actions/checkout#579
Release 3.6.0 by @​luketomlinson in actions/checkout#1437

New Contributors

@​RobertWieczoreck made their first contribution in actions/checkout#579
@​luketomlinson made their first contribution in actions/checkout#1437

Full Changelog: actions/checkout@v3.5.3...v3.6.0
v3.5.3
What's Changed

Fix: Checkout Issue in self hosted runner due to faulty submodule check-ins by @​megamanics in actions/checkout#1196
Fix typos found by codespell by @​DimitriPapadopoulos in actions/checkout#1287
Add support for sparse checkouts by @​dscho and @​dfdez in actions/checkout#1369
Release v3.5.3 by @​TingluoHuang in actions/checkout#1376

New Contributors

@​megamanics made their first contribution in actions/checkout#1196
@​DimitriPapadopoulos made their first contribution in actions/checkout#1287
@​dfdez made their first contribution in actions/checkout#1369

Full Changelog: actions/checkout@v3...v3.5.3
v3.5.2
What's Changed

Fix: Use correct API url / endpoint in GHES by @​fhammerl in actions/checkout#1289 based on #1286 by @​1newsr

Full Changelog: actions/checkout@v3.5.1...v3.5.2
v3.5.1
What's Changed

Improve checkout performance on Windows runners by upgrading @​actions/github dependency by @​BrettDong in actions/checkout#1246

New Contributors

@​BrettDong made their first contribution in actions/checkout#1246



... (truncated)


Changelog
Sourced from actions/checkout's changelog.

Changelog
v4.2.2

url-helper.ts now leverages well-known environment variables by @​jww3 in actions/checkout#1941
Expand unit test coverage for isGhes by @​jww3 in actions/checkout#1946

v4.2.1

Check out other refs/* by commit if provided, fall back to ref by @​orhantoy in actions/checkout#1924

v4.2.0

Add Ref and Commit outputs by @​lucacome in actions/checkout#1180
Dependency updates by @​dependabot- actions/checkout#1777, actions/checkout#1872

v4.1.7

Bump the minor-npm-dependencies group across 1 directory with 4 updates by @​dependabot in actions/checkout#1739
Bump actions/checkout from 3 to 4 by @​dependabot in actions/checkout#1697
Check out other refs/* by commit by @​orhantoy in actions/checkout#1774
Pin actions/checkout's own workflows to a known, good, stable version. by @​jww3 in actions/checkout#1776

v4.1.6

Check platform to set archive extension appropriately by @​cory-miller in actions/checkout#1732

v4.1.5

Update NPM dependencies by @​cory-miller in actions/checkout#1703
Bump github/codeql-action from 2 to 3 by @​dependabot in actions/checkout#1694
Bump actions/setup-node from 1 to 4 by @​dependabot in actions/checkout#1696
Bump actions/upload-artifact from 2 to 4 by @​dependabot in actions/checkout#1695
README: Suggest user.email to be 41898282+github-actions[bot]@users.noreply.github.com by @​cory-miller in actions/checkout#1707

v4.1.4

Disable extensions.worktreeConfig when disabling sparse-checkout by @​jww3 in actions/checkout#1692
Add dependabot config by @​cory-miller in actions/checkout#1688
Bump the minor-actions-dependencies group with 2 updates by @​dependabot in actions/checkout#1693
Bump word-wrap from 1.2.3 to 1.2.5 by @​dependabot in actions/checkout#1643

v4.1.3

Check git version before attempting to disable sparse-checkout by @​jww3 in actions/checkout#1656
Add SSH user parameter by @​cory-miller in actions/checkout#1685
Update actions/checkout version in update-main-version.yml by @​jww3 in actions/checkout#1650

v4.1.2

Fix: Disable sparse checkout whenever sparse-checkout option is not present @​dscho in actions/checkout#1598

v4.1.1

Correct link to GitHub Docs by @​peterbe in actions/checkout#1511
Link to release page from what's new section by @​cory-miller in actions/checkout#1514

v4.1.0

Add support for partial checkout filters



... (truncated)


Commits

11bd719 Prepare 4.2.2 Release (#1953)
e3d2460 Expand unit test coverage (#1946)
163217d url-helper.ts now leverages well-known environment variables. (#1941)
eef6144 Prepare 4.2.1 release (#1925)
6b42224 Add workflow file for publishing releases to immutable action package (#1919)
de5a000 Check out other refs/* by commit if provided, fall back to ref (#1924)
d632683 Prepare 4.2.0 release (#1878)
6d193bf Bump braces from 3.0.2 to 3.0.3 (#1777)
db0cee9 Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)
b684943 Add Ref and Commit outputs (#1180)
Additional commits viewable in compare view



Updates azure/setup-helm from 3 to 4

Release notes
Sourced from azure/setup-helm's releases.

v4.0.0

#121 update to node20 as node16 is deprecated

v3.5 release
Bump @​actions/core version to remove output warning.
v3.4 release
Improves the querying method to find the latest Helm release. Takes advantage of new GitHub api changes.
v3.3 release
Add token input. Needed for fetching latest
v3.1 release
Swap to GraphQL GitHub API



Changelog
Sourced from azure/setup-helm's changelog.

Change Log
[4.3.0] - 2025-02-15

#152 feat: log when restoring from cache
#157 Dependencies Update
#137 Add dependabot

[4.2.0] - 2024-04-15

#124 Fix OS detection and download OS-native archive extension

[4.1.0] - 2024-03-01

#130 switches to use Helm published file to read latest version instead of using GitHub releases

[4.0.0] - 2024-02-12

#121 update to node20 as node16 is deprecated




Commits

b9e5190 build
0e8654b Release setup-helm version 4.3.0 (#162)
b48e1df feat: log when restoring from cache (#152)
855ae7a Bump the actions group across 1 directory with 3 updates (#159)
124c6d8 Dependencies Update (#157)
048f4e7 Bump the actions group across 1 directory with 2 updates (#151)
8618769 Bump the actions group across 1 directory with 4 updates (#149)
4eb898e Bump the actions group across 1 directory with 2 updates (#145)
7a2001c Bump the actions group across 1 directory with 2 updates (#143)
e90c86c Bump the actions group across 1 directory with 9 updates (#141)
Additional commits viewable in compare view



Updates actions/setup-python from 4 to 5

Release notes
Sourced from actions/setup-python's releases.

v5.0.0
What's Changed
In scope of this release, we update node version runtime from node16 to node20 (actions/setup-python#772). Besides, we update dependencies to the latest versions.
Full Changelog: actions/setup-python@v4.8.0...v5.0.0
v4.9.1
What's Changed

Add workflow file for publishing releases to immutable action package by @​aparnajyothi-y in actions/setup-python#1084

Full Changelog: actions/setup-python@v4...v4.9.1
v4.9.0
What's Changed

Upgrade actions/cache to 4.0.3 by @​priya-kinthali in actions/setup-python#1073
In scope of this release we updated actions/cache package to ensure continued support and compatibility, as older versions of the package are now deprecated. For more information please refer to the toolkit/cache.

Full Changelog: actions/setup-python@v4.8.0...v4.9.0
v4.8.0
What's Changed
In scope of this release we added support for GraalPy (actions/setup-python#694). You can use this snippet to set up GraalPy:
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v4 
  with:
    python-version: 'graalpy-22.3' 
- run: python my_script.py
Besides, the release contains such changes as:

Trim python version when reading from file by @​FerranPares in actions/setup-python#628
Use non-deprecated versions in examples by @​jeffwidman in actions/setup-python#724
Change deprecation comment to past tense by @​jeffwidman in actions/setup-python#723
Bump @​babel/traverse from 7.9.0 to 7.23.2 by @​dependabot in actions/setup-python#743
advanced-usage.md: Encourage the use actions/checkout@v4 by @​cclauss in actions/setup-python#729
Examples now use checkout@v4 by @​simonw in actions/setup-python#738
Update actions/checkout to v4 by @​dmitry-shibanov in actions/setup-python#761

New Contributors

@​FerranPares made their first contribution in actions/setup-python#628
@​timfel made their first contribution in actions/setup-python#694
@​jeffwidman made their first contribution in actions/setup-python#724

Full Changelog: actions/setup-python@v4...v4.8.0


... (truncated)


Commits

a26af69 Bump ts-jest from 29.1.2 to 29.3.2 (#1081)
30eafe9 Bump prettier from 2.8.8 to 3.5.3 (#1046)
5d95bc1 Bump semver and @​types/semver (#1091)
6ed2c67 Fix for Candidate Not Iterable Error (#1082)
e348410 Remove Ubuntu 20.04 from workflows due to deprecation from 2025-04-15 (#1065)
8d9ed9a Add e2e Testing for free threaded and Bump @​action/cache from 4.0.0 to 4.0.3 ...
19e4675 Add support for .tool-versions file in setup-python (#1043)
6fd11e1 Bump @​actions/glob from 0.4.0 to 0.5.0 (#1015)
9e62be8 Support free threaded Python versions like '3.13t' (#973)
6ca8e85 Bump @​vercel/ncc from 0.38.1 to 0.38.3 (#1016)
Additional commits viewable in compare view



Updates peter-evans/create-pull-request from 5 to 7

Release notes
Sourced from peter-evans/create-pull-request's releases.

Create Pull Request v7.0.0
✨ Now supports commit signing with bot-generated tokens! See "What's new" below. ✍️🤖
Behaviour changes

Action input git-token has been renamed branch-token, to be more clear about its purpose. The branch-token is the token that the action will use to create and update the branch.
The action now handles requests that have been rate-limited by GitHub. Requests hitting a primary rate limit will retry twice, for a total of three attempts. Requests hitting a secondary rate limit will not be retried.
The pull-request-operation output now returns none when no operation was executed.
Removed deprecated output environment variable PULL_REQUEST_NUMBER. Please use the pull-request-number action output instead.

What's new

The action can now sign commits as github-actions[bot] when using GITHUB_TOKEN, or your own bot when using GitHub App tokens. See commit signing for details.
Action input draft now accepts a new value always-true. This will set the pull request to draft status when the pull request is updated, as well as on creation.
A new action input maintainer-can-modify indicates whether maintainers can modify the pull request. The default is true, which retains the existing behaviour of the action.
A new output pull-request-commits-verified returns true or false, indicating whether GitHub considers the signature of the branch's commits to be verified.

What's Changed

build(deps-dev): bump @​types/node from 18.19.36 to 18.19.39 by @​dependabot in peter-evans/create-pull-request#3000
build(deps-dev): bump ts-jest from 29.1.5 to 29.2.0 by @​dependabot in peter-evans/create-pull-request#3008
build(deps-dev): bump prettier from 3.3.2 to 3.3.3 by @​dependabot in peter-evans/create-pull-request#3018
build(deps-dev): bump ts-jest from 29.2.0 to 29.2.2 by @​dependabot in peter-evans/create-pull-request#3019
build(deps-dev): bump eslint-plugin-prettier from 5.1.3 to 5.2.1 by @​dependabot in peter-evans/create-pull-request#3035
build(deps-dev): bump @​types/node from 18.19.39 to 18.19.41 by @​dependabot in peter-evans/create-pull-request#3037
build(deps): bump undici from 6.19.2 to 6.19.4 by @​dependabot in peter-evans/create-pull-request#3036
build(deps-dev): bump ts-jest from 29.2.2 to 29.2.3 by @​dependabot in peter-evans/create-pull-request#3038
build(deps-dev): bump @​types/node from 18.19.41 to 18.19.42 by @​dependabot in peter-evans/create-pull-request#3070
build(deps): bump undici from 6.19.4 to 6.19.5 by @​dependabot in peter-evans/create-pull-request#3086
build(deps-dev): bump @​types/node from 18.19.42 to 18.19.43 by @​dependabot in peter-evans/create-pull-request#3087
build(deps-dev): bump ts-jest from 29.2.3 to 29.2.4 by @​dependabot in peter-evans/create-pull-request#3088
build(deps): bump undici from 6.19.5 to 6.19.7 by @​dependabot in peter-evans/create-pull-request#3145
build(deps-dev): bump @​types/node from 18.19.43 to 18.19.44 by @​dependabot in peter-evans/create-pull-request#3144
Update distribution by @​actions-bot in peter-evans/create-pull-request#3154
build(deps): bump undici from 6.19.7 to 6.19.8 by @​dependabot in peter-evans/create-pull-request#3213
build(deps-dev): bump @​types/node from 18.19.44 to 18.19.45 by @​dependabot in peter-evans/create-pull-request#3214
Update distribution by @​actions-bot in peter-evans/create-pull-request#3221
build(deps-dev): bump eslint-import-resolver-typescript from 3.6.1 to 3.6.3 by @​dependabot in peter-evans/create-pull-request#3255
build(deps-dev): bump @​types/node from 18.19.45 to 18.19.46 by @​dependabot in peter-evans/create-pull-request#3254
build(deps-dev): bump ts-jest from 29.2.4 to 29.2.5 by @​dependabot in peter-evans/create-pull-request#3256
v7 - signed commits by @​peter-evans in peter-evans/create-pull-request#3057

New Contributors

@​rustycl0ck made their first contribution in peter-evans/create-pull-request#3057

Full Changelog: peter-evans/create-pull-request@v6.1.0...v7.0.0
Create Pull Request v6.1.0
✨ Adds pull-request-branch as an action output.
What's Changed


... (truncated)


Commits

271a8d0 fix: suppress output for some git operations (#3776)
6f7efd1 test: update cpr-example-command
13c47c5 build(deps-dev): bump prettier from 3.5.1 to 3.5.2 (#3754)
63e5829 build(deps): bump @​octokit/plugin-paginate-rest from 11.4.2 to 11.4.3 (#3753)
a92c90f build(deps-dev): bump eslint-import-resolver-typescript (#3752)
b23b62d build(deps-dev): bump ts-jest from 29.2.5 to 29.2.6 (#3751)
dd2324f fix: use showFileAtRefBase64 to read per-commit file contents (#3744)
367180c ci: remove testv5 cmd
25575a1 build: update distribution (#3736)
a56e7a5 build(deps): bump @​octokit/core from 6.1.3 to 6.1.4 (#3711)
Additional commits viewable in compare view



Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Reviewed-by: Vladimir Vshivkov

vladimirvshivkov pushed a commit to opentelekomcloud-infra/system-config that referenced this pull request

May 21, 2025
Bump the all-actions group with 4 updates

Bumps the all-actions group with 4 updates: actions/checkout, azure/setup-helm, actions/setup-python and peter-evans/create-pull-request.
Updates actions/checkout from 3 to 4

Release notes
Sourced from actions/checkout's releases.

v4.0.0
What's Changed

Update default runtime to node20 by @​takost in actions/checkout#1436
Support fetching without the --progress option by @​simonbaird in actions/checkout#1067
Release 4.0.0 by @​takost in actions/checkout#1447

New Contributors

@​takost made their first contribution in actions/checkout#1436
@​simonbaird made their first contribution in actions/checkout#1067

Full Changelog: actions/checkout@v3...v4.0.0
v3.6.0
What's Changed

Mark test scripts with Bash'isms to be run via Bash by @​dscho in actions/checkout#1377
Add option to fetch tags even if fetch-depth > 0 by @​RobertWieczoreck in actions/checkout#579
Release 3.6.0 by @​luketomlinson in actions/checkout#1437

New Contributors

@​RobertWieczoreck made their first contribution in actions/checkout#579
@​luketomlinson made their first contribution in actions/checkout#1437

Full Changelog: actions/checkout@v3.5.3...v3.6.0
v3.5.3
What's Changed

Fix: Checkout Issue in self hosted runner due to faulty submodule check-ins by @​megamanics in actions/checkout#1196
Fix typos found by codespell by @​DimitriPapadopoulos in actions/checkout#1287
Add support for sparse checkouts by @​dscho and @​dfdez in actions/checkout#1369
Release v3.5.3 by @​TingluoHuang in actions/checkout#1376

New Contributors

@​megamanics made their first contribution in actions/checkout#1196
@​DimitriPapadopoulos made their first contribution in actions/checkout#1287
@​dfdez made their first contribution in actions/checkout#1369

Full Changelog: actions/checkout@v3...v3.5.3
v3.5.2
What's Changed

Fix: Use correct API url / endpoint in GHES by @​fhammerl in actions/checkout#1289 based on #1286 by @​1newsr

Full Changelog: actions/checkout@v3.5.1...v3.5.2
v3.5.1
What's Changed

Improve checkout performance on Windows runners by upgrading @​actions/github dependency by @​BrettDong in actions/checkout#1246

New Contributors

@​BrettDong made their first contribution in actions/checkout#1246



... (truncated)


Changelog
Sourced from actions/checkout's changelog.

Changelog
v4.2.2

url-helper.ts now leverages well-known environment variables by @​jww3 in actions/checkout#1941
Expand unit test coverage for isGhes by @​jww3 in actions/checkout#1946

v4.2.1

Check out other refs/* by commit if provided, fall back to ref by @​orhantoy in actions/checkout#1924

v4.2.0

Add Ref and Commit outputs by @​lucacome in actions/checkout#1180
Dependency updates by @​dependabot- actions/checkout#1777, actions/checkout#1872

v4.1.7

Bump the minor-npm-dependencies group across 1 directory with 4 updates by @​dependabot in actions/checkout#1739
Bump actions/checkout from 3 to 4 by @​dependabot in actions/checkout#1697
Check out other refs/* by commit by @​orhantoy in actions/checkout#1774
Pin actions/checkout's own workflows to a known, good, stable version. by @​jww3 in actions/checkout#1776

v4.1.6

Check platform to set archive extension appropriately by @​cory-miller in actions/checkout#1732

v4.1.5

Update NPM dependencies by @​cory-miller in actions/checkout#1703
Bump github/codeql-action from 2 to 3 by @​dependabot in actions/checkout#1694
Bump actions/setup-node from 1 to 4 by @​dependabot in actions/checkout#1696
Bump actions/upload-artifact from 2 to 4 by @​dependabot in actions/checkout#1695
README: Suggest user.email to be 41898282+github-actions[bot]@users.noreply.github.com by @​cory-miller in actions/checkout#1707

v4.1.4

Disable extensions.worktreeConfig when disabling sparse-checkout by @​jww3 in actions/checkout#1692
Add dependabot config by @​cory-miller in actions/checkout#1688
Bump the minor-actions-dependencies group with 2 updates by @​dependabot in actions/checkout#1693
Bump word-wrap from 1.2.3 to 1.2.5 by @​dependabot in actions/checkout#1643

v4.1.3

Check git version before attempting to disable sparse-checkout by @​jww3 in actions/checkout#1656
Add SSH user parameter by @​cory-miller in actions/checkout#1685
Update actions/checkout version in update-main-version.yml by @​jww3 in actions/checkout#1650

v4.1.2

Fix: Disable sparse checkout whenever sparse-checkout option is not present @​dscho in actions/checkout#1598

v4.1.1

Correct link to GitHub Docs by @​peterbe in actions/checkout#1511
Link to release page from what's new section by @​cory-miller in actions/checkout#1514

v4.1.0

Add support for partial checkout filters



... (truncated)


Commits

11bd719 Prepare 4.2.2 Release (#1953)
e3d2460 Expand unit test coverage (#1946)
163217d url-helper.ts now leverages well-known environment variables. (#1941)
eef6144 Prepare 4.2.1 release (#1925)
6b42224 Add workflow file for publishing releases to immutable action package (#1919)
de5a000 Check out other refs/* by commit if provided, fall back to ref (#1924)
d632683 Prepare 4.2.0 release (#1878)
6d193bf Bump braces from 3.0.2 to 3.0.3 (#1777)
db0cee9 Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)
b684943 Add Ref and Commit outputs (#1180)
Additional commits viewable in compare view



Updates azure/setup-helm from 3 to 4

Release notes
Sourced from azure/setup-helm's releases.

v4.0.0

#121 update to node20 as node16 is deprecated

v3.5 release
Bump @​actions/core version to remove output warning.
v3.4 release
Improves the querying method to find the latest Helm release. Takes advantage of new GitHub api changes.
v3.3 release
Add token input. Needed for fetching latest
v3.1 release
Swap to GraphQL GitHub API



Changelog
Sourced from azure/setup-helm's changelog.

Change Log
[4.3.0] - 2025-02-15

#152 feat: log when restoring from cache
#157 Dependencies Update
#137 Add dependabot

[4.2.0] - 2024-04-15

#124 Fix OS detection and download OS-native archive extension

[4.1.0] - 2024-03-01

#130 switches to use Helm published file to read latest version instead of using GitHub releases

[4.0.0] - 2024-02-12

#121 update to node20 as node16 is deprecated




Commits

b9e5190 build
0e8654b Release setup-helm version 4.3.0 (#162)
b48e1df feat: log when restoring from cache (#152)
855ae7a Bump the actions group across 1 directory with 3 updates (#159)
124c6d8 Dependencies Update (#157)
048f4e7 Bump the actions group across 1 directory with 2 updates (#151)
8618769 Bump the actions group across 1 directory with 4 updates (#149)
4eb898e Bump the actions group across 1 directory with 2 updates (#145)
7a2001c Bump the actions group across 1 directory with 2 updates (#143)
e90c86c Bump the actions group across 1 directory with 9 updates (#141)
Additional commits viewable in compare view



Updates actions/setup-python from 4 to 5

Release notes
Sourced from actions/setup-python's releases.

v5.0.0
What's Changed
In scope of this release, we update node version runtime from node16 to node20 (actions/setup-python#772). Besides, we update dependencies to the latest versions.
Full Changelog: actions/setup-python@v4.8.0...v5.0.0
v4.9.1
What's Changed

Add workflow file for publishing releases to immutable action package by @​aparnajyothi-y in actions/setup-python#1084

Full Changelog: actions/setup-python@v4...v4.9.1
v4.9.0
What's Changed

Upgrade actions/cache to 4.0.3 by @​priya-kinthali in actions/setup-python#1073
In scope of this release we updated actions/cache package to ensure continued support and compatibility, as older versions of the package are now deprecated. For more information please refer to the toolkit/cache.

Full Changelog: actions/setup-python@v4.8.0...v4.9.0
v4.8.0
What's Changed
In scope of this release we added support for GraalPy (actions/setup-python#694). You can use this snippet to set up GraalPy:
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v4 
  with:
    python-version: 'graalpy-22.3' 
- run: python my_script.py
Besides, the release contains such changes as:

Trim python version when reading from file by @​FerranPares in actions/setup-python#628
Use non-deprecated versions in examples by @​jeffwidman in actions/setup-python#724
Change deprecation comment to past tense by @​jeffwidman in actions/setup-python#723
Bump @​babel/traverse from 7.9.0 to 7.23.2 by @​dependabot in actions/setup-python#743
advanced-usage.md: Encourage the use actions/checkout@v4 by @​cclauss in actions/setup-python#729
Examples now use checkout@v4 by @​simonw in actions/setup-python#738
Update actions/checkout to v4 by @​dmitry-shibanov in actions/setup-python#761

New Contributors

@​FerranPares made their first contribution in actions/setup-python#628
@​timfel made their first contribution in actions/setup-python#694
@​jeffwidman made their first contribution in actions/setup-python#724

Full Changelog: actions/setup-python@v4...v4.8.0


... (truncated)


Commits

a26af69 Bump ts-jest from 29.1.2 to 29.3.2 (#1081)
30eafe9 Bump prettier from 2.8.8 to 3.5.3 (#1046)
5d95bc1 Bump semver and @​types/semver (#1091)
6ed2c67 Fix for Candidate Not Iterable Error (#1082)
e348410 Remove Ubuntu 20.04 from workflows due to deprecation from 2025-04-15 (#1065)
8d9ed9a Add e2e Testing for free threaded and Bump @​action/cache from 4.0.0 to 4.0.3 ...
19e4675 Add support for .tool-versions file in setup-python (#1043)
6fd11e1 Bump @​actions/glob from 0.4.0 to 0.5.0 (#1015)
9e62be8 Support free threaded Python versions like '3.13t' (#973)
6ca8e85 Bump @​vercel/ncc from 0.38.1 to 0.38.3 (#1016)
Additional commits viewable in compare view



Updates peter-evans/create-pull-request from 5 to 7

Release notes
Sourced from peter-evans/create-pull-request's releases.

Create Pull Request v7.0.0
✨ Now supports commit signing with bot-generated tokens! See "What's new" below. ✍️🤖
Behaviour changes

Action input git-token has been renamed branch-token, to be more clear about its purpose. The branch-token is the token that the action will use to create and update the branch.
The action now handles requests that have been rate-limited by GitHub. Requests hitting a primary rate limit will retry twice, for a total of three attempts. Requests hitting a secondary rate limit will not be retried.
The pull-request-operation output now returns none when no operation was executed.
Removed deprecated output environment variable PULL_REQUEST_NUMBER. Please use the pull-request-number action output instead.

What's new

The action can now sign commits as github-actions[bot] when using GITHUB_TOKEN, or your own bot when using GitHub App tokens. See commit signing for details.
Action input draft now accepts a new value always-true. This will set the pull request to draft status when the pull request is updated, as well as on creation.
A new action input maintainer-can-modify indicates whether maintainers can modify the pull request. The default is true, which retains the existing behaviour of the action.
A new output pull-request-commits-verified returns true or false, indicating whether GitHub considers the signature of the branch's commits to be verified.

What's Changed

build(deps-dev): bump @​types/node from 18.19.36 to 18.19.39 by @​dependabot in peter-evans/create-pull-request#3000
build(deps-dev): bump ts-jest from 29.1.5 to 29.2.0 by @​dependabot in peter-evans/create-pull-request#3008
build(deps-dev): bump prettier from 3.3.2 to 3.3.3 by @​dependabot in peter-evans/create-pull-request#3018
build(deps-dev): bump ts-jest from 29.2.0 to 29.2.2 by @​dependabot in peter-evans/create-pull-request#3019
build(deps-dev): bump eslint-plugin-prettier from 5.1.3 to 5.2.1 by @​dependabot in peter-evans/create-pull-request#3035
build(deps-dev): bump @​types/node from 18.19.39 to 18.19.41 by @​dependabot in peter-evans/create-pull-request#3037
build(deps): bump undici from 6.19.2 to 6.19.4 by @​dependabot in peter-evans/create-pull-request#3036
build(deps-dev): bump ts-jest from 29.2.2 to 29.2.3 by @​dependabot in peter-evans/create-pull-request#3038
build(deps-dev): bump @​types/node from 18.19.41 to 18.19.42 by @​dependabot in peter-evans/create-pull-request#3070
build(deps): bump undici from 6.19.4 to 6.19.5 by @​dependabot in peter-evans/create-pull-request#3086
build(deps-dev): bump @​types/node from 18.19.42 to 18.19.43 by @​dependabot in peter-evans/create-pull-request#3087
build(deps-dev): bump ts-jest from 29.2.3 to 29.2.4 by @​dependabot in peter-evans/create-pull-request#3088
build(deps): bump undici from 6.19.5 to 6.19.7 by @​dependabot in peter-evans/create-pull-request#3145
build(deps-dev): bump @​types/node from 18.19.43 to 18.19.44 by @​dependabot in peter-evans/create-pull-request#3144
Update distribution by @​actions-bot in peter-evans/create-pull-request#3154
build(deps): bump undici from 6.19.7 to 6.19.8 by @​dependabot in peter-evans/create-pull-request#3213
build(deps-dev): bump @​types/node from 18.19.44 to 18.19.45 by @​dependabot in peter-evans/create-pull-request#3214
Update distribution by @​actions-bot in peter-evans/create-pull-request#3221
build(deps-dev): bump eslint-import-resolver-typescript from 3.6.1 to 3.6.3 by @​dependabot in peter-evans/create-pull-request#3255
build(deps-dev): bump @​types/node from 18.19.45 to 18.19.46 by @​dependabot in peter-evans/create-pull-request#3254
build(deps-dev): bump ts-jest from 29.2.4 to 29.2.5 by @​dependabot in peter-evans/create-pull-request#3256
v7 - signed commits by @​peter-evans in peter-evans/create-pull-request#3057

New Contributors

@​rustycl0ck made their first contribution in peter-evans/create-pull-request#3057

Full Changelog: peter-evans/create-pull-request@v6.1.0...v7.0.0
Create Pull Request v6.1.0
✨ Adds pull-request-branch as an action output.
What's Changed


... (truncated)


Commits

271a8d0 fix: suppress output for some git operations (#3776)
6f7efd1 test: update cpr-example-command
13c47c5 build(deps-dev): bump prettier from 3.5.1 to 3.5.2 (#3754)
63e5829 build(deps): bump @​octokit/plugin-paginate-rest from 11.4.2 to 11.4.3 (#3753)
a92c90f build(deps-dev): bump eslint-import-resolver-typescript (#3752)
b23b62d build(deps-dev): bump ts-jest from 29.2.5 to 29.2.6 (#3751)
dd2324f fix: use showFileAtRefBase64 to read per-commit file contents (#3744)
367180c ci: remove testv5 cmd
25575a1 build: update distribution (#3736)
a56e7a5 build(deps): bump @​octokit/core from 6.1.3 to 6.1.4 (#3711)
Additional commits viewable in compare view



Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Reviewed-by: Vladimir Vshivkov

vladimirvshivkov added a commit to opentelekomcloud-infra/system-config that referenced this pull request

May 21, 2025
….yaml

adding users to base (#1248)

adding users to base

Reviewed-by: Vladimir Vshivkov

Addition of docker check of dependabot for system-config repository on daily bases (#1255)

1254 - Addition of docker check of dependabot for system-config repository

Addapted dependabot.yaml for docker check on daily bases
closes #1254

Reviewed-by: Vladimir Vshivkov

chore: update helm chart dependencies (#1257)

Update helm chart dependencies

Helm Chart Dependencies Updates
victoria-metrics-cluster (victoria-metrics-cluster)

victoria-metrics-cluster: 0.21.0 → 0.22.1

kube-prometheus-stack (kube-prometheus-stack)

kube-prometheus-stack: 72.3.0 → 72.5.0

victoria-metrics-auth (victoria-metrics-auth)

victoria-metrics-auth: 0.13.0 → 0.14.1

Automatically created PR for helm chart dependencies updates. Please check before merge!

Reviewed-by: Vladimir Vshivkov

Enhance dependabot configuration to include GitHub Actions and update scheduling for Helm and Docker. Added daily checks at 09:00 for all specified ecosystems. (#1258)

Enhance dependabot configuration to include GitHub Actions

and update scheduling for Helm and Docker.
Added daily checks at 09:00 for all specified ecosystems.

Reviewed-by: Vladimir Hasko <vladimirhasko@gmail.com>

Bump the all-actions group with 4 updates (#1260)

Bump the all-actions group with 4 updates

Bumps the all-actions group with 4 updates: actions/checkout, azure/setup-helm, actions/setup-python and peter-evans/create-pull-request.
Updates actions/checkout from 3 to 4

Release notes
Sourced from actions/checkout's releases.

v4.0.0
What's Changed

Update default runtime to node20 by @​takost in actions/checkout#1436
Support fetching without the --progress option by @​simonbaird in actions/checkout#1067
Release 4.0.0 by @​takost in actions/checkout#1447

New Contributors

@​takost made their first contribution in actions/checkout#1436
@​simonbaird made their first contribution in actions/checkout#1067

Full Changelog: actions/checkout@v3...v4.0.0
v3.6.0
What's Changed

Mark test scripts with Bash'isms to be run via Bash by @​dscho in actions/checkout#1377
Add option to fetch tags even if fetch-depth > 0 by @​RobertWieczoreck in actions/checkout#579
Release 3.6.0 by @​luketomlinson in actions/checkout#1437

New Contributors

@​RobertWieczoreck made their first contribution in actions/checkout#579
@​luketomlinson made their first contribution in actions/checkout#1437

Full Changelog: actions/checkout@v3.5.3...v3.6.0
v3.5.3
What's Changed

Fix: Checkout Issue in self hosted runner due to faulty submodule check-ins by @​megamanics in actions/checkout#1196
Fix typos found by codespell by @​DimitriPapadopoulos in actions/checkout#1287
Add support for sparse checkouts by @​dscho and @​dfdez in actions/checkout#1369
Release v3.5.3 by @​TingluoHuang in actions/checkout#1376

New Contributors

@​megamanics made their first contribution in actions/checkout#1196
@​DimitriPapadopoulos made their first contribution in actions/checkout#1287
@​dfdez made their first contribution in actions/checkout#1369

Full Changelog: actions/checkout@v3...v3.5.3
v3.5.2
What's Changed

Fix: Use correct API url / endpoint in GHES by @​fhammerl in actions/checkout#1289 based on #1286 by @​1newsr

Full Changelog: actions/checkout@v3.5.1...v3.5.2
v3.5.1
What's Changed

Improve checkout performance on Windows runners by upgrading @​actions/github dependency by @​BrettDong in actions/checkout#1246

New Contributors

@​BrettDong made their first contribution in actions/checkout#1246

... (truncated)

Changelog
Sourced from actions/checkout's changelog.

Changelog
v4.2.2

url-helper.ts now leverages well-known environment variables by @​jww3 in actions/checkout#1941
Expand unit test coverage for isGhes by @​jww3 in actions/checkout#1946

v4.2.1

Check out other refs/* by commit if provided, fall back to ref by @​orhantoy in actions/checkout#1924

v4.2.0

Add Ref and Commit outputs by @​lucacome in actions/checkout#1180
Dependency updates by @​dependabot- actions/checkout#1777, actions/checkout#1872

v4.1.7

Bump the minor-npm-dependencies group across 1 directory with 4 updates by @​dependabot in actions/checkout#1739
Bump actions/checkout from 3 to 4 by @​dependabot in actions/checkout#1697
Check out other refs/* by commit by @​orhantoy in actions/checkout#1774
Pin actions/checkout's own workflows to a known, good, stable version. by @​jww3 in actions/checkout#1776

v4.1.6

Check platform to set archive extension appropriately by @​cory-miller in actions/checkout#1732

v4.1.5

Update NPM dependencies by @​cory-miller in actions/checkout#1703
Bump github/codeql-action from 2 to 3 by @​dependabot in actions/checkout#1694
Bump actions/setup-node from 1 to 4 by @​dependabot in actions/checkout#1696
Bump actions/upload-artifact from 2 to 4 by @​dependabot in actions/checkout#1695
README: Suggest user.email to be 41898282+github-actions[bot]@users.noreply.github.com by @​cory-miller in actions/checkout#1707

v4.1.4

Disable extensions.worktreeConfig when disabling sparse-checkout by @​jww3 in actions/checkout#1692
Add dependabot config by @​cory-miller in actions/checkout#1688
Bump the minor-actions-dependencies group with 2 updates by @​dependabot in actions/checkout#1693
Bump word-wrap from 1.2.3 to 1.2.5 by @​dependabot in actions/checkout#1643

v4.1.3

Check git version before attempting to disable sparse-checkout by @​jww3 in actions/checkout#1656
Add SSH user parameter by @​cory-miller in actions/checkout#1685
Update actions/checkout version in update-main-version.yml by @​jww3 in actions/checkout#1650

v4.1.2

Fix: Disable sparse checkout whenever sparse-checkout option is not present @​dscho in actions/checkout#1598

v4.1.1

Correct link to GitHub Docs by @​peterbe in actions/checkout#1511
Link to release page from what's new section by @​cory-miller in actions/checkout#1514

v4.1.0

Add support for partial checkout filters

... (truncated)

Commits

11bd719 Prepare 4.2.2 Release (#1953)
e3d2460 Expand unit test coverage (#1946)
163217d url-helper.ts now leverages well-known environment variables. (#1941)
eef6144 Prepare 4.2.1 release (#1925)
6b42224 Add workflow file for publishing releases to immutable action package (#1919)
de5a000 Check out other refs/* by commit if provided, fall back to ref (#1924)
d632683 Prepare 4.2.0 release (#1878)
6d193bf Bump braces from 3.0.2 to 3.0.3 (#1777)
db0cee9 Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1872)
b684943 Add Ref and Commit outputs (#1180)
Additional commits viewable in compare view

Updates azure/setup-helm from 3 to 4

Release notes
Sourced from azure/setup-helm's releases.

v4.0.0

v3.5 release
Bump @​actions/core version to remove output warning.
v3.4 release
Improves the querying method to find the latest Helm release. Takes advantage of new GitHub api changes.
v3.3 release
Add token input. Needed for fetching latest
v3.1 release
Swap to GraphQL GitHub API

Changelog
Sourced from azure/setup-helm's changelog.

Change Log
[4.3.0] - 2025-02-15

[4.2.0] - 2024-04-15

[4.1.0] - 2024-03-01

[4.0.0] - 2024-02-12

Commits

b9e5190 build
0e8654b Release setup-helm version 4.3.0 (#162)
b48e1df feat: log when restoring from cache (#152)
855ae7a Bump the actions group across 1 directory with 3 updates (#159)
124c6d8 Dependencies Update (#157)
048f4e7 Bump the actions group across 1 directory with 2 updates (#151)
8618769 Bump the actions group across 1 directory with 4 updates (#149)
4eb898e Bump the actions group across 1 directory with 2 updates (#145)
7a2001c Bump the actions group across 1 directory with 2 updates (#143)
e90c86c Bump the actions group across 1 directory with 9 updates (#141)
Additional commits viewable in compare view

Updates actions/setup-python from 4 to 5

Release notes
Sourced from actions/setup-python's releases.

v5.0.0
What's Changed
In scope of this release, we update node version runtime from node16 to node20 (actions/setup-python#772). Besides, we update dependencies to the latest versions.
Full Changelog: actions/setup-python@v4.8.0...v5.0.0
v4.9.1
What's Changed

Add workflow file for publishing releases to immutable action package by @​aparnajyothi-y in actions/setup-python#1084

Full Changelog: actions/setup-python@v4...v4.9.1
v4.9.0
What's Changed

Upgrade actions/cache to 4.0.3 by @​priya-kinthali in actions/setup-python#1073
In scope of this release we updated actions/cache package to ensure continued support and compatibility, as older versions of the package are now deprecated. For more information please refer to the toolkit/cache.

Full Changelog: actions/setup-python@v4.8.0...v4.9.0
v4.8.0
What's Changed
In scope of this release we added support for GraalPy (actions/setup-python#694). You can use this snippet to set up GraalPy:
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v4
  with:
    python-version: 'graalpy-22.3'
- run: python my_script.py
Besides, the release contains such changes as:

Trim python version when reading from file by @​FerranPares in actions/setup-python#628
Use non-deprecated versions in examples by @​jeffwidman in actions/setup-python#724
Change deprecation comment to past tense by @​jeffwidman in actions/setup-python#723
Bump @​babel/traverse from 7.9.0 to 7.23.2 by @​dependabot in actions/setup-python#743
advanced-usage.md: Encourage the use actions/checkout@v4 by @​cclauss in actions/setup-python#729
Examples now use checkout@v4 by @​simonw in actions/setup-python#738
Update actions/checkout to v4 by @​dmitry-shibanov in actions/setup-python#761

New Contributors

@​FerranPares made their first contribution in actions/setup-python#628
@​timfel made their first contribution in actions/setup-python#694
@​jeffwidman made their first contribution in actions/setup-python#724

Full Changelog: actions/setup-python@v4...v4.8.0

... (truncated)

Commits

a26af69 Bump ts-jest from 29.1.2 to 29.3.2 (#1081)
30eafe9 Bump prettier from 2.8.8 to 3.5.3 (#1046)
5d95bc1 Bump semver and @​types/semver (#1091)
6ed2c67 Fix for Candidate Not Iterable Error (#1082)
e348410 Remove Ubuntu 20.04 from workflows due to deprecation from 2025-04-15 (#1065)
8d9ed9a Add e2e Testing for free threaded and Bump @​action/cache from 4.0.0 to 4.0.3 ...
19e4675 Add support for .tool-versions file in setup-python (#1043)
6fd11e1 Bump @​actions/glob from 0.4.0 to 0.5.0 (#1015)
9e62be8 Support free threaded Python versions like '3.13t' (#973)
6ca8e85 Bump @​vercel/ncc from 0.38.1 to 0.38.3 (#1016)
Additional commits viewable in compare view

Updates peter-evans/create-pull-request from 5 to 7

Release notes
Sourced from peter-evans/create-pull-request's releases.

Create Pull Request v7.0.0
✨ Now supports commit signing with bot-generated tokens! See "What's new" below. ✍️🤖
Behaviour changes

Action input git-token has been renamed branch-token, to be more clear about its purpose. The branch-token is the token that the action will use to create and update the branch.
The action now handles requests that have been rate-limited by GitHub. Requests hitting a primary rate limit will retry twice, for a total of three attempts. Requests hitting a secondary rate limit will not be retried.
The pull-request-operation output now returns none when no operation was executed.
Removed deprecated output environment variable PULL_REQUEST_NUMBER. Please use the pull-request-number action output instead.

What's new

The action can now sign commits as github-actions[bot] when using GITHUB_TOKEN, or your own bot when using GitHub App tokens. See commit signing for details.
Action input draft now accepts a new value always-true. This will set the pull request to draft status when the pull request is updated, as well as on creation.
A new action input maintainer-can-modify indicates whether maintainers can modify the pull request. The default is true, which retains the existing behaviour of the action.
A new output pull-request-commits-verified returns true or false, indicating whether GitHub considers the signature of the branch's commits to be verified.

What's Changed

build(deps-dev): bump @​types/node from 18.19.36 to 18.19.39 by @​dependabot in peter-evans/create-pull-request#3000
build(deps-dev): bump ts-jest from 29.1.5 to 29.2.0 by @​dependabot in peter-evans/create-pull-request#3008
build(deps-dev): bump prettier from 3.3.2 to 3.3.3 by @​dependabot in peter-evans/create-pull-request#3018
build(deps-dev): bump ts-jest from 29.2.0 to 29.2.2 by @​dependabot in peter-evans/create-pull-request#3019
build(deps-dev): bump eslint-plugin-prettier from 5.1.3 to 5.2.1 by @​dependabot in peter-evans/create-pull-request#3035
build(deps-dev): bump @​types/node from 18.19.39 to 18.19.41 by @​dependabot in peter-evans/create-pull-request#3037
build(deps): bump undici from 6.19.2 to 6.19.4 by @​dependabot in peter-evans/create-pull-request#3036
build(deps-dev): bump ts-jest from 29.2.2 to 29.2.3 by @​dependabot in peter-evans/create-pull-request#3038
build(deps-dev): bump @​types/node from 18.19.41 to 18.19.42 by @​dependabot in peter-evans/create-pull-request#3070
build(deps): bump undici from 6.19.4 to 6.19.5 by @​dependabot in peter-evans/create-pull-request#3086
build(deps-dev): bump @​types/node from 18.19.42 to 18.19.43 by @​dependabot in peter-evans/create-pull-request#3087
build(deps-dev): bump ts-jest from 29.2.3 to 29.2.4 by @​dependabot in peter-evans/create-pull-request#3088
build(deps): bump undici from 6.19.5 to 6.19.7 by @​dependabot in peter-evans/create-pull-request#3145
build(deps-dev): bump @​types/node from 18.19.43 to 18.19.44 by @​dependabot in peter-evans/create-pull-request#3144
Update distribution by @​actions-bot in peter-evans/create-pull-request#3154
build(deps): bump undici from 6.19.7 to 6.19.8 by @​dependabot in peter-evans/create-pull-request#3213
build(deps-dev): bump @​types/node from 18.19.44 to 18.19.45 by @​dependabot in peter-evans/create-pull-request#3214
Update distribution by @​actions-bot in peter-evans/create-pull-request#3221
build(deps-dev): bump eslint-import-resolver-typescript from 3.6.1 to 3.6.3 by @​dependabot in peter-evans/create-pull-request#3255
build(deps-dev): bump @​types/node from 18.19.45 to 18.19.46 by @​dependabot in peter-evans/create-pull-request#3254
build(deps-dev): bump ts-jest from 29.2.4 to 29.2.5 by @​dependabot in peter-evans/create-pull-request#3256
v7 - signed commits by @​peter-evans in peter-evans/create-pull-request#3057

New Contributors

@​rustycl0ck made their first contribution in peter-evans/create-pull-request#3057

Full Changelog: peter-evans/create-pull-request@v6.1.0...v7.0.0
Create Pull Request v6.1.0
✨ Adds pull-request-branch as an action output.
What's Changed

... (truncated)

Commits

271a8d0 fix: suppress output for some git operations (#3776)
6f7efd1 test: update cpr-example-command
13c47c5 build(deps-dev): bump prettier from 3.5.1 to 3.5.2 (#3754)
63e5829 build(deps): bump @​octokit/plugin-paginate-rest from 11.4.2 to 11.4.3 (#3753)
a92c90f build(deps-dev): bump eslint-import-resolver-typescript (#3752)
b23b62d build(deps-dev): bump ts-jest from 29.2.5 to 29.2.6 (#3751)
dd2324f fix: use showFileAtRefBase64 to read per-commit file contents (#3744)
367180c ci: remove testv5 cmd
25575a1 build: update distribution (#3736)
a56e7a5 build(deps): bump @​octokit/core from 6.1.3 to 6.1.4 (#3711)
Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Reviewed-by: Vladimir Vshivkov

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Aug 4, 2025

@TTAPI TTAPI mentioned this pull request

Nov 25, 2025

rafegoldberg pushed a commit to readmeio/markdown that referenced this pull request

Dec 1, 2025

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 2, 2025

onap-github pushed a commit to onap/portal-ng-ui that referenced this pull request

Dec 8, 2025

oran-osc-github pushed a commit to o-ran-sc/it-dep that referenced this pull request

Dec 10, 2025

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 15, 2025

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Dec 15, 2025

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Jan 1, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Jan 1, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Jan 24, 2026

mergify bot added a commit to ArcadeData/arcadedb that referenced this pull request

Jan 27, 2026

onap-github pushed a commit to onap/portal-ng-bff that referenced this pull request

Jan 28, 2026

mergify bot added a commit to ArcadeData/arcadedb that referenced this pull request

Feb 2, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Feb 3, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Feb 3, 2026

myparcel-bot bot added a commit to myparcelnl/actions that referenced this pull request

Feb 6, 2026

mergify bot added a commit to ArcadeData/arcadedb that referenced this pull request

Feb 8, 2026

oran-osc-github pushed a commit to o-ran-sc/it-dep that referenced this pull request

Feb 9, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Feb 13, 2026

renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request

Feb 13, 2026

mergify bot added a commit to robfrank/linklift that referenced this pull request

Feb 14, 2026
…updates [skip ci]

Bumps the github-actions group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.1` | `6.0.2` |
| [actions/cache](https://github.com/actions/cache) | `5.0.2` | `5.0.3` |
| [docker/login-action](https://github.com/docker/login-action) | `3.6.0` | `3.7.0` |
| [mikepenz/release-changelog-builder-action](https://github.com/mikepenz/release-changelog-builder-action) | `6.0.1` | `6.1.0` |
| [anchore/scan-action](https://github.com/anchore/scan-action) | `7.3.0` | `7.3.2` |
| [github/codeql-action](https://github.com/github/codeql-action) | `4.31.10` | `4.32.1` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.31` | `1.0.43` |
| [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.286.0` | `1.288.0` |
Updates `actions/checkout` from 6.0.1 to 6.0.2
Release notes

*Sourced from [actions/checkout's releases](https://github.com/actions/checkout/releases).*

> v6.0.2
> ------
>
> What's Changed
> --------------
>
> * Add orchestration\_id to git user-agent when ACTIONS\_ORCHESTRATION\_ID is set by [`@​TingluoHuang`](https://github.com/TingluoHuang) in [actions/checkout#2355](https://redirect.github.com/actions/checkout/pull/2355)
> * Fix tag handling: preserve annotations and explicit fetch-tags by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2356](https://redirect.github.com/actions/checkout/pull/2356)
>
> **Full Changelog**: <actions/checkout@v6.0.1...v6.0.2>


Changelog

*Sourced from [actions/checkout's changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md).*

> Changelog
> =========
>
> v6.0.2
> ------
>
> * Fix tag handling: preserve annotations and explicit fetch-tags by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2356](https://redirect.github.com/actions/checkout/pull/2356)
>
> v6.0.1
> ------
>
> * Add worktree support for persist-credentials includeIf by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2327](https://redirect.github.com/actions/checkout/pull/2327)
>
> v6.0.0
> ------
>
> * Persist creds to a separate file by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2286](https://redirect.github.com/actions/checkout/pull/2286)
> * Update README to include Node.js 24 support details and requirements by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2248](https://redirect.github.com/actions/checkout/pull/2248)
>
> v5.0.1
> ------
>
> * Port v6 cleanup to v5 by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2301](https://redirect.github.com/actions/checkout/pull/2301)
>
> v5.0.0
> ------
>
> * Update actions checkout to use node 24 by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2226](https://redirect.github.com/actions/checkout/pull/2226)
>
> v4.3.1
> ------
>
> * Port v6 cleanup to v4 by [`@​ericsciple`](https://github.com/ericsciple) in [actions/checkout#2305](https://redirect.github.com/actions/checkout/pull/2305)
>
> v4.3.0
> ------
>
> * docs: update README.md by [`@​motss`](https://github.com/motss) in [actions/checkout#1971](https://redirect.github.com/actions/checkout/pull/1971)
> * Add internal repos for checking out multiple repositories by [`@​mouismail`](https://github.com/mouismail) in [actions/checkout#1977](https://redirect.github.com/actions/checkout/pull/1977)
> * Documentation update - add recommended permissions to Readme by [`@​benwells`](https://github.com/benwells) in [actions/checkout#2043](https://redirect.github.com/actions/checkout/pull/2043)
> * Adjust positioning of user email note and permissions heading by [`@​joshmgross`](https://github.com/joshmgross) in [actions/checkout#2044](https://redirect.github.com/actions/checkout/pull/2044)
> * Update README.md by [`@​nebuk89`](https://github.com/nebuk89) in [actions/checkout#2194](https://redirect.github.com/actions/checkout/pull/2194)
> * Update CODEOWNERS for actions by [`@​TingluoHuang`](https://github.com/TingluoHuang) in [actions/checkout#2224](https://redirect.github.com/actions/checkout/pull/2224)
> * Update package dependencies by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2236](https://redirect.github.com/actions/checkout/pull/2236)
>
> v4.2.2
> ------
>
> * `url-helper.ts` now leverages well-known environment variables by [`@​jww3`](https://github.com/jww3) in [actions/checkout#1941](https://redirect.github.com/actions/checkout/pull/1941)
> * Expand unit test coverage for `isGhes` by [`@​jww3`](https://github.com/jww3) in [actions/checkout#1946](https://redirect.github.com/actions/checkout/pull/1946)
>
> v4.2.1
> ------
>
> * Check out other refs/\* by commit if provided, fall back to ref by [`@​orhantoy`](https://github.com/orhantoy) in [actions/checkout#1924](https://redirect.github.com/actions/checkout/pull/1924)
>
> v4.2.0
> ------
>
> * Add Ref and Commit outputs by [`@​lucacome`](https://github.com/lucacome) in [actions/checkout#1180](https://redirect.github.com/actions/checkout/pull/1180)
> * Dependency updates by [`@​dependabot`](https://github.com/dependabot)- [actions/checkout#1777](https://redirect.github.com/actions/checkout/pull/1777), [actions/checkout#1872](https://redirect.github.com/actions/checkout/pull/1872)
>
> v4.1.7
> ------
>
> * Bump the minor-npm-dependencies group across 1 directory with 4 updates by [`@​dependabot`](https://github.com/dependabot) in [actions/checkout#1739](https://redirect.github.com/actions/checkout/pull/1739)
> * Bump actions/checkout from 3 to 4 by [`@​dependabot`](https://github.com/dependabot) in [actions/checkout#1697](https://redirect.github.com/actions/checkout/pull/1697)
> * Check out other refs/\* by commit by [`@​orhantoy`](https://github.com/orhantoy) in [actions/checkout#1774](https://redirect.github.com/actions/checkout/pull/1774)
> * Pin actions/checkout's own workflows to a known, good, stable version. by [`@​jww3`](https://github.com/jww3) in [actions/checkout#1776](https://redirect.github.com/actions/checkout/pull/1776)
>
> v4.1.6
> ------
>
> * Check platform to set archive extension appropriately by [`@​cory-miller`](https://github.com/cory-miller) in [actions/checkout#1732](https://redirect.github.com/actions/checkout/pull/1732)

... (truncated)


Commits

* [`de0fac2`](actions/checkout@de0fac2) Fix tag handling: preserve annotations and explicit fetch-tags ([#2356](https://redirect.github.com/actions/checkout/issues/2356))
* [`064fe7f`](actions/checkout@064fe7f) Add orchestration\_id to git user-agent when ACTIONS\_ORCHESTRATION\_ID is set (...
* See full diff in [compare view](actions/checkout@8e8c483...de0fac2)
  
Updates `actions/cache` from 5.0.2 to 5.0.3
Release notes

*Sourced from [actions/cache's releases](https://github.com/actions/cache/releases).*

> v5.0.3
> ------
>
> What's Changed
> --------------
>
> * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>)
> * Bump `@actions/core` to v2.0.3
>
> **Full Changelog**: <actions/cache@v5...v5.0.3>


Changelog

*Sourced from [actions/cache's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).*

> Releases
> ========
>
> How to prepare a release
> ------------------------
>
> > [!NOTE]  
> > Relevant for maintainers with write access only.
>
> 1. Switch to a new branch from `main`.
> 2. Run `npm test` to ensure all tests are passing.
> 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json).
> 4. Run `npm run build` to update the compiled files.
> 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section.
> 6. Run `licensed cache` to update the license report.
> 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions.
> 8. Commit your changes and push your branch upstream.
> 9. Open a pull request against `main` and get it reviewed and merged.
> 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json`
>     1. Create a new tag with the version number.
>     2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`.
>     3. Toggle the set as the latest release option.
>     4. Publish the release.
> 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml>
>     1. There should be a workflow run queued with the same version number.
>     2. Approve the run to publish the new version and update the major tags for this action.
>
> Changelog
> ---------
>
> ### 5.0.3
>
> * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>)
> * Bump `@actions/core` to v2.0.3
>
> ### 5.0.2
>
> * Bump `@actions/cache` to v5.0.3 [#1692](https://redirect.github.com/actions/cache/pull/1692)
>
> ### 5.0.1
>
> * Update `@azure/storage-blob` to `^12.29.1` via `@actions/cache@5.0.1` [#1685](https://redirect.github.com/actions/cache/pull/1685)
>
> ### 5.0.0
>
> > [!IMPORTANT]
> > `actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.
> > If you are using self-hosted runners, ensure they are updated before upgrading.
>
> ### 4.3.0
>
> * Bump `@actions/cache` to [v4.1.0](https://redirect.github.com/actions/toolkit/pull/2132)

... (truncated)


Commits

* [`cdf6c1f`](actions/cache@cdf6c1f) Merge pull request [#1695](https://redirect.github.com/actions/cache/issues/1695) from actions/Link-/prepare-5.0.3
* [`a1bee22`](actions/cache@a1bee22) Add review for the `@​actions/http-client` license
* [`4695763`](actions/cache@4695763) Add licensed output
* [`dc73bb9`](actions/cache@dc73bb9) Upgrade dependencies and address security warnings
* [`345d5c2`](actions/cache@345d5c2) Add 5.0.3 builds
* See full diff in [compare view](actions/cache@8b402f5...cdf6c1f)
  
Updates `docker/login-action` from 3.6.0 to 3.7.0
Release notes

*Sourced from [docker/login-action's releases](https://github.com/docker/login-action/releases).*

> v3.7.0
> ------
>
> * Add `scope` input to set scopes for the authentication token by [`@​crazy-max`](https://github.com/crazy-max) in [docker/login-action#912](https://redirect.github.com/docker/login-action/pull/912)
> * Add support for AWS European Sovereign Cloud ECR by [`@​dphi`](https://github.com/dphi) in [docker/login-action#914](https://redirect.github.com/docker/login-action/pull/914)
> * Ensure passwords are redacted with `registry-auth` input by [`@​crazy-max`](https://github.com/crazy-max) in [docker/login-action#911](https://redirect.github.com/docker/login-action/pull/911)
> * build(deps): bump lodash from 4.17.21 to 4.17.23 in [docker/login-action#915](https://redirect.github.com/docker/login-action/pull/915)
>
> **Full Changelog**: <docker/login-action@v3.6.0...v3.7.0>


Commits

* [`c94ce9f`](docker/login-action@c94ce9f) Merge pull request [#915](https://redirect.github.com/docker/login-action/issues/915) from docker/dependabot/npm\_and\_yarn/lodash-4.17.23
* [`8339c95`](docker/login-action@8339c95) Merge pull request [#912](https://redirect.github.com/docker/login-action/issues/912) from docker/scope
* [`c83e932`](docker/login-action@c83e932) build(deps): bump lodash from 4.17.21 to 4.17.23
* [`b268aa5`](docker/login-action@b268aa5) chore: update generated content
* [`a603229`](docker/login-action@a603229) documentation for scope input
* [`7567f92`](docker/login-action@7567f92) Add scope input to set scopes for the authentication token
* [`0567fa5`](docker/login-action@0567fa5) Merge pull request [#914](https://redirect.github.com/docker/login-action/issues/914) from dphi/add-support-for-amazonaws.eu
* [`f6ef577`](docker/login-action@f6ef577) feat: add support for AWS European Sovereign Cloud ECR registries
* [`916386b`](docker/login-action@916386b) Merge pull request [#911](https://redirect.github.com/docker/login-action/issues/911) from crazy-max/ensure-redact
* [`5b3f94a`](docker/login-action@5b3f94a) chore: update generated content
* Additional commits viewable in [compare view](docker/login-action@5e57cd1...c94ce9f)
  
Updates `mikepenz/release-changelog-builder-action` from 6.0.1 to 6.1.0
Release notes

*Sourced from [mikepenz/release-changelog-builder-action's releases](https://github.com/mikepenz/release-changelog-builder-action/releases).*

> v6.1.0
> ------
>
> 🚀 Features
> ----------
>
> * fix: update dependencies | fix undici vunerability | upgrade github dependency
>   + PR: [#1510](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1510)
> * chore: upgrade dependencies to latest major versions
>   + PR: [#1512](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1512)
>
> 📦 Dependencies
> --------------
>
> * Bump github/codeql-action from 3 to 4
>   + PR: [#1490](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1490)
> * Bump actions/setup-node from 4 to 6
>   + PR: [#1486](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1486)
> * Bump mikepenz/release-changelog-builder-action from 5 to 6
>   + PR: [#1489](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1489)
> * Bump actions/upload-artifact from 4 to 5
>   + PR: [#1488](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1488)
> * Bump mikepenz/action-junit-report from 5 to 6
>   + PR: [#1487](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1487)
> * Update `octokit/rest`, `globals`
>   + PR: [#1491](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1491)
> * Bump actions/checkout from 4 to 5
>   + PR: [#1492](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1492)
> * Bump js-yaml from 4.1.0 to 4.1.1
>   + PR: [#1494](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1494)
> * Bump the dev-dependencies group with 3 updates
>   + PR: [#1495](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1495)
> * Bump vitest from 4.0.7 to 4.0.10
>   + PR: [#1496](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1496)
> * Bump actions/checkout from 5 to 6
>   + PR: [#1501](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1501)
> * Bump actions/upload-artifact from 5 to 6
>   + PR: [#1508](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1508)
> * fix: update dependencies | fix undici vunerability | upgrade github dependency
>   + PR: [#1510](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1510)
> * chore: upgrade dependencies to latest major versions
>   + PR: [#1512](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1512)
>
> Contributors:
> -------------
>
> * [`@​dependabot`](https://github.com/dependabot)[bot], [`@​mikepenz`](https://github.com/mikepenz)


Commits

* [`6faf020`](mikepenz/release-changelog-builder-action@6faf020) Merge pull request [#1513](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1513) from mikepenz/develop
* [`758b277`](mikepenz/release-changelog-builder-action@758b277) fix: update release-changelog-builder-action to version 6
* [`22fe05c`](mikepenz/release-changelog-builder-action@22fe05c) Merge pull request [#1512](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1512) from mikepenz/feature/upgrade-dependencies-major-ver...
* [`46b3aa3`](mikepenz/release-changelog-builder-action@46b3aa3) fix: add globals as direct devDependency for ESLint 9+
* [`a8034b4`](mikepenz/release-changelog-builder-action@a8034b4) chore: upgrade dependencies to latest major versions
* [`2348b8c`](mikepenz/release-changelog-builder-action@2348b8c) Merge pull request [#1510](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1510) from mikepenz/fix/undici-security-vulnerability
* [`fe56a39`](mikepenz/release-changelog-builder-action@fe56a39) fix: address moderate security vulnerability in undici (GHSA-g9mf-h72j-4rw9)
* [`7f7d0e7`](mikepenz/release-changelog-builder-action@7f7d0e7) Merge pull request [#1508](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1508) from mikepenz/dependabot/github\_actions/actions/uplo...
* [`d51fb13`](mikepenz/release-changelog-builder-action@d51fb13) Bump actions/upload-artifact from 5 to 6
* [`dd6c4fe`](mikepenz/release-changelog-builder-action@dd6c4fe) Merge pull request [#1501](https://redirect.github.com/mikepenz/release-changelog-builder-action/issues/1501) from mikepenz/dependabot/github\_actions/actions/chec...
* Additional commits viewable in [compare view](mikepenz/release-changelog-builder-action@439f79b...6faf020)
  
Updates `anchore/scan-action` from 7.3.0 to 7.3.2
Release notes

*Sourced from [anchore/scan-action's releases](https://github.com/anchore/scan-action/releases).*

> v7.3.2
> ------
>
> * feat: add option to specify one or more grype config files ([#589](https://redirect.github.com/anchore/scan-action/issues/589)) [[`@​sam-super`](https://github.com/sam-super)]
>
> ⬆️ Dependencies
> ---------------
>
> * chore(deps): bump `@​actions/cache` from 5.0.3 to 5.0.5 ([#592](https://redirect.github.com/anchore/scan-action/issues/592)) [@[dependabot[bot]](https://github.com/apps/dependabot)]
> * chore(deps): bump `@​actions/tool-cache` from 3.0.0 to 3.0.1 ([#593](https://redirect.github.com/anchore/scan-action/issues/593)) [@[dependabot[bot]](https://github.com/apps/dependabot)]
> * chore(deps): update Grype to v0.107.1 ([#594](https://redirect.github.com/anchore/scan-action/issues/594)) [@[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator)]
> * chore(deps): bump fast-xml-parser from 5.3.3 to 5.3.4 ([#590](https://redirect.github.com/anchore/scan-action/issues/590)) [@[dependabot[bot]](https://github.com/apps/dependabot)]
> * chore(deps): update Grype to v0.107.0 ([#588](https://redirect.github.com/anchore/scan-action/issues/588)) [@[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator)]
> * chore(deps-dev): bump prettier from 3.8.0 to 3.8.1 ([#584](https://redirect.github.com/anchore/scan-action/issues/584)) [@[dependabot[bot]](https://github.com/apps/dependabot)]
> * chore(deps-dev): bump tar from 7.5.6 to 7.5.7 ([#586](https://redirect.github.com/anchore/scan-action/issues/586)) [@[dependabot[bot]](https://github.com/apps/dependabot)]
>
> v7.3.1
> ------
>
> ⬆️ Dependencies
> ---------------
>
> * chore(deps): update Grype to v0.106.0 ([#583](https://redirect.github.com/anchore/scan-action/issues/583)) [@[anchore-actions-token-generator[bot]](https://github.com/apps/anchore-actions-token-generator)]
> * chore(deps): bump lodash from 4.17.21 to 4.17.23 ([#580](https://redirect.github.com/anchore/scan-action/issues/580)) [@[dependabot[bot]](https://github.com/apps/dependabot)]


Commits

* [`7037fa0`](anchore/scan-action@7037fa0) chore(deps): bump `@​actions/cache` from 5.0.3 to 5.0.5 ([#592](https://redirect.github.com/anchore/scan-action/issues/592))
* [`d4c1dcd`](anchore/scan-action@d4c1dcd) chore(deps): bump `@​actions/tool-cache` from 3.0.0 to 3.0.1 ([#593](https://redirect.github.com/anchore/scan-action/issues/593))
* [`d7f5518`](anchore/scan-action@d7f5518) chore(deps): update Grype to v0.107.1 ([#594](https://redirect.github.com/anchore/scan-action/issues/594))
* [`e573fa1`](anchore/scan-action@e573fa1) feat: add option to specify one or more grype config files ([#589](https://redirect.github.com/anchore/scan-action/issues/589))
* [`4829fea`](anchore/scan-action@4829fea) chore(deps): bump fast-xml-parser from 5.3.3 to 5.3.4 ([#590](https://redirect.github.com/anchore/scan-action/issues/590))
* [`db5ac0e`](anchore/scan-action@db5ac0e) chore(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0 ([#587](https://redirect.github.com/anchore/scan-action/issues/587))
* [`5b5f7cd`](anchore/scan-action@5b5f7cd) chore(deps): update Grype to v0.107.0 ([#588](https://redirect.github.com/anchore/scan-action/issues/588))
* [`9fc81f9`](anchore/scan-action@9fc81f9) chore(deps-dev): bump prettier from 3.8.0 to 3.8.1 ([#584](https://redirect.github.com/anchore/scan-action/issues/584))
* [`d2e46d3`](anchore/scan-action@d2e46d3) chore(deps): bump peter-evans/create-pull-request from 8.0.0 to 8.1.0 ([#585](https://redirect.github.com/anchore/scan-action/issues/585))
* [`1091f6b`](anchore/scan-action@1091f6b) chore(deps-dev): bump tar from 7.5.6 to 7.5.7 ([#586](https://redirect.github.com/anchore/scan-action/issues/586))
* Additional commits viewable in [compare view](anchore/scan-action@0d444ed...7037fa0)
  
Updates `github/codeql-action` from 4.31.10 to 4.32.1
Release notes

*Sourced from [github/codeql-action's releases](https://github.com/github/codeql-action/releases).*

> v4.32.1
> -------
>
> * A warning is now shown in Default Setup workflow logs if a [private package registry is configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) using a GitHub Personal Access Token (PAT), but no username is configured. [#3422](https://redirect.github.com/github/codeql-action/pull/3422)
> * Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. [#3421](https://redirect.github.com/github/codeql-action/pull/3421)
>
> v4.32.0
> -------
>
> * Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://redirect.github.com/github/codeql-action/pull/3425)
>
> v4.31.11
> --------
>
> * When running a Default Setup workflow with [Actions debugging enabled](https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging), the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. [#3409](https://redirect.github.com/github/codeql-action/pull/3409)
> * Improved error handling throughout the CodeQL Action. [#3415](https://redirect.github.com/github/codeql-action/pull/3415)
> * Added experimental support for automatically excluding [generated files](https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github) from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. [#3318](https://redirect.github.com/github/codeql-action/pull/3318)
> * The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. [#3403](https://redirect.github.com/github/codeql-action/pull/3403)


Changelog

*Sourced from [github/codeql-action's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.32.1 - 02 Feb 2026
> --------------------
>
> * A warning is now shown in Default Setup workflow logs if a [private package registry is configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) using a GitHub Personal Access Token (PAT), but no username is configured. [#3422](https://redirect.github.com/github/codeql-action/pull/3422)
> * Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. [#3421](https://redirect.github.com/github/codeql-action/pull/3421)
>
> 4.32.0 - 26 Jan 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://redirect.github.com/github/codeql-action/pull/3425)
>
> 4.31.11 - 23 Jan 2026
> ---------------------
>
> * When running a Default Setup workflow with [Actions debugging enabled](https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging), the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. [#3409](https://redirect.github.com/github/codeql-action/pull/3409)
> * Improved error handling throughout the CodeQL Action. [#3415](https://redirect.github.com/github/codeql-action/pull/3415)
> * Added experimental support for automatically excluding [generated files](https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github) from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. [#3318](https://redirect.github.com/github/codeql-action/pull/3318)
> * The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. [#3403](https://redirect.github.com/github/codeql-action/pull/3403)
>
> 4.31.10 - 12 Jan 2026
> ---------------------
>
> * Update default CodeQL bundle version to 2.23.9. [#3393](https://redirect.github.com/github/codeql-action/pull/3393)
>
> 4.31.9 - 16 Dec 2025
> --------------------
>
> No user facing changes.
>
> 4.31.8 - 11 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.8. [#3354](https://redirect.github.com/github/codeql-action/pull/3354)
>
> 4.31.7 - 05 Dec 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.7. [#3343](https://redirect.github.com/github/codeql-action/pull/3343)
>
> 4.31.6 - 01 Dec 2025
> --------------------
>
> No user facing changes.
>
> 4.31.5 - 24 Nov 2025
> --------------------
>
> * Update default CodeQL bundle version to 2.23.6. [#3321](https://redirect.github.com/github/codeql-action/pull/3321)
>
> 4.31.4 - 18 Nov 2025
> --------------------

... (truncated)


Commits

* [`6bc82e0`](github/codeql-action@6bc82e0) Merge pull request [#3447](https://redirect.github.com/github/codeql-action/issues/3447) from github/update-v4.32.1-f52cbc830
* [`42f00f2`](github/codeql-action@42f00f2) Add a couple of change notes
* [`cedee6d`](github/codeql-action@cedee6d) Update changelog for v4.32.1
* [`f52cbc8`](github/codeql-action@f52cbc8) Merge pull request [#3445](https://redirect.github.com/github/codeql-action/issues/3445) from github/dependabot/npm\_and\_yarn/fast-xml-parser-...
* [`c5aaca4`](github/codeql-action@c5aaca4) Merge pull request [#3446](https://redirect.github.com/github/codeql-action/issues/3446) from github/mbg/ci/pin-node-packages
* [`3e58739`](github/codeql-action@3e58739) Pin `@actions/tool-cache@3` in workflows to avoid failures with `github-script`
* [`a6ccefb`](github/codeql-action@a6ccefb) Rebuild
* [`0e64858`](github/codeql-action@0e64858) Bump fast-xml-parser from 5.3.3 to 5.3.4
* [`f985be5`](github/codeql-action@f985be5) Merge pull request [#3443](https://redirect.github.com/github/codeql-action/issues/3443) from github/dependabot/npm\_and\_yarn/tar-7.5.7
* [`0c8e06d`](github/codeql-action@0c8e06d) Bump tar from 7.5.6 to 7.5.7
* Additional commits viewable in [compare view](github/codeql-action@cdefb33...6bc82e0)
  
Updates `anthropics/claude-code-action` from 1.0.31 to 1.0.43
Release notes

*Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).*

> v1.0.43
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.43>
>
> v1.0.42
> -------
>
> What's Changed
> --------------
>
> * fix: pass OpenTelemetry environment variables to Claude Code subprocess by [`@​csy1204`](https://github.com/csy1204) in [anthropics/claude-code-action#886](https://redirect.github.com/anthropics/claude-code-action/pull/886)
> * fix: pass GitHub token to setup-bun to avoid rate limits by [`@​peloyeje`](https://github.com/peloyeje) in [anthropics/claude-code-action#861](https://redirect.github.com/anthropics/claude-code-action/pull/861)
>
> New Contributors
> ----------------
>
> * [`@​csy1204`](https://github.com/csy1204) made their first contribution in [anthropics/claude-code-action#886](https://redirect.github.com/anthropics/claude-code-action/pull/886)
> * [`@​peloyeje`](https://github.com/peloyeje) made their first contribution in [anthropics/claude-code-action#861](https://redirect.github.com/anthropics/claude-code-action/pull/861)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.42>
>
> v1.0.41
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.41>
>
> v1.0.40
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.40>
>
> v1.0.39
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.39>
>
> v1.0.38
> -------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.38>
>
> v1.0.37
> -------
>
> What's Changed
> --------------
>
> * feat: add actor-based comment filtering to GitHub data fetching by [`@​ranyhb`](https://github.com/ranyhb) in [anthropics/claude-code-action#812](https://redirect.github.com/anthropics/claude-code-action/pull/812)
> * Revert "Revert "feat: send additional\_permissions in token exchange request"" by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#866](https://redirect.github.com/anthropics/claude-code-action/pull/866)
> * Revert "chore: bump Claude Code to 2.1.21 and Agent SDK to 0.2.21" by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#869](https://redirect.github.com/anthropics/claude-code-action/pull/869)
>
> New Contributors
> ----------------
>
> * [`@​ranyhb`](https://github.com/ranyhb) made their first contribution in [anthropics/claude-code-action#812](https://redirect.github.com/anthropics/claude-code-action/pull/812)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.37>
>
> v1.0.36
> -------
>
> What's Changed
> --------------
>
> * Revert "feat: send additional\_permissions in token exchange request" by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#864](https://redirect.github.com/anthropics/claude-code-action/pull/864)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.36>
>
> v1.0.35
> -------
>
> What's Changed
> --------------
>
> * feat: send additional\_permissions in token exchange request by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#859](https://redirect.github.com/anthropics/claude-code-action/pull/859)
> * chore: upgrade checkout-action to v6 by [`@​arthur-mountain`](https://github.com/arthur-mountain) in [anthropics/claude-code-action#862](https://redirect.github.com/anthropics/claude-code-action/pull/862)
>
> New Contributors
> ----------------

... (truncated)


Commits

* [`6867bb3`](anthropics/claude-code-action@6867bb3) chore: bump Claude Code to 2.1.31 and Agent SDK to 0.2.31
* [`98af40b`](anthropics/claude-code-action@98af40b) chore: bump Claude Code to 2.1.30 and Agent SDK to 0.2.30
* [`4ce5f17`](anthropics/claude-code-action@4ce5f17) fix: pass GitHub token to setup-bun to avoid rate limits ([#861](https://redirect.github.com/anthropics/claude-code-action/issues/861))
* [`fab4258`](anthropics/claude-code-action@fab4258) fix: pass OpenTelemetry environment variables to Claude Code subprocess ([#886](https://redirect.github.com/anthropics/claude-code-action/issues/886))
* [`70e16de`](anthropics/claude-code-action@70e16de) chore: bump Claude Code to 2.1.29 and Agent SDK to 0.2.29
* [`0ed5eea`](anthropics/claude-code-action@0ed5eea) chore: bump Claude Code to 2.1.27 and Agent SDK to 0.2.27
* [`01e756b`](anthropics/claude-code-action@01e756b) chore: bump Claude Code to 2.1.25 and Agent SDK to 0.2.25
* [`ff34ce0`](anthropics/claude-code-action@ff34ce0) chore: bump Claude Code to 2.1.23 and Agent SDK to 0.2.23
* [`2817c54`](anthropics/claude-code-action@2817c54) chore: bump Claude Code to 2.1.22 and Agent SDK to 0.2.22
* [`d01eedd`](anthropics/claude-code-action@d01eedd) Revert "chore: bump Claude Code to 2.1.21 and Agent SDK to 0.2.21" ([#869](https://redirect.github.com/anthropics/claude-code-action/issues/869))
* Additional commits viewable in [compare view](anthropics/claude-code-action@2316a9a...6867bb3)
  
Updates `ruby/setup-ruby` from 1.286.0 to 1.288.0
Release notes

*Sourced from [ruby/setup-ruby's releases](https://github.com/ruby/setup-ruby/releases).*

> v1.288.0
> --------
>
> What's Changed
> --------------
>
> * Move check-new-windows-versions.yml workflow from ruby/ruby-builder to ruby/setup-ruby by [`@​eregon`](https://github.com/eregon) in [ruby/setup-ruby#870](https://redirect.github.com/ruby/setup-ruby/pull/870)
> * Add jruby-10.0.3.0 by [`@​ruby-builder-bot`](https://github.com/ruby-builder-bot) in [ruby/setup-ruby#875](https://redirect.github.com/ruby/setup-ruby/pull/875)
>
> **Full Changelog**: <ruby/setup-ruby@v1.287.0...v1.288.0>
>
> v1.287.0
> --------
>
> What's Changed
> --------------
>
> * Improve the mise.toml parser to conform to the TOML specification by [`@​pan93412`](https://github.com/pan93412) in [ruby/setup-ruby#868](https://redirect.github.com/ruby/setup-ruby/pull/868)
>
> New Contributors
> ----------------
>
> * [`@​pan93412`](https://github.com/pan93412) made their first contribution in [ruby/setup-ruby#868](https://redirect.github.com/ruby/setup-ruby/pull/868)
>
> **Full Changelog**: <ruby/setup-ruby@v1.286.0...v1.287.0>


Commits

* [`09a7688`](ruby/setup-ruby@09a7688) Add jruby-10.0.3.0
* [`67178a2`](ruby/setup-ruby@67178a2) Improve the automated PR description
* [`ede5b72`](ruby/setup-ruby@ede5b72) Shorten workflow name
* [`aaddd68`](ruby/setup-ruby@aaddd68) new-versions.rb is no longer used for RubyInstaller releases
* [`c7aa9f4`](ruby/setup-ruby@c7aa9f4) Move check-new-windows-versions.yml workflow from ruby/ruby-builder to ruby/s...
* [`8d27f39`](ruby/setup-ruby@8d27f39) Improve the mise.toml parser to conform to the TOML specification
* See full diff in [compare view](ruby/setup-ruby@90be115...09a7688)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore  major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore  minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore  ` will remove the ignore condition of the specified dependency and ignore conditions