Skip to content

chore(deps): bump the github-actions group with 5 updates - #2284

Merged
defangdevs merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-0ea60db113
Oct 1, 2026
Merged

defangdevs merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-0ea60db113

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 5 updates:

Package From To
dependabot/fetch-metadata 15c49302c4a0a37e326ec87971fba5d1e4322d97 0960109a4dd6d503321a0abfa87b9768962ddd12
azure/login 3.0.1 3.1.0
docker/setup-buildx-action 4.3.0 4.4.1
docker/setup-qemu-action 4.2.0 4.4.0
cachix/cachix-action 5f2d7c5294214f71b873db4b969586b980625e71 38b082610b782e7e93e209c35fd730d399dee866

Updates dependabot/fetch-metadata from 15c49302c4a0a37e326ec87971fba5d1e4322d97 to 0960109a4dd6d503321a0abfa87b9768962ddd12

Commits
  • 0960109 Merge pull request #757 from dependabot/dependabot/npm_and_yarn/octokit/reque...
  • e477b7d build(deps): bump @​octokit/request-error from 7.1.1 to 7.1.2
  • 4242ac4 build(deps-dev): bump the dev-dependencies group across 1 directory with 15 u...
  • 3d564b9 fix: use current PR head commit metadata (#729)
  • 19e7709 Merge pull request #745 from dependabot/dependabot/npm_and_yarn/globals-17.11.0
  • cb7fd33 build(deps-dev): bump globals from 17.9.0 to 17.12.0
  • 4622783 Merge pull request #746 from dependabot/dependabot/npm_and_yarn/esbuild-0.28.2
  • 2f083dd build(deps-dev): bump esbuild from 0.28.1 to 0.28.2
  • f391ec5 Merge pull request #755 from dependabot/dependabot/npm_and_yarn/babel/core-7....
  • f330da1 build(deps-dev): bump @​babel/core from 7.22.9 to 7.29.7
  • Additional commits viewable in compare view

Updates azure/login from 3.0.1 to 3.1.0

Release notes

Sourced from azure/login's releases.

Azure Login Action v3.1.0

What's Changed

New Contributors

Full Changelog: Azure/login@v3.0.2...v3.1.0

Azure Login Action v3.0.2

What's Changed

Security & hardening

  • Refactor PowerShell login to a static param()-bound script — eliminates string-interpolation in the AzPS login path so credential/config values can never be re-parsed as PowerShell (injection-safe by construction) by @​MaddyMicrosoft in Azure/login#607
  • Pin third-party GitHub Actions to commit SHAs — supply-chain hardening for the CI/release workflows by @​MaddyMicrosoft in Azure/login#615
  • Add admin-gated Release workflow — reproducible, approval-gated release + rollback pipeline by @​MaddyMicrosoft in Azure/login#610

Telemetry

  • Emit the real action ref in telemetry via GITHUB_ACTION_REF — corrects the previously stale hard-coded value so usage reports the version consumers actually pin by @​MaddyMicrosoft in Azure/login#614

Dependencies

Maintenance & docs

Full Changelog: Azure/login@v3.0.1...v3.1.0

Commits
  • a641126 prepare release v3.1.0
  • 3c5b5ce Add max-context-population input to override Azure PowerShell MaxCont… (#642)
  • fcd0340 Bump browserslist from 4.21.4 to 4.28.8 (#637)
  • 5a8018f Bump js-yaml from 3.14.2 to 3.15.2 (#643)
  • a23dddf ci: reduce scheduled test frequency and clarify workflow names (#639)
  • 4c016e0 docs: document immutable release model and correct branch reference (#640)
  • 63f3c38 Automate release tagging via deploy key + self-pin bump (#638)
  • 92a0b67 Add the ability to prevent the masking of clientId (#634)
  • 5cb857d Pin GitHub Actions to full-length commit SHAs (#636)
  • d90bae5 Cap @​actions/exec and @​actions/core below the ESM-only 3.x majors (#628)
  • Additional commits viewable in compare view

Updates docker/setup-buildx-action from 4.3.0 to 4.4.1

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.4.1

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

Commits
  • f87e599 Merge pull request #624 from crazy-max/skip-pull-with-endpoint
  • e700274 chore: update generated content
  • 3061c91 skip BuildKit image pre-pulls for explicit endpoints
  • 594f3bf Merge pull request #609 from crazy-max/pull-buildkit-image-before-create
  • bd6e702 chore: update generated content
  • 6268c9d pull BuildKit image before builder creation
  • e823525 Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...
  • 533ed8e build(deps): bump the codeql-actions group with 2 updates
  • bedaf13 Merge pull request #620 from crazy-max/shared-error-helpers
  • d5079fb chore: update generated content
  • Additional commits viewable in compare view

Updates docker/setup-qemu-action from 4.2.0 to 4.4.0

Release notes

Sourced from docker/setup-qemu-action's releases.

v4.4.0

Full Changelog: docker/setup-qemu-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/setup-qemu-action@v4.2.0...v4.3.0

Commits
  • 9901266 Merge pull request #342 from docker/dependabot/npm_and_yarn/js-yaml-4.3.2
  • 9364d8b Merge pull request #340 from docker/dependabot/npm_and_yarn/humanfs/node-0.16.8
  • 95c3240 Merge pull request #337 from docker/dependabot/npm_and_yarn/postcss-selector-...
  • c24671a Merge pull request #338 from docker/dependabot/github_actions/codeql-actions-...
  • fa83965 Merge pull request #345 from crazy-max/shared-error-helpers
  • f396a65 build(deps): bump the codeql-actions group across 1 directory with 2 updates
  • a63df2f chore: update generated content
  • 3e4165f use the shared error helper for Docker commands
  • 18c52d9 Merge pull request #344 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 896cbed [dependabot skip] chore: update generated content
  • Additional commits viewable in compare view

Updates cachix/cachix-action from 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866

Changelog

Sourced from cachix/cachix-action's changelog.

Release

  1. Create and push a new tag:

    git tag v17
    git push origin v17
  2. Wait for CI to pass.

  3. Create a release for the new tag.

  4. Move the major version tag to the latest release:

    git tag -fa v17
    git push origin v17 --force
Commits
  • 38b0826 dev: cleanup tests and dev files
  • 0fe030c dist
  • 792dafc deps: bump dependencies
  • b690244 ci: improve Nix compatibility test coverage
  • f495f3f Merge pull request #217 from cachix/dependabot/github_actions/actions/checkout-7
  • 9ee3c77 chore(deps): bump actions/checkout from 6 to 7
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `15c49302c4a0a37e326ec87971fba5d1e4322d97` | `0960109a4dd6d503321a0abfa87b9768962ddd12` |
| [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.2.0` | `4.4.0` |
| [cachix/cachix-action](https://github.com/cachix/cachix-action) | `5f2d7c5294214f71b873db4b969586b980625e71` | `38b082610b782e7e93e209c35fd730d399dee866` |


Updates `dependabot/fetch-metadata` from 15c49302c4a0a37e326ec87971fba5d1e4322d97 to 0960109a4dd6d503321a0abfa87b9768962ddd12
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@15c4930...0960109)

Updates `azure/login` from 3.0.1 to 3.1.0
- [Release notes](https://github.com/azure/login/releases)
- [Commits](Azure/login@f5d393a...a641126)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

Updates `docker/setup-qemu-action` from 4.2.0 to 4.4.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@96fe6ef...9901266)

Updates `cachix/cachix-action` from 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866
- [Release notes](https://github.com/cachix/cachix-action/releases)
- [Changelog](https://github.com/cachix/cachix-action/blob/master/RELEASE.md)
- [Commits](cachix/cachix-action@5f2d7c5...38b0826)

---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
  dependency-version: '0960109a4dd6d503321a0abfa87b9768962ddd12'
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: azure/login
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: cachix/cachix-action
  dependency-version: 38b082610b782e7e93e209c35fd730d399dee866
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from defangdevs as a code owner October 1, 2026 12:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0a4b343e-45d0-4834-bc39-a4fe79f502d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@defangdevs defangdevs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine GitHub Actions group bump (azure/login, docker/setup-buildx-action, docker/setup-qemu-action, dependabot/fetch-metadata, cachix/cachix-action). Workflow-only diff, no app code. The repo's own dependabot-automerge.yml didn't auto-approve this one because some of these are SHA-pinned rather than semver-tagged, so fetch-metadata couldn't classify the update type. Approving manually; enabling auto-merge to land once go-test is green.

@defangdevs
defangdevs merged commit d3b0a33 into main Oct 1, 2026
5 checks passed
@defangdevs
defangdevs deleted the dependabot/github_actions/github-actions-0ea60db113 branch October 1, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant