Skip to content

chore(ci): bump dorny/paths-filter from 6852f92c20ea7fd3b0c25de3b5112db3a98da050 to d1c1ffe0248fe513906c8e24db8ea791d46f8590#27

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dorny/paths-filter-d1c1ffe0248fe513906c8e24db8ea791d46f8590
Open

chore(ci): bump dorny/paths-filter from 6852f92c20ea7fd3b0c25de3b5112db3a98da050 to d1c1ffe0248fe513906c8e24db8ea791d46f8590#27
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dorny/paths-filter-d1c1ffe0248fe513906c8e24db8ea791d46f8590

Conversation

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github May 21, 2026

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot requested a review from a team as a code owner May 21, 2026 12:02
@github-actions github-actions Bot added the size/XS PR size: XS label May 21, 2026
Copy link
Copy Markdown

@Jerry-Xin Jerry-Xin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary: This PR is relevant to octo-lib because it updates the CI path-filter action used by the repository’s workflow, and I found no blocking issues.

💬 Non-blocking
None.

✅ Highlights

  • .github/workflows/ci.yml:50 keeps dorny/paths-filter pinned to an immutable SHA, preserving supply-chain hygiene.
  • The new SHA resolves to the v3.0.3/v3 target, so the existing # v3 comment remains accurate.
  • Workflow permissions remain scoped to contents: read and pull-requests: read; no new privilege or secret exposure risk.
  • No project code behavior changes, so no additional tests are required beyond the normal CI workflow run.

Copy link
Copy Markdown
Contributor

@lml2468 lml2468 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: APPROVED

Dependabot bump: dorny/paths-filter SHA update within v3 (v3.0.2 → v3.0.3). CI green (Build/Test/Vet pass).

Verification:

  • SHA d1c1ffe0248fe513906c8e24db8ea791d46f8590 verified as v3.0.3 commit (2026-03-12) ✅
  • Single occurrence, tag comment stays # v3
  • Patch bump, no breaking changes ✅

LGTM.

Copy link
Copy Markdown
Contributor

@lml2468 lml2468 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[APPROVE] — reviewer account matches PR author; flagging for a human maintainer to merge.

SHA-to-SHA bump for dorny/paths-filter (still v3). Correct pattern: SHA-pinned with version comment preserved. All CI passing (Build green, Test/Vet green). No blockers.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/dorny/paths-filter-d1c1ffe0248fe513906c8e24db8ea791d46f8590 branch 2 times, most recently from b3dacb6 to 1b0e53a Compare May 28, 2026 10:54
Bumps [dorny/paths-filter](https://github.com/dorny/paths-filter) from 6852f92c20ea7fd3b0c25de3b5112db3a98da050 to d1c1ffe0248fe513906c8e24db8ea791d46f8590.
- [Release notes](https://github.com/dorny/paths-filter/releases)
- [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md)
- [Commits](dorny/paths-filter@6852f92...d1c1ffe)

---
updated-dependencies:
- dependency-name: dorny/paths-filter
  dependency-version: d1c1ffe0248fe513906c8e24db8ea791d46f8590
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/dorny/paths-filter-d1c1ffe0248fe513906c8e24db8ea791d46f8590 branch from 1b0e53a to d784f25 Compare May 28, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants