chore(deps): bump the actions-minor-and-patch group across 1 directory with 8 updates - #1492
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
force-pushed
the
dependabot/github_actions/dev/actions-minor-and-patch-3b6737d5e1
branch
from
September 16, 2026 22:06
f55938c to
0da475c
Compare
…y with 8 updates Bumps the actions-minor-and-patch group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.1` | `4.2.2` | | [devops-actions/actionlint](https://github.com/devops-actions/actionlint) | `0.1.10` | `0.1.13` | | [bridgecrewio/checkov-action](https://github.com/bridgecrewio/checkov-action) | `12.3075.0` | `12.3125.0` | | [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `8.2.0` | `8.2.2` | | [aws-actions/amazon-ecr-login](https://github.com/aws-actions/amazon-ecr-login) | `2.1.6` | `2.1.7` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.35.4` | `4.38.1` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.35.4` | `4.38.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.35.4` | `4.38.1` | Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@0f67c3f...4d10147) Updates `devops-actions/actionlint` from 0.1.10 to 0.1.13 - [Release notes](https://github.com/devops-actions/actionlint/releases) - [Commits](devops-actions/actionlint@467e2ce...ec02b36) Updates `bridgecrewio/checkov-action` from 12.3075.0 to 12.3125.0 - [Release notes](https://github.com/bridgecrewio/checkov-action/releases) - [Commits](bridgecrewio/checkov-action@02a4c5d...444c9db) Updates `SonarSource/sonarqube-scan-action` from 8.2.0 to 8.2.2 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@7138816...ba9859e) Updates `aws-actions/amazon-ecr-login` from 2.1.6 to 2.1.7 - [Release notes](https://github.com/aws-actions/amazon-ecr-login/releases) - [Changelog](https://github.com/aws-actions/amazon-ecr-login/blob/main/CHANGELOG.md) - [Commits](aws-actions/amazon-ecr-login@d539f09...03f1aad) Updates `github/codeql-action/init` from 4.35.4 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...1c5b675) Updates `github/codeql-action/autobuild` from 4.35.4 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...1c5b675) Updates `github/codeql-action/analyze` from 4.35.4 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...1c5b675) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: aws-actions/amazon-ecr-login dependency-version: 2.1.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch - dependency-name: bridgecrewio/checkov-action dependency-version: 12.3121.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: devops-actions/actionlint dependency-version: 0.1.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/autobuild dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/dev/actions-minor-and-patch-3b6737d5e1
branch
from
September 21, 2026 21:44
0da475c to
e73e91b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions-minor-and-patch group with 8 updates in the / directory:
4.1.14.2.20.1.100.1.1312.3075.012.3125.08.2.08.2.22.1.62.1.74.35.44.38.14.35.44.38.14.35.44.38.1Updates
actions/attest-build-provenancefrom 4.1.1 to 4.2.2Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)Updates
devops-actions/actionlintfrom 0.1.10 to 0.1.13Release notes
Sourced from devops-actions/actionlint's releases.
... (truncated)
Commits
ec02b36Drop the unneeded pull-requests: write permission (#210)621ddf5Fix shell issues in the action script (#212)34c3538Fix file path parsing for consecutive actionlint errors (#211)f9ec6b4chore(deps): bump the github-actions group with 7 updates (#209)887b104chore(deps): bump the github-actions group across 1 directory with 7 updates ...2e68a47chore(deps): bump the github-actions group with 6 updates (#206)3efb329Merge pull request #205 from devops-actions/dependabot/github_actions/github-...4bd4c0fchore(deps): bump the github-actions group with 2 updatesadbfa07chore: group github-actions dependabot updates (#204)af0b0b8chore(deps): bump devops-actions/.github/.github/workflows/approve-dependabot...Updates
bridgecrewio/checkov-actionfrom 12.3075.0 to 12.3125.0Commits
444c9dbBump checkov container version to 3.3.1956271afBump checkov container version to 3.3.18a8664e3Bump checkov container version to 3.3.17f967808Bump checkov container version to 3.3.165659ddeBump checkov container version to 3.3.15ec0fde7Bump checkov container version to 3.3.1459b9d7eBump checkov container version to 3.3.133be6be7Bump checkov container version to 3.3.121246d92Bump checkov container version to 3.3.11358405dBump checkov container version to 3.3.10Updates
SonarSource/sonarqube-scan-actionfrom 8.2.0 to 8.2.2Release notes
Sourced from SonarSource/sonarqube-scan-action's releases.
Commits
ba9859eSQSCANGHA-159 Bump undici from 6.24.1 to 6.28.1 (#261)5bc5285Rename code-quality teams to code-orchestration in CODEOWNERSad82103SQSCANGHA-158 NO-JIRA Bump actions/checkout from 7.0.0 to 7.0.1 (#260)7451dafSQSCANGHA-157 NO-JIRA Bump actions/setup-node from 6.4.0 to 7.0.0 (#259)2291811SQSCANGHA-156 GPG signature verification fails when temporary directory path ...7cdc154SQSCANGHA-153 NO-JIRA Bump actions/checkout from 6.0.2 to 7.0.0 (#255)45f2736SQSCANGHA-151 Change Code Owners (#254)Updates
aws-actions/amazon-ecr-loginfrom 2.1.6 to 2.1.7Release notes
Sourced from aws-actions/amazon-ecr-login's releases.
Changelog
Sourced from aws-actions/amazon-ecr-login's changelog.
... (truncated)
Commits
03f1aadchore(release): 2.1.7af990dachore: Update dist (#1250)824b400chore(deps): bump@aws-sdk/client-ecrfrom 3.1106.0 to 3.1111.0 (#1242)12a27d2chore(deps): bump@aws-sdk/credential-providers(#1241)606a5e3chore: Update dist (#1246)7e05affchore(deps-dev): bump@vercel/nccfrom 0.44.1 to 0.45.0 (#1239)b342b60chore(deps-dev): bump globals from 17.9.0 to 17.11.0 (#1240)c2241b0chore(deps): bump@aws-sdk/client-ecr-publicfrom 3.1106.0 to 3.1111.0 (#1238)7fd27f2chore: Update dist (#1236)b4eaaadchore(deps): bump@aws-sdk/client-ecr-publicfrom 3.1097.0 to 3.1106.0 (#1226)Updates
github/codeql-action/initfrom 4.35.4 to 4.38.1Release notes
Sourced from github/codeql-action/init's releases.
... (truncated)
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/autobuildfrom 4.35.4 to 4.38.1Release notes
Sourced from github/codeql-action/autobuild's releases.
... (truncated)
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/analyzefrom 4.35.4 to 4.38.1Release notes
Sourced from github/codeql-action/analyze's releases.