Skip to content

build(deps): bump model-checking/kani-github-action from 2534b7aeb3c6b4b0a5ecc3981bb3e63d47b5b126 to 69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237 - #595

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/model-checking/kani-github-action-69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/model-checking/kani-github-action-69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps model-checking/kani-github-action from 2534b7aeb3c6b4b0a5ecc3981bb3e63d47b5b126 to 69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [model-checking/kani-github-action](https://github.com/model-checking/kani-github-action) from 2534b7aeb3c6b4b0a5ecc3981bb3e63d47b5b126 to 69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237.
- [Release notes](https://github.com/model-checking/kani-github-action/releases)
- [Commits](model-checking/kani-github-action@2534b7a...69d357b)

---
updated-dependencies:
- dependency-name: model-checking/kani-github-action
  dependency-version: 69d357bade1eb7b32bc3fc3d5c3d173c5bfa5237
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 3, 2026
@dependabot
dependabot Bot requested a review from eKisNonos as a code owner October 3, 2026 11:22
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 3, 2026
@senseix21

Copy link
Copy Markdown
Collaborator

Review: safe to merge

Verified the pin provenance rather than trusting the bump:

  • 69d357ba is a real commit in model-checking/kani-github-action, dated 2026-09-20, exactly 1 commit ahead of the outgoing 2534b7ae (2025-05-13).
  • Single commit: "Fix Kani version parsing in install script ([P0] F-028: CSS Support Is Near-Zero — No Cascade, Specificity, or Stylesheets #58)". Touches action.yml, src/install-kani.sh, the action's own test workflow, and adds a proptest fixture.
  • The # v1 trailer is accurate — v1 is this action's default branch, not a tag. For the record the pin sits 2 commits past tag v1.1, and the branch head has since moved to daca1b75, so this is not the tip either. That's fine; the SHA pin is what gives us immutability.

Why this one is actually relevant, not just noise: we pin kani-version: "0.67.0" in verify.yml, and the single upstream change is a fix to version parsing in the install script. This is squarely in the path we exercise. The kani job is green on this PR (1m18s), along with boot-proofs, crypto-proofs and the full proof-crates matrix — so the installer change is proven against our actual pinned version.

Low blast radius (CI-only, 1 line), verified provenance, upstream-official repo, relevant fix, green proof lane. Ship it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant