Skip to content

ci: bump the actions group across 1 directory with 8 updates - #146

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-b12fc971c0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-b12fc971c0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 8 updates in the / directory:

Package From To
bounded-systems/.github/.github/workflows/_auto-merge.yml a0330aea1a9fc899ff1002bf52d20ef8d9b2edad 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
bounded-systems/.github/.github/workflows/_claim-sweep.yml 953ed46c6560abe5366fbcf1235023dc46192776 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
bounded-systems/ci-workflows/.github/workflows/osv-scan.yml ce6310f52e47fcd3f536bfd267edc62974ecfc9f 752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b
bounded-systems/.github/.github/actions/broker-gh-token 953ed46c6560abe5366fbcf1235023dc46192776 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
bounded-systems/.github/.github/workflows/_pr-claim.yml bc4cb7dada47cc59eed416372a4851201bd6f503 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
cachix/cachix-action 5f2d7c5294214f71b873db4b969586b980625e71 38b082610b782e7e93e209c35fd730d399dee866
softprops/action-gh-release 3.0.2 3.0.3
bounded-systems/.github/.github/workflows/repo-standard.yml 953ed46c6560abe5366fbcf1235023dc46192776 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Updates bounded-systems/.github/.github/workflows/_auto-merge.yml from a0330aea1a9fc899ff1002bf52d20ef8d9b2edad to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Commits
  • 1716efd ci: adopt auto-merge, so a green PR here merges without waiting for a person ...
  • 848335c CLAUDE.md: name scripts/ and its runner in the pre-push commands (#419)
  • 5e180d1 conformance: name the rulesets a row's gate-absent should be attributed to (#...
  • 6a70979 cold-hook-coverage: gate the SessionStart declarations against the cold path ...
  • bb2589a claim-ceremony: say WHICH 403 it was, so nobody re-derives the transport agai...
  • See full diff in compare view

Updates bounded-systems/.github/.github/workflows/_claim-sweep.yml from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Commits
  • 1716efd ci: adopt auto-merge, so a green PR here merges without waiting for a person ...
  • 848335c CLAUDE.md: name scripts/ and its runner in the pre-push commands (#419)
  • 5e180d1 conformance: name the rulesets a row's gate-absent should be attributed to (#...
  • 6a70979 cold-hook-coverage: gate the SessionStart declarations against the cold path ...
  • bb2589a claim-ceremony: say WHICH 403 it was, so nobody re-derives the transport agai...
  • a0330ae _auto-merge: gated means a CI context is required — the claim alone is not a ...
  • 2080f24 PRs open ready, not draft: retire the draft convention (#400)
  • 8851780 conformance: the legacy armer is no longer org-managed, and no longer reporte...
  • d63837a selftest: the reference caller triggers on merge_group, and conformance measu...
  • eccc232 claim-ceremony: announce through the injecting proxy, and never send the sent...
  • Additional commits viewable in compare view

Updates bounded-systems/ci-workflows/.github/workflows/osv-scan.yml from ce6310f52e47fcd3f536bfd267edc62974ecfc9f to 752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b

Commits

Updates bounded-systems/.github/.github/actions/broker-gh-token from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Commits
  • 1716efd ci: adopt auto-merge, so a green PR here merges without waiting for a person ...
  • 848335c CLAUDE.md: name scripts/ and its runner in the pre-push commands (#419)
  • 5e180d1 conformance: name the rulesets a row's gate-absent should be attributed to (#...
  • 6a70979 cold-hook-coverage: gate the SessionStart declarations against the cold path ...
  • bb2589a claim-ceremony: say WHICH 403 it was, so nobody re-derives the transport agai...
  • a0330ae _auto-merge: gated means a CI context is required — the claim alone is not a ...
  • 2080f24 PRs open ready, not draft: retire the draft convention (#400)
  • 8851780 conformance: the legacy armer is no longer org-managed, and no longer reporte...
  • d63837a selftest: the reference caller triggers on merge_group, and conformance measu...
  • eccc232 claim-ceremony: announce through the injecting proxy, and never send the sent...
  • Additional commits viewable in compare view

Updates bounded-systems/.github/.github/workflows/_pr-claim.yml from bc4cb7dada47cc59eed416372a4851201bd6f503 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Commits
  • 1716efd ci: adopt auto-merge, so a green PR here merges without waiting for a person ...
  • 848335c CLAUDE.md: name scripts/ and its runner in the pre-push commands (#419)
  • 5e180d1 conformance: name the rulesets a row's gate-absent should be attributed to (#...
  • 6a70979 cold-hook-coverage: gate the SessionStart declarations against the cold path ...
  • bb2589a claim-ceremony: say WHICH 403 it was, so nobody re-derives the transport agai...
  • a0330ae _auto-merge: gated means a CI context is required — the claim alone is not a ...
  • 2080f24 PRs open ready, not draft: retire the draft convention (#400)
  • 8851780 conformance: the legacy armer is no longer org-managed, and no longer reporte...
  • d63837a selftest: the reference caller triggers on merge_group, and conformance measu...
  • eccc232 claim-ceremony: announce through the injecting proxy, and never send the sent...
  • Additional commits viewable in compare view

Updates cachix/cachix-action from 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866

Changelog

Sourced from cachix/cachix-action's changelog.

Release

  1. Create and push a new tag:

    git tag v17
    git push origin v17
  2. Wait for CI to pass.

  3. Create a release for the new tag.

  4. Move the major version tag to the latest release:

    git tag -fa v17
    git push origin v17 --force
Commits
  • 38b0826 dev: cleanup tests and dev files
  • 0fe030c dist
  • 792dafc deps: bump dependencies
  • b690244 ci: improve Nix compatibility test coverage
  • f495f3f Merge pull request #217 from cachix/dependabot/github_actions/actions/checkout-7
  • 9ee3c77 chore(deps): bump actions/checkout from 6 to 7
  • See full diff in compare view

Updates softprops/action-gh-release from 3.0.2 to 3.0.3

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates
Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

... (truncated)

Commits
  • efb3536 release 3.0.3 (#840)
  • 6441963 chore(deps): bump the npm group with 2 updates (#839)
  • e5ee6bc chore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)
  • d1e6617 chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)
  • 6403751 chore(deps): bump the npm group with 2 updates (#835)
  • 7c7184b chore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)
  • 0f3f0d2 chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)
  • 77fb938 chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)
  • 5a6f517 chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)
  • a3c91c9 chore(deps): bump the github-actions group with 2 updates (#825)
  • Additional commits viewable in compare view

Updates bounded-systems/.github/.github/workflows/repo-standard.yml from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c

Commits
  • 1716efd ci: adopt auto-merge, so a green PR here merges without waiting for a person ...
  • 848335c CLAUDE.md: name scripts/ and its runner in the pre-push commands (#419)
  • 5e180d1 conformance: name the rulesets a row's gate-absent should be attributed to (#...
  • 6a70979 cold-hook-coverage: gate the SessionStart declarations against the cold path ...
  • bb2589a claim-ceremony: say WHICH 403 it was, so nobody re-derives the transport agai...
  • a0330ae _auto-merge: gated means a CI context is required — the claim alone is not a ...
  • 2080f24 PRs open ready, not draft: retire the draft convention (#400)
  • 8851780 conformance: the legacy armer is no longer org-managed, and no longer reporte...
  • d63837a selftest: the reference caller triggers on merge_group, and conformance measu...
  • eccc232 claim-ceremony: announce through the injecting proxy, and never send the sent...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [bounded-systems/.github/.github/workflows/_auto-merge.yml](https://github.com/bounded-systems/.github) | `a0330aea1a9fc899ff1002bf52d20ef8d9b2edad` | `1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c` |
| [bounded-systems/.github/.github/workflows/_claim-sweep.yml](https://github.com/bounded-systems/.github) | `953ed46c6560abe5366fbcf1235023dc46192776` | `1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c` |
| [bounded-systems/ci-workflows/.github/workflows/osv-scan.yml](https://github.com/bounded-systems/ci-workflows) | `ce6310f52e47fcd3f536bfd267edc62974ecfc9f` | `752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b` |
| [bounded-systems/.github/.github/actions/broker-gh-token](https://github.com/bounded-systems/.github) | `953ed46c6560abe5366fbcf1235023dc46192776` | `1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c` |
| [bounded-systems/.github/.github/workflows/_pr-claim.yml](https://github.com/bounded-systems/.github) | `bc4cb7dada47cc59eed416372a4851201bd6f503` | `1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c` |
| [cachix/cachix-action](https://github.com/cachix/cachix-action) | `5f2d7c5294214f71b873db4b969586b980625e71` | `38b082610b782e7e93e209c35fd730d399dee866` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.2` | `3.0.3` |
| [bounded-systems/.github/.github/workflows/repo-standard.yml](https://github.com/bounded-systems/.github) | `953ed46c6560abe5366fbcf1235023dc46192776` | `1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c` |



Updates `bounded-systems/.github/.github/workflows/_auto-merge.yml` from a0330aea1a9fc899ff1002bf52d20ef8d9b2edad to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
- [Release notes](https://github.com/bounded-systems/.github/releases)
- [Commits](bounded-systems/.github@a0330ae...1716efd)

Updates `bounded-systems/.github/.github/workflows/_claim-sweep.yml` from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
- [Release notes](https://github.com/bounded-systems/.github/releases)
- [Commits](bounded-systems/.github@953ed46...1716efd)

Updates `bounded-systems/ci-workflows/.github/workflows/osv-scan.yml` from ce6310f52e47fcd3f536bfd267edc62974ecfc9f to 752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b
- [Commits](bounded-systems/ci-workflows@ce6310f...752eb5c)

Updates `bounded-systems/.github/.github/actions/broker-gh-token` from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
- [Release notes](https://github.com/bounded-systems/.github/releases)
- [Commits](bounded-systems/.github@953ed46...1716efd)

Updates `bounded-systems/.github/.github/workflows/_pr-claim.yml` from bc4cb7dada47cc59eed416372a4851201bd6f503 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
- [Release notes](https://github.com/bounded-systems/.github/releases)
- [Commits](bounded-systems/.github@bc4cb7d...1716efd)

Updates `cachix/cachix-action` from 5f2d7c5294214f71b873db4b969586b980625e71 to 38b082610b782e7e93e209c35fd730d399dee866
- [Release notes](https://github.com/cachix/cachix-action/releases)
- [Changelog](https://github.com/cachix/cachix-action/blob/master/RELEASE.md)
- [Commits](cachix/cachix-action@5f2d7c5...38b0826)

Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@3d0d988...efb3536)

Updates `bounded-systems/.github/.github/workflows/repo-standard.yml` from 953ed46c6560abe5366fbcf1235023dc46192776 to 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
- [Release notes](https://github.com/bounded-systems/.github/releases)
- [Commits](bounded-systems/.github@953ed46...1716efd)

---
updated-dependencies:
- dependency-name: bounded-systems/.github/.github/workflows/_auto-merge.yml
  dependency-version: 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: bounded-systems/.github/.github/workflows/_claim-sweep.yml
  dependency-version: 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: bounded-systems/ci-workflows/.github/workflows/osv-scan.yml
  dependency-version: 752eb5ca508e4bdcb895ae4f4f2b423ff0726c7b
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: bounded-systems/.github/.github/actions/broker-gh-token
  dependency-version: 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: bounded-systems/.github/.github/workflows/_pr-claim.yml
  dependency-version: 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: cachix/cachix-action
  dependency-version: 38b082610b782e7e93e209c35fd730d399dee866
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: bounded-systems/.github/.github/workflows/repo-standard.yml
  dependency-version: 1716efd3a3cc81ba97e0ff2be0f9a0a0ebd6574c
  dependency-type: direct:production
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
@dependabot
dependabot Bot requested a review from bdelanghe as a code owner September 14, 2026 13:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

0 participants