Skip to content

chore(deps): update github-actions - #11

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
actions/attest-build-provenance action minor v4.1.1v4.2.2 OpenSSF Scorecard
actions/checkout action patch v7.0.0v7.0.1 OpenSSF Scorecard
github/codeql-action action minor v4.36.2v4.37.9 v4.38.1 (+1) OpenSSF Scorecard
go uses-with minor 1.26.51.27.1 OpenSSF Scorecard
ossf/scorecard-action action patch v2.4.0v2.4.4 OpenSSF Scorecard

Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v4.2.2

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.1...v4.2.2

actions/checkout (actions/checkout)

v7.0.1

Compare Source

github/codeql-action (github/codeql-action)

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v4.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v4.37.4

Compare Source

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

actions/go-versions (go)

v1.27.1: 1.27.1

Compare Source

Go 1.27.1

v1.27.0: 1.27.0

Compare Source

Go 1.27.0

v1.26.8: 1.26.8

Compare Source

Go 1.26.8

v1.26.7: 1.26.7

Compare Source

Go 1.26.7

v1.26.6: 1.26.6

Compare Source

Go 1.26.6

ossf/scorecard-action (ossf/scorecard-action)

v2.4.4

Compare Source

What's Changed

This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.

Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4

v2.4.3

Compare Source

What's Changed

This update bumps the Scorecard version to the v5.3.0 release. For a complete list of changes, please refer to the Scorecard v5.3.0 release notes.

Documentation

Other

New Contributors

Full Changelog: ossf/scorecard-action@v2.4.2...v2.4.3

v2.4.2

Compare Source

What's Changed

This update bumps the Scorecard version to the v5.2.1 release. For a complete list of changes, please refer to the Scorecard v5.2.0 and v5.2.1 release notes.

Full Changelog: ossf/scorecard-action@v2.4.1...v2.4.2

v2.4.1

Compare Source

What's Changed

  • This update bumps the Scorecard version to the v5.1.1 release. For a complete list of changes, please refer to the v5.1.0 and v5.1.1 release notes.
  • Publishing results now uses half the API quota as before. The exact savings depends on the repository in question.
  • Some errors were made into annotations to make them more visible
  • There is now an optional file_mode input which controls how repository files are fetched from GitHub. The default is archive, but git produces the most accurate results for repositories with .gitattributes files at the cost of analysis speed.
  • The underlying container for the action is now hosted on GitHub Container Registry. There should be no functional changes.
Docs

New Contributors


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Aug 1, 2026
@renovate
renovate Bot requested a review from NX1X as a code owner August 1, 2026 06:55
@renovate renovate Bot assigned NX1X Aug 1, 2026
@egret-security-app

egret-security-app Bot commented Aug 1, 2026

Copy link
Copy Markdown

🪶 Egret report

  • Command: bash (+4 argument(s) omitted)
  • Mode: audit
  • Exit code: 0
  • Duration: 520ms
  • Connections: 1 · Processes: 2 · File writes: 2 · Violations: 1

⚠️ Flagged

Kind Reason Detail Blocked
connection raw-ip egress 104.20.23.154:443/tcp by curl[2411] with no prior DNS lookup -

🌐 Connections

PID Process Destination Port Proto
2411 curl 104.20.23.154 443 tcp

📝 File writes

PID Process Op Path
2411 bash open-write
2411 curl open-write /dev/null

🧬 Processes

PID PPID Process Filename
2411 2400 egret /usr/bin/bash
2411 2400 bash /usr/bin/curl

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8f8860a to 2ddeb34 Compare August 6, 2026 23:54
@renovate
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 888ab6d to 158badc Compare August 20, 2026 23:53
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 158badc to c550440 Compare August 29, 2026 04:43
@renovate
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 43ac40b to 32f8281 Compare September 12, 2026 19:43
@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f76398ef-af33-412f-b216-809d239c3ed4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 32f8281 to 6588a8c Compare September 20, 2026 00:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant