Skip to content

chore(deps): bump the github-actions group across 1 directory with 10 updates#139

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-232bccb2a8
Open

chore(deps): bump the github-actions group across 1 directory with 10 updates#139
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-232bccb2a8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 22, 2026

Bumps the github-actions group with 10 updates in the / directory:

Package From To
docker/login-action 3 4
netcracker/qubership-workflow-hub 2.0.10 2.2.2
actions/download-artifact 7.0.0 8.0.1
webiny/action-conventional-commits 1.3.1 1.4.2
docker/metadata-action 5 6
docker/setup-qemu-action 3 4
docker/setup-buildx-action 3 4
docker/build-push-action 6 7
netcracker/qubership-workflow-hub/.github/workflows/re-security-scan.yml b36802acb86d790b877aa6c86098041dfc36ed25 58d49c7b22485c43f9999e73fa097e87fa1cd6c8
super-linter/super-linter 8.5.0 8.6.0

Updates docker/login-action from 3 to 4

Release notes

Sourced from docker/login-action's releases.

v4.0.0

Full Changelog: docker/login-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/login-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/login-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/login-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/login-action@v3.3.0...v3.4.0

... (truncated)

Commits
  • 650006c Merge pull request #960 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...
  • 99df1a3 chore: update generated content
  • 3ab375f build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 39d8580 Merge pull request #970 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 4eefcd3 chore: update generated content
  • 56d092c build(deps): bump @​docker/actions-toolkit from 0.86.0 to 0.90.0
  • e2e31ca Merge pull request #976 from docker/dependabot/npm_and_yarn/actions/core-3.0.1
  • 0bced94 chore: update generated content
  • 3e75a0f build(deps): bump @​actions/core from 3.0.0 to 3.0.1
  • 365bebd Merge pull request #984 from docker/dependabot/github_actions/aws-actions/con...
  • Additional commits viewable in compare view

Updates netcracker/qubership-workflow-hub from 2.0.10 to 2.2.2

Release notes

Sourced from netcracker/qubership-workflow-hub's releases.

2.2.2

🚀 Release

What's Changed

  • (#748) chore(deps): bump webiny/action-conventional-commits from 1.3.1 to 1.4.2 in /.github/workflows by @dependabot[bot]
  • (#746) chore(deps): bump Netcracker/qubership-workflow-hub from 1.0.7 to 2.2.1 in /.github/workflows by @dependabot[bot]
  • (#740) chore: k8s-hardening-scan action changed default config path by @​borislavr
  • (#738) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /actions/store-input-params by @dependabot[bot]
  • (#737) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /actions/maven-snapshot-deploy by @dependabot[bot]
  • (#736) chore(deps): bump actions/cache from 5.0.4 to 5.0.5 in /actions/maven-snapshot-deploy by @dependabot[bot]
  • (#735) chore(deps): bump actions/cache from 5.0.4 to 5.0.5 in /actions/maven-release by @dependabot[bot]
  • (#734) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /actions/docker-action by @dependabot[bot]
  • (#733) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /actions/charts-values-update-action by @dependabot[bot]
  • (#732) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /actions/cdxgen by @dependabot[bot]
  • (#729) chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 in /.github/workflows by @dependabot[bot]
  • (#728) chore(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1 in /.github/workflows by @dependabot[bot]
  • (#731) chore(deps): bump actions/cache from 5.0.4 to 5.0.5 in /.github/workflows by @dependabot[bot]
  • (#730) chore(deps): bump github/codeql-action from 4.35.1 to 4.35.2 in /.github/workflows by @dependabot[bot]
  • (#727) chore(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 in /.github/workflows by @dependabot[bot]
  • (#726) chore(deps): bump @​actions/github from 9.0.0 to 9.1.1 in /actions/pr-assigner by @dependabot[bot]
  • (#725) chore(deps-dev): bump esbuild from 0.27.7 to 0.28.0 in /actions/pr-assigner by @dependabot[bot]
  • (#723) chore(deps-dev): bump esbuild from 0.27.7 to 0.28.0 in /actions/metadata-action by @dependabot[bot]
  • (#724) chore(deps): bump @​actions/github from 9.0.0 to 9.1.1 in /actions/metadata-action by @dependabot[bot]
  • (#721) chore(deps): bump @​actions/github from 9.0.0 to 9.1.1 in /actions/custom-event by @dependabot[bot]
  • (#722) chore(deps-dev): bump esbuild from 0.27.7 to 0.28.0 in /actions/custom-event by @dependabot[bot]
  • (#720) chore(deps-dev): bump esbuild from 0.27.7 to 0.28.0 in /actions/container-package-cleanup by @dependabot[bot]
  • (#719) chore(deps): bump @​actions/github from 9.0.0 to 9.1.1 in /actions/container-package-cleanup by @dependabot[bot]
  • (#718) chore(deps-dev): bump esbuild from 0.27.7 to 0.28.0 in /actions/assets-action by @dependabot[bot]
  • (#717) chore(deps): bump @​actions/glob from 0.6.1 to 0.7.0 in /actions/assets-action by @dependabot[bot]
  • (#716) chore(deps): bump @​actions/github from 9.0.0 to 9.1.1 in /actions/assets-action by @dependabot[bot]

💡 New Features

📝 Documentation

  • (#714) docs(actions/charts-values-update-action): sync README by @​borislavr
  • (#715) docs(actions): rewrite READMEs for maven-snapshot-deploy and maven-release by @​borislavr

Full Changelog: Netcracker/qubership-workflow-hub@v2.2.1...v2.2.2

2.2.1

🚀 Release

What's Changed

  • (#695) chore(deps-dev): bump esbuild from 0.27.4 to 0.27.7 in /actions/custom-event by @dependabot[bot]
  • (#694) chore(deps-dev): bump esbuild from 0.27.4 to 0.27.7 in /actions/container-package-cleanup by @dependabot[bot]

... (truncated)

Commits
  • 6a2de8d Update references to the new version
  • c782a34 chore(deps): bump webiny/action-conventional-commits (#748)
  • e579ba0 chore(deps): bump Netcracker/qubership-workflow-hub from 1.0.7 to 2.2.1 in /....
  • 8eff1bd chore: k8s-hardening-scan action changed default config path (#740)
  • 7c19692 docs(actions/charts-values-update-action): sync README (#714)
  • 01114a3 feat: changed results filtration and log notification (#739)
  • 17ff764 chore(deps): bump actions/upload-artifact in /actions/store-input-params (#738)
  • 9db7f6f chore(deps): bump actions/upload-artifact (#737)
  • 145ca82 chore(deps): bump actions/cache in /actions/maven-snapshot-deploy (#736)
  • e52c5a1 chore(deps): bump actions/cache in /actions/maven-release (#735)
  • Additional commits viewable in compare view

Updates actions/download-artifact from 7.0.0 to 8.0.1

Release notes

Sourced from actions/download-artifact's releases.

v8.0.1

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

Updates webiny/action-conventional-commits from 1.3.1 to 1.4.2

Commits
  • 7f91b15 fix: allow 'improvement' prefix
  • 096eff5 fix: allow 'improvement' prefix
  • b6cc3cc docs: update latest version
  • 6a05e2b feat: use node24
  • b34f00b Merge remote-tracking branch 'origin/master'
  • 0fecf10 feat: refactor commit message validation to use exception list
  • See full diff in compare view

Updates docker/metadata-action from 5 to 6

Release notes

Sourced from docker/metadata-action's releases.

v6.0.0

Full Changelog: docker/metadata-action@v5.10.0...v6.0.0

v5.10.0

Full Changelog: docker/metadata-action@v5.9.0...v5.10.0

v5.9.0

Full Changelog: docker/metadata-action@v5.8.0...v5.9.0

v5.8.0

Full Changelog: docker/metadata-action@v5.7.0...v5.8.0

v5.7.0

Full Changelog: docker/metadata-action@v5.6.1...v5.7.0

... (truncated)

Commits
  • 80c7e94 Merge pull request #613 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 8e0ddab chore: update generated content
  • a8db14b chore(deps): Bump @​docker/actions-toolkit from 0.79.0 to 0.90.0
  • 63a7371 Merge pull request #617 from docker/dependabot/npm_and_yarn/csv-parse-6.2.0
  • c6916a6 chore: update generated content
  • aca9205 chore(deps): Bump csv-parse from 6.1.0 to 6.2.1
  • 9dcfe60 Merge pull request #629 from docker/dependabot/npm_and_yarn/handlebars-4.7.9
  • 43dea76 chore: update generated content
  • 7a56f5a chore(deps): Bump handlebars from 4.7.8 to 4.7.9
  • e49e0aa Merge pull request #658 from docker/dependabot/npm_and_yarn/brace-expansion-5...
  • Additional commits viewable in compare view

Updates docker/setup-qemu-action from 3 to 4

Release notes

Sourced from docker/setup-qemu-action's releases.

v4.0.0

Full Changelog: docker/setup-qemu-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/setup-qemu-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/setup-qemu-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/setup-qemu-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/setup-qemu-action@v3.3.0...v3.4.0

v3.3.0

Full Changelog: docker/setup-qemu-action@v3.2.0...v3.3.0

v3.2.0

Full Changelog: docker/setup-qemu-action@v3.1.0...v3.2.0

v3.1.0

... (truncated)

Commits
  • ce36039 Merge pull request #245 from crazy-max/node24
  • 6386344 node 24 as default runtime
  • 1ea3db7 Merge pull request #243 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • b56a002 chore: update generated content
  • c43f02d build(deps): bump @​docker/actions-toolkit from 0.67.0 to 0.77.0
  • ce10c58 Merge pull request #244 from docker/dependabot/npm_and_yarn/actions/core-3.0.0
  • 429fc9d chore: update generated content
  • 060e5f8 build(deps): bump @​actions/core from 1.11.1 to 3.0.0
  • 44be13e Merge pull request #231 from docker/dependabot/npm_and_yarn/js-yaml-3.14.2
  • 1897438 chore: update generated content
  • Additional commits viewable in compare view

Updates docker/setup-buildx-action from 3 to 4

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.0.0

Full Changelog: docker/setup-buildx-action@v3.12.0...v4.0.0

v3.12.0

Full Changelog: docker/setup-buildx-action@v3.11.1...v3.12.0

v3.11.1

Full Changelog: docker/setup-buildx-action@v3.11.0...v3.11.1

v3.11.0

Full Changelog: docker/setup-buildx-action@v3.10.0...v3.11.0

v3.10.0

Full Changelog: docker/setup-buildx-action@v3.9.0...v3.10.0

v3.9.0

Full Changelog: docker/setup-buildx-action@v3.8.0...v3.9.0

v3.8.0

Full Changelog: docker/setup-buildx-action@v3.7.1...v3.8.0

... (truncated)

Commits
  • 4d04d5d Merge pull request #485 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • cd74e05 chore: update generated content
  • eee38ec build(deps): bump @​docker/actions-toolkit from 0.77.0 to 0.79.0
  • 7a83f65 Merge pull request #484 from docker/dependabot/github_actions/docker/setup-qe...
  • a5aa967 Merge pull request #464 from crazy-max/rm-deprecated
  • e73d53f build(deps): bump docker/setup-qemu-action from 3 to 4
  • 28a438e Merge pull request #483 from crazy-max/node24
  • 034e9d3 chore: update generated content
  • b4664d8 remove deprecated inputs/outputs
  • a8257de node 24 as default runtime
  • Additional commits viewable in compare view

Updates docker/build-push-action from 6 to 7

Release notes

Sourced from docker/build-push-action's releases.

v7.0.0

Full Changelog: docker/build-push-action@v6.19.2...v7.0.0

v6.19.2

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

v6.18.0

[!NOTE] Build summary is now supported with Docker Build Cloud.

Full Changelog: docker/build-push-action@v6.17.0...v6.18.0

v6.17.0

[!NOTE] Build record is now exported using the buildx history export command instead of the legacy export-build tool.

Full Changelog: docker/build-push-action@v6.16.0...v6.17.0

v6.16.0

... (truncated)

Commits
  • f9f3042 Merge pull request #1517 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 812d5fd chore: update generated content
  • b6f6693 chore(deps): Bump @​docker/actions-toolkit from 0.87.0 to 0.90.0
  • c1c626e Merge pull request #1525 from docker/dependabot/npm_and_yarn/actions/core-3.0.1
  • 51bb284 chore: update generated content
  • 5f7884d chore(deps): Bump @​actions/coreDescription has been truncated

… updates

Bumps the github-actions group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |
| [netcracker/qubership-workflow-hub](https://github.com/netcracker/qubership-workflow-hub) | `2.0.10` | `2.2.2` |
| [actions/download-artifact](https://github.com/actions/download-artifact) | `7.0.0` | `8.0.1` |
| [webiny/action-conventional-commits](https://github.com/webiny/action-conventional-commits) | `1.3.1` | `1.4.2` |
| [docker/metadata-action](https://github.com/docker/metadata-action) | `5` | `6` |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3` | `4` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6` | `7` |
| [netcracker/qubership-workflow-hub/.github/workflows/re-security-scan.yml](https://github.com/netcracker/qubership-workflow-hub) | `b36802acb86d790b877aa6c86098041dfc36ed25` | `58d49c7b22485c43f9999e73fa097e87fa1cd6c8` |
| [super-linter/super-linter](https://github.com/super-linter/super-linter) | `8.5.0` | `8.6.0` |



Updates `docker/login-action` from 3 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v3...v4)

Updates `netcracker/qubership-workflow-hub` from 2.0.10 to 2.2.2
- [Release notes](https://github.com/netcracker/qubership-workflow-hub/releases)
- [Commits](Netcracker/qubership-workflow-hub@8d542a4...6a2de8d)

Updates `actions/download-artifact` from 7.0.0 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v7...3e5f45b)

Updates `webiny/action-conventional-commits` from 1.3.1 to 1.4.2
- [Release notes](https://github.com/webiny/action-conventional-commits/releases)
- [Commits](webiny/action-conventional-commits@v1.3.1...v1.4.2)

Updates `docker/metadata-action` from 5 to 6
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](docker/metadata-action@v5...v6)

Updates `docker/setup-qemu-action` from 3 to 4
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@v3...v4)

Updates `docker/setup-buildx-action` from 3 to 4
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@v3...v4)

Updates `docker/build-push-action` from 6 to 7
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v6...v7)

Updates `netcracker/qubership-workflow-hub/.github/workflows/re-security-scan.yml` from b36802acb86d790b877aa6c86098041dfc36ed25 to 58d49c7b22485c43f9999e73fa097e87fa1cd6c8
- [Release notes](https://github.com/netcracker/qubership-workflow-hub/releases)
- [Commits](Netcracker/qubership-workflow-hub@b36802a...58d49c7)

Updates `super-linter/super-linter` from 8.5.0 to 8.6.0
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@61abc07...9e86335)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: netcracker/qubership-workflow-hub
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: webiny/action-conventional-commits
  dependency-version: 1.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/metadata-action
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/setup-qemu-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: netcracker/qubership-workflow-hub/.github/workflows/re-security-scan.yml
  dependency-version: 58d49c7b22485c43f9999e73fa097e87fa1cd6c8
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: super-linter/super-linter
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants