chore(deps): bump the github-actions group with 5 updates - #2284
Conversation
Bumps the github-actions group with 5 updates: | Package | From | To | | --- | --- | --- | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `15c49302c4a0a37e326ec87971fba5d1e4322d97` | `0960109a4dd6d503321a0abfa87b9768962ddd12` | | [azure/login](https://github.com/azure/login) | `3.0.1` | `3.1.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.2.0` | `4.4.0` | | [cachix/cachix-action](https://github.com/cachix/cachix-action) | `5f2d7c5294214f71b873db4b969586b980625e71` | `38b082610b782e7e93e209c35fd730d399dee866` | Updates `dependabot/fetch-metadata` from 15c49302c4a0a37e326ec87971fba5d1e4322d97 to 0960109a4dd6d503321a0abfa87b9768962ddd12 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@15c4930...0960109) Updates `azure/login` from 3.0.1 to 3.1.0 - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@f5d393a...a641126) Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@37fe631...f87e599) Updates `docker/setup-qemu-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@96fe6ef...9901266) Updates `cachix/cachix-action` from 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866 - [Release notes](https://github.com/cachix/cachix-action/releases) - [Changelog](https://github.com/cachix/cachix-action/blob/master/RELEASE.md) - [Commits](cachix/cachix-action@5f2d7c5...38b0826) --- updated-dependencies: - dependency-name: dependabot/fetch-metadata dependency-version: '0960109a4dd6d503321a0abfa87b9768962ddd12' dependency-type: direct:production dependency-group: github-actions - dependency-name: azure/login dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: cachix/cachix-action dependency-version: 38b082610b782e7e93e209c35fd730d399dee866 dependency-type: direct:production dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
defangdevs
left a comment
There was a problem hiding this comment.
Routine GitHub Actions group bump (azure/login, docker/setup-buildx-action, docker/setup-qemu-action, dependabot/fetch-metadata, cachix/cachix-action). Workflow-only diff, no app code. The repo's own dependabot-automerge.yml didn't auto-approve this one because some of these are SHA-pinned rather than semver-tagged, so fetch-metadata couldn't classify the update type. Approving manually; enabling auto-merge to land once go-test is green.
Bumps the github-actions group with 5 updates:
15c49302c4a0a37e326ec87971fba5d1e4322d970960109a4dd6d503321a0abfa87b9768962ddd123.0.13.1.04.3.04.4.14.2.04.4.05f2d7c5294214f71b873db4b969586b980625e7138b082610b782e7e93e209c35fd730d399dee866Updates
dependabot/fetch-metadatafrom 15c49302c4a0a37e326ec87971fba5d1e4322d97 to 0960109a4dd6d503321a0abfa87b9768962ddd12Commits
0960109Merge pull request #757 from dependabot/dependabot/npm_and_yarn/octokit/reque...e477b7dbuild(deps): bump@octokit/request-errorfrom 7.1.1 to 7.1.24242ac4build(deps-dev): bump the dev-dependencies group across 1 directory with 15 u...3d564b9fix: use current PR head commit metadata (#729)19e7709Merge pull request #745 from dependabot/dependabot/npm_and_yarn/globals-17.11.0cb7fd33build(deps-dev): bump globals from 17.9.0 to 17.12.04622783Merge pull request #746 from dependabot/dependabot/npm_and_yarn/esbuild-0.28.22f083ddbuild(deps-dev): bump esbuild from 0.28.1 to 0.28.2f391ec5Merge pull request #755 from dependabot/dependabot/npm_and_yarn/babel/core-7....f330da1build(deps-dev): bump@babel/corefrom 7.22.9 to 7.29.7Updates
azure/loginfrom 3.0.1 to 3.1.0Release notes
Sourced from azure/login's releases.
Commits
a641126prepare release v3.1.03c5b5ceAdd max-context-population input to override Azure PowerShell MaxCont… (#642)fcd0340Bump browserslist from 4.21.4 to 4.28.8 (#637)5a8018fBump js-yaml from 3.14.2 to 3.15.2 (#643)a23dddfci: reduce scheduled test frequency and clarify workflow names (#639)4c016e0docs: document immutable release model and correct branch reference (#640)63f3c38Automate release tagging via deploy key + self-pin bump (#638)92a0b67Add the ability to prevent the masking of clientId (#634)5cb857dPin GitHub Actions to full-length commit SHAs (#636)d90bae5Cap@actions/execand@actions/corebelow the ESM-only 3.x majors (#628)Updates
docker/setup-buildx-actionfrom 4.3.0 to 4.4.1Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
f87e599Merge pull request #624 from crazy-max/skip-pull-with-endpointe700274chore: update generated content3061c91skip BuildKit image pre-pulls for explicit endpoints594f3bfMerge pull request #609 from crazy-max/pull-buildkit-image-before-createbd6e702chore: update generated content6268c9dpull BuildKit image before builder creatione823525Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...533ed8ebuild(deps): bump the codeql-actions group with 2 updatesbedaf13Merge pull request #620 from crazy-max/shared-error-helpersd5079fbchore: update generated contentUpdates
docker/setup-qemu-actionfrom 4.2.0 to 4.4.0Release notes
Sourced from docker/setup-qemu-action's releases.
Commits
9901266Merge pull request #342 from docker/dependabot/npm_and_yarn/js-yaml-4.3.29364d8bMerge pull request #340 from docker/dependabot/npm_and_yarn/humanfs/node-0.16.895c3240Merge pull request #337 from docker/dependabot/npm_and_yarn/postcss-selector-...c24671aMerge pull request #338 from docker/dependabot/github_actions/codeql-actions-...fa83965Merge pull request #345 from crazy-max/shared-error-helpersf396a65build(deps): bump the codeql-actions group across 1 directory with 2 updatesa63df2fchore: update generated content3e4165fuse the shared error helper for Docker commands18c52d9Merge pull request #344 from docker/dependabot/npm_and_yarn/docker/actions-to...896cbed[dependabot skip] chore: update generated contentUpdates
cachix/cachix-actionfrom 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866Changelog
Sourced from cachix/cachix-action's changelog.
Commits
38b0826dev: cleanup tests and dev files0fe030cdist792dafcdeps: bump dependenciesb690244ci: improve Nix compatibility test coveragef495f3fMerge pull request #217 from cachix/dependabot/github_actions/actions/checkout-79ee3c77chore(deps): bump actions/checkout from 6 to 7Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions