Skip to content

[actions] Update GitHub Actions versions - 2026-09-23 - #62899

Merged
pelikhan merged 2 commits into
mainfrom
actions-update-2026-09-23-09ed30fef16dc053
Sep 23, 2026
Merged

pelikhan merged 2 commits into
mainfrom
actions-update-2026-09-23-09ed30fef16dc053

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

GitHub Actions Updates - 2026-09-23

This PR updates GitHub Actions versions in .github/aw/actions-lock.json to their latest compatible releases.

📦 Actions Updated (full list)

Actions Updated

  • astral-sh/setup-uv: v10.1.0 → v10.2.0
  • haskell-actions/setup: v2.11.0 → v2.12.1
  • ruby/setup-ruby: v1.324.0 → v1.325.0

Summary

  • Total actions updated: 3
  • Update command: gh aw update
  • Workflow lock files: Not included (will be regenerated on next compile)

Notes

  • All action updates respect semantic versioning and maintain compatibility
  • Actions are pinned to commit SHAs for security
  • Workflow .lock.yml files are excluded from this PR and will be regenerated during the next compilation
  • The gh aw update run also proposed skill/source ref updates (e.g. cathrynlavery/diagram-design, mattpocock/skills, DietrichGebert/ponytail, and githubnext/agentics source pin) and .lock.yml/.md regeneration, but these are out of scope for this actions-only update and were reverted before committing, per this workflow's guidelines.
  • 2 actions (actions/gh-drives-preview/checkout, actions/gh-drives-preview/commit) could not be checked: no releases or tags found for that repository.
  • A post-update SHA/version validation step reported mismatches for several unrelated, already up-to-date action entries (e.g. actions/github-script@v9.0.0, anchore/sbom-action@v0.24.2, github/codeql-action/upload-sarif@v4.38.1, safedep/pmg@v1, actions-ecosystem/action-add-labels@v1.1.3, actions/upload-code-coverage@v1.4.2). These were not modified by this PR; they may need a separate follow-up to reconcile pinned SHAs with current tag resolution.

Testing

The updated actions will be automatically used in workflow compilations. No manual testing required.


This PR was automatically created by the Daily Workflow Updater workflow.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com
  • o205451.ingest.us.sentry.io
  • proxy.golang.org
  • raw.githubusercontent.com
  • storage.googleapis.com
  • sum.golang.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"
    - "o205451.ingest.us.sentry.io"
    - "proxy.golang.org"
    - "raw.githubusercontent.com"
    - "storage.googleapis.com"
    - "sum.golang.org"

See Network Configuration for more information.

Generated by 🔧 Daily Workflow Updater · copilot · auto · 25.5 AIC · ⌖ 9 AIC · ⊞ 7.8K · ◷

  • expires on Sep 23, 2026, 11:11 PM UTC-08:00

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 13.6 AIC · ⌖ 8.83 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

- astral-sh/setup-uv: v10.1.0 -> v10.2.0
- haskell-actions/setup: v2.11.0 -> v2.12.1
- ruby/setup-ruby: v1.324.0 -> v1.325.0

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor Author

👋 Thanks for the automated dependency update! This PR updates GitHub Actions to their latest compatible releases and is ready for review. The changes respect semantic versioning and maintain compatibility. Well done!

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com
  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

Generated by ✅ Contribution Check · copilot · auto · 63.8 AIC · ⌖ 7.02 AIC · ⊞ 9.2K · ◷

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot recompile

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

@copilot recompile

Recompiled in 7f95a68 — regenerated the affected .lock.yml files and the embedded action pin data (pkg/actionpins/data/action_pins.json, pkg/workflow/data/action_pins.json) for the updated astral-sh/setup-uv, haskell-actions/setup, and ruby/setup-ruby pins. make agent-report-progress passes and all lock files are in sync with their markdown sources.

Copilot AI requested a review from pelikhan September 23, 2026 10:24
@pelikhan
pelikhan merged commit 7334b08 into main Sep 23, 2026
@pelikhan
pelikhan deleted the actions-update-2026-09-23-09ed30fef16dc053 branch September 23, 2026 10:28
@github-actions

Copy link
Copy Markdown
Contributor Author

🎉 This pull request is included in a new release.

Release: v0.89.21

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants