Skip to content

Update github actions - #826

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
SonarSource/ci-github-actions (changelog) action digest d41706a2120607
SonarSource/gh-action_release workflow minor 7.5.07.7.0
SonarSource/release-github-actions action patch 1.9.131.9.15
SonarSource/release-github-actions workflow patch 1.9.131.9.15
SonarSource/vault-action-wrapper action minor 3.6.13.7.0
sonarsource/gh-action-lt-backlog action pinDigest 63ab0d7

Release Notes

SonarSource/gh-action_release (SonarSource/gh-action_release)

v7.7.0

Compare Source

What's Changed

New Features
  • Maven Central publishes are now validated against the Central Portal before the Repox promote step, and the same validated deployment is published after promotion succeeds — no double upload, no split-brain between Repox and Central. A Central rejection now aborts the release before anything is promoted; a post-promotion publish failure no longer reverts the Repox promotion, it fails loudly with manual recovery instructions instead. download_artifacts_for_central() also walks each published artifact's own <parent> chain and fetches every public ancestor's pom, so an aggregator/root pom (never itself listed in artifactsToPublish) still reaches the bundle. (#​416, BUILD-12538)
  • Javadoc publication now supports mixed-privacy releases (one build producing both org.sonarsource.* and com.sonarsource.* artifacts): both tiers are attempted, and the existing publicRelease flag decides whether to publish just the public half or both when a release is genuinely mixed. Single-privacy repos are unaffected — publicRelease only matters once a repo actually becomes mixed-privacy, no config migration needed. download-build gained a new fail-no-op input (default true, preserving existing behavior for every current caller) so a tolerated empty tier isn't confused with a real download error. (#​420, BUILD-12556)
Bug Fixes
  • Guard against a same-named javadoc jar in one privacy tier silently overwriting the other tier's already-copied jar in the destination directory; a collision is now skipped with a logged warning instead. (#​421, BUILD-12556)

Full Changelog: SonarSource/gh-action_release@7.6.0...7.7.0

v7.6.0

Compare Source

What's Changed

New Features
  • Add support for publishing Rust crates to crates.io via publishToCratesIo, backed by a Vault-sourced CARGO_REGISTRY_TOKEN. The job runs cargo publish --dry-run before the real publish so a crate that doesn't package or build standalone fails before it ships, and an already-published version is detected and skipped rather than retried (crates.io refuses duplicates, so this also makes a release re-run safe). See Publishing to crates.io for the single-crate-repo requirement, Cargo.toml prerequisites, and the additional Vault permission needed. With @​saberduck (Tibor Blenessy). (#​413, BUILD-12231)

Full Changelog: SonarSource/gh-action_release@7.5.0...7.6.0

SonarSource/release-github-actions (SonarSource/release-github-actions)

v1.9.15

Compare Source

What's Changed
New Contributors

Full Changelog: SonarSource/release-github-actions@1.9.14...1.9.15

v1.9.14

Compare Source

What's Changed

Full Changelog: SonarSource/release-github-actions@1.9.13...1.9.14

SonarSource/vault-action-wrapper (SonarSource/vault-action-wrapper)

v3.7.0

Compare Source

What's new

Full Changelog: SonarSource/vault-action-wrapper@3.6.1...3.7.0


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At 08:00 PM through 11:59 PM and 12:00 AM through 07:59 AM, Monday through Friday (* 20-23,0-7 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Sep 11, 2026

Copy link
Copy Markdown

Deploy Preview for sonarqube-cli canceled.

Name Link
🔨 Latest commit 28cf297
🔍 Latest deploy log https://app.netlify.com/projects/sonarqube-cli/deploys/6aad3ba4f9409f0008f9d7af

@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 11, 2026

Copy link
Copy Markdown

Renovate Jira issue ID: CLI-1099

@renovate
renovate Bot force-pushed the renovate/github-actions branch 11 times, most recently from 82e13bb to 8d7ef70 Compare September 16, 2026 15:41
@sonarqubecloud

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8d7ef70 to 2a419dd Compare September 17, 2026 15:17
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 2a419dd to 28cf297 Compare September 18, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants