Skip to content

ci(deps): bump the actions-all group across 1 directory with 4 updates - #1300

Merged
jleinenbach merged 1 commit into
mainfrom
dependabot/github_actions/actions-all-20104b2d05
Sep 20, 2026
Merged

jleinenbach merged 1 commit into
mainfrom
dependabot/github_actions/actions-all-20104b2d05

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown

Bumps the actions-all group with 4 updates in the / directory: actions/checkout, actions/setup-python, actions/cache and codecov/codecov-action.

Updates actions/checkout from 5 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-python from 6 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates actions/cache from 5 to 6

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

@dependabot @github

dependabot Bot commented on behalf of github Sep 17, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep OSS found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@codecov

codecov Bot commented Sep 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@jleinenbach

Copy link
Copy Markdown
Owner

Pre-merge checklist for the bot comments on this PR

All four items below were measured, not assumed.

1. Dependabot: The following labels could not be found: ci — fixed

The label ci was declared in .github/dependabot.yml (github-actions ecosystem) but did not exist in the repository, so Dependabot could not apply it. Measured: the repo carried 13 labels, ci was not among them, while dependencies and automated-pr were.

Resolution: the label was created (ci, #ededed, matching the existing dependencies / automated-pr / codex convention) and applied to this PR. dependabot.yml is left unchanged, because the declared intent was correct — only the label was missing. Checked across all open Dependabot PRs: this was the only configuration error reported, so no other invalid value remains.

2. Semgrep OSS: 37 new warnings — pre-existing class, dismissed with reason

All 37 annotations are the same rule: yaml.github-actions.security.github-actions-mutable-action-tag (action referenced by a movable tag instead of a commit SHA).

This class already exists on main: 49 uses: …@v<N> references are tag-pinned there today. The Semgrep job runs with --baseline-commit, so a finding is attributed to the PR whenever its line changes — which is exactly what a version bump does. This PR therefore introduces no new class; it moves the version on lines that were already flagged.

SHA-pinning the workflow tree is a legitimate but separate scope (it changes how Dependabot updates these references) and is not part of a dependency bump. codecov/codecov-action@v7.1.0 is likewise a tag, consistent with the rest of the tree.

3. actions/checkout v5 → v7 breaking change — does not apply here

The release notes flag block checking out fork PR for pull_request_target and workflow_run. Verified at the source rather than from the notes: src/unsafe-pr-checkout-helper.ts at tag v7 returns early for any event that is not pull_request_target or workflow_run.

All nine workflows in this repository were enumerated; their triggers are pull_request, push, schedule, workflow_dispatch and release. Zero use pull_request_target or workflow_run, so the guard cannot fire and allow-unsafe-pr-checkout is not needed.

4. actions/setup-python v7 removed the pip-install input — not used

v7.0.0 removes the pip-install input (actions/setup-python#1336). Measured: pip-install has 0 occurrences anywhere under .github/, and the only input passed to setup-python across all six call sites is python-version. actions/cache v6.0.0 is an ESM/dependency migration with no input change.

Remaining step before merge

The branch is 44 commits behind main (#1297, #1293 and #1306 landed since). The green run belongs to the old base, so a rebase is requested below to re-run CI against current main.

@jleinenbach

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps the actions-all group with 4 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/setup-python](https://github.com/actions/setup-python), [actions/cache](https://github.com/actions/cache) and [codecov/codecov-action](https://github.com/codecov/codecov-action).


Updates `actions/checkout` from 5 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v7)

Updates `actions/setup-python` from 6 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6...v7)

Updates `actions/cache` from 5 to 6
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@v7.0.0...v7.1.1)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-all
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-all
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions-all
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-all-20104b2d05 branch from 127cff8 to 8f36c42 Compare September 20, 2026 15:10
@jleinenbach
jleinenbach merged commit b5053ab into main Sep 20, 2026
28 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-all-20104b2d05 branch September 20, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated-pr ci Continuous integration and workflow changes dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants