Repository navigation
ci(deps): Bump the actions group across 1 directory with 3 updates - #13
Conversation
Bumps the actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [dorny/paths-filter](https://github.com/dorny/paths-filter) and [actions/setup-python](https://github.com/actions/setup-python). Updates `actions/checkout` from 6.0.3 to 7.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@df4cb1c...9c091bb) Updates `dorny/paths-filter` from 4.0.1 to 4.0.2 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](dorny/paths-filter@fbd0ab8...7b450ff) Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@a309ff8...ece7cb0) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: dorny/paths-filter dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
📝 WalkthroughWalkthroughThis PR updates pinned commit SHAs for GitHub Actions (actions/checkout, actions/setup-python, dorny/paths-filter) across jobs in ci.yml and molecule.yml workflow files. No workflow logic, job structure, or configuration otherwise changed. ChangesGitHub Actions SHA Pin Updates
Estimated code review effort: 1 (Trivial) | ~3 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 30-31: The workflow’s checkout steps are leaving repo credentials
persisted even though these jobs only lint/build/scan and do not need git auth.
Update every actions/checkout invocation in the CI workflow to set
persist-credentials to false so the token is not written into .git/config; make
this change consistently wherever checkout is used.
In @.github/workflows/molecule.yml:
- Around line 28-29: Update the Molecule workflow’s actions/checkout step to
disable persisted GitHub credentials by setting persist-credentials to false.
This job only runs tests, so adjust the checkout configuration directly in the
checkout action entry to prevent the token from being stored in git config and
reduce exposure.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: eb8e5fa3-4a1b-4c6d-aadf-04b7563deb4c
📒 Files selected for processing (2)
.github/workflows/ci.yml.github/workflows/molecule.yml
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Inspect the workflow file around the cited lines.
git ls-files .github/workflows/ci.yml
wc -l .github/workflows/ci.yml
sed -n '1,220p' .github/workflows/ci.yml | cat -n
# Look for any subsequent git push/auth usage that would require persisted credentials.
rg -n --no-heading -S 'git (push|fetch|submodule|clone)|github\.token|persist-credentials|checkout@' .github/workflows/ci.ymlRepository: decdn/devops
Length of output: 8141
Disable persisted credentials on each checkout step. .github/workflows/ci.yml:30,48,80,120,155 These jobs only lint/build/scan and never need repo auth, so add persist-credentials: false to every actions/checkout invocation to keep the token out of .git/config.
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 30-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml around lines 30 - 31, The workflow’s checkout steps
are leaving repo credentials persisted even though these jobs only
lint/build/scan and do not need git auth. Update every actions/checkout
invocation in the CI workflow to set persist-credentials to false so the token
is not written into .git/config; make this change consistently wherever checkout
is used.
Source: Linters/SAST tools
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Show the workflow around the referenced lines with numbers.
sed -n '1,120p' .github/workflows/molecule.yml | cat -nRepository: decdn/devops
Length of output: 1562
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Check whether the Molecule job or Ansible test setup depends on git credentials or submodules.
rg -n --hidden --glob '!**/.git/**' \
-e 'submodule' -e 'git ' -e 'github.token' -e 'GITHUB_TOKEN' -e 'persist-credentials' \
.github ansibleRepository: decdn/devops
Length of output: 257
Disable persisted credentials on checkout. This job only runs Molecule tests, so the GitHub token does not need to remain in git config. Set persist-credentials: false on actions/checkout to reduce token exposure.
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 28-28: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/molecule.yml around lines 28 - 29, Update the Molecule
workflow’s actions/checkout step to disable persisted GitHub credentials by
setting persist-credentials to false. This job only runs tests, so adjust the
checkout configuration directly in the checkout action entry to prevent the
token from being stored in git config and reduce exposure.
Source: Linters/SAST tools
Bumps the actions group with 3 updates in the / directory: actions/checkout, dorny/paths-filter and actions/setup-python.
Updates
actions/checkoutfrom 6.0.3 to 7.0.0Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Updates
dorny/paths-filterfrom 4.0.1 to 4.0.2Release notes
Sourced from dorny/paths-filter's releases.
Changelog
Sourced from dorny/paths-filter's changelog.
... (truncated)
Commits
7b450ffdocs: update changelog for v4.0.2 (#318)9280377fix: work around git dubious ownership errors in container jobs (#317)f3ceefdfix: use rev-parse instead of branch --show-current for older git compat (#303)61f87a1chore: fix GitHub spelling in logs (#278)b82ff81fix warning message (#282)Updates
actions/setup-pythonfrom 6.2.0 to 6.3.0Release notes
Sourced from actions/setup-python's releases.
Commits
ece7cb0Fix pip cache error handling on Windows. (#1040)1d18d7aUpdate advanced-usage.md (#811)d2b357aUpdate dependency versions and test workflow configuration (#1322)8f639b1Merge pull request #1324 from jasongin/update-actions-cache-5.1.06731c2bResolve high-severity audit issues0cb1a84Add RHEL support and include Linux distro in cache keys (#1323)dc6eab6Update dist6f4b74bStrict equalityfa8bde1Bump@actions/cacheto 5.1.0, log cache write deniedc8813baUpgrade@actionsdependencies and update licenses (#1303)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsSummary by CodeRabbit