Skip to content

chore(deps): bump the actions group across 1 directory with 8 updates - #36

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-ec39a05952
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-ec39a05952

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown

Bumps the actions group with 8 updates in the / directory:

Package From To
openhoo/hooversion/actions/lint 1.1.1 1.1.2
docker/setup-buildx-action 4.3.0 4.4.1
openhoo/hoolicy/actions/check 0.3.1 0.3.2
openhoo/hooray/actions/scan 0.6.5 0.8.0
openhoo/hoonarqube/actions/analyze 0.3.1 0.8.2
openhoo/hooversion/actions/prepare-release 1.1.1 1.1.2
openhoo/hooversion/actions/release 1.1.1 1.1.2
docker/build-push-action 7.3.0 7.4.0

Updates openhoo/hooversion/actions/lint from 1.1.1 to 1.1.2

Release notes

Sourced from openhoo/hooversion/actions/lint's releases.

v1.1.2

What's Changed

Full Changelog: openhoo/hooversion@v1.1.1...v1.1.2

Changelog

Sourced from openhoo/hooversion/actions/lint's changelog.

@​openhoo/hooversion Changelog

1.1.2 (2026-09-18)

Bug Fixes

  • release: tolerate squash-merge subject suffix in resume derivation (#43) (9c0eb80)

Other Changes

  • ci: adopt Hooversion v1.1.1 (d500d01)
  • ci: adopt Hoonarqube v0.3.1 (96783b9)

1.1.1 (2026-09-03)

Bug Fixes

  • release: harden automation and webhook delivery (15f35c2)

Other Changes

  • ci: update Hoostack tool pins (#33) (1526329)
  • ci: update HooNeedsUpdates to v0.3.0 (3153886)
  • ci: enable manual CI recovery (#35) (9a87cd8)
  • policy: allow generated release branches (7c5d4a1)

1.1.0 (2026-08-31)

Features

  • verify: add published release verification (#30) (75d3a4b)

1.0.7 (2026-08-31)

Bug Fixes

  • align Hoostack policy and release supply chain (#27) (29e0517)
  • release: support protected release pull requests (8eff47f)

1.0.6 (2026-08-30)

Bug Fixes

  • release: include license in binary archives (#25) (0410989)

1.0.5 (2026-08-30)

Bug Fixes

  • release: publish prepared tag after protected PR (#23) (07e8654)

... (truncated)

Commits
  • f0a37cc chore(release): hooversion 1.1.2
  • 9c0eb80 fix(release): tolerate squash-merge subject suffix in resume derivation (#43)
  • 96783b9 chore(ci): adopt Hoonarqube v0.3.1
  • d500d01 chore(ci): adopt Hooversion v1.1.1
  • See full diff in compare view

Updates docker/setup-buildx-action from 4.3.0 to 4.4.1

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.4.1

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

Commits
  • f87e599 Merge pull request #624 from crazy-max/skip-pull-with-endpoint
  • e700274 chore: update generated content
  • 3061c91 skip BuildKit image pre-pulls for explicit endpoints
  • 594f3bf Merge pull request #609 from crazy-max/pull-buildkit-image-before-create
  • bd6e702 chore: update generated content
  • 6268c9d pull BuildKit image before builder creation
  • e823525 Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...
  • 533ed8e build(deps): bump the codeql-actions group with 2 updates
  • bedaf13 Merge pull request #620 from crazy-max/shared-error-helpers
  • d5079fb chore: update generated content
  • Additional commits viewable in compare view

Updates openhoo/hoolicy/actions/check from 0.3.1 to 0.3.2

Release notes

Sourced from openhoo/hoolicy/actions/check's releases.

hoolicy 0.3.2

0.3.2 (2026-09-08)

Bug Fixes

  • reports: harden GitHub and GitLab compatibility (3714dc8)

Other Changes

  • ci: converge released tool pins (c0fbd65)
Changelog

Sourced from openhoo/hoolicy/actions/check's changelog.

Changelog

0.3.2 (2026-09-08)

Bug Fixes

  • reports: harden GitHub and GitLab compatibility (3714dc8)

Other Changes

  • ci: converge released tool pins (c0fbd65)

0.3.1 (2026-09-03)

Bug Fixes

  • policy: preserve lifecycle and path safety (3730945)
  • policy: allow generated release branches (7de6ba4)

Other Changes

  • ci: update Hoostack tool pins (#19) (ad4fb19)
  • ci: update HooNeedsUpdates to v0.3.0 (269737d)

0.3.0 (2026-08-31)

Features

  • evidence: consume SLSA verification summaries (#15) (c95b4c0)

0.2.5 (2026-08-31)

Bug Fixes

  • align Hoostack policy and release supply chain (#11) (babc96c)
  • release: honor protected main branch (cd7072c)

0.2.4 (2026-08-30)

Bug Fixes

  • license: include complete Apache-2.0 terms (#9) (7f3a1d4)

Other Changes

  • standardize Hoostack dogfood (#8) (c7cd89e)

0.2.3 (2026-08-30)

Bug Fixes

... (truncated)

Commits
  • 17cac34 chore(release): hoolicy 0.3.2
  • 3714dc8 fix(reports): harden GitHub and GitLab compatibility
  • c0fbd65 chore(ci): converge released tool pins
  • See full diff in compare view

Updates openhoo/hooray/actions/scan from 0.6.5 to 0.8.0

Release notes

Sourced from openhoo/hooray/actions/scan's releases.

hooray 0.8.0

0.8.0 (2026-09-18)

Features

  • cli: add --offline flag matching documented behavior (#34) (4097058)
  • parsers: support Bun text lockfiles (#38) (945dda9)
  • parsers: add Chart.lock, composer.lock, and NuGet CPM/csproj/packages.config parsers (#52) (3b51a20)
  • parsers: add Gradle lockfile, Maven pom.xml, and Go stdlib toolchain coverage (#84) (62f91f6)
  • parsers: inventory Cabal dependencies and freeze pins (#103) (bc68185)
  • parsers: add Mix lockfile parser for Hex dependencies (#101) (e8ec136)
  • parsers: inventory Gradle version catalog declarations (#104) (190b85f)

Bug Fixes

  • scanner: exclude VCS metadata directories from repository walk (#35) (4a55ccd)
  • scanner: honor usedforsecurity=False in Python weak-hash rules (#36) (92f1172)
  • parsers: anchor asset identity to root lockfile (#37) (200232a)
  • scanners: tolerate JSONC/BOM IaC JSON, detect encrypted PEMs, skip regex literals (#51) (5e275b1)
  • parsers: pnpm v9 edges/scopes, specifier phantoms, bun asset identity (#53) (191e043)
  • core: OCI layer decompression, shared dependency-path index, honest introduced:0 (#54) (b5c2ca7)
  • cli: scope --format enums per subcommand; fix monitor target display and errors (#80) (b5a389c)
  • parsers: tolerate versionless SBOM entries, ./ tar roots, compressed tarballs (#82) (d3e7f2e)
  • parsers: indent-aware bundler/pod specs, poetry groups, honest unpinned versions (#81) (3961a76)
  • scanners: IaC anchoring/coverage, secret placeholder filtering, polyglot and SAST FPs (#83) (e5bb809)
  • parsers: preserve Composer lockfile licenses (#97) (228d4a8)
  • parsers: retain versioned yarn descriptor identities (#98) (57ea15f)
  • scanners: structure-aware PE recognition, escaped PEM detection, credential-shape suppression (#100) (82303be)
  • parsers: support legacy per-configuration Gradle lockfiles (#99) (f086600)
  • parsers: preserve Composer lockfile dependency edges (#102) (0c9de34)
  • parsers: exclude Maven template placeholders and record unresolved declarations (#105) (8d1085a)

Other Changes

  • issues: port issue governance and exploratory-smoke campaign skills (#28) (e6533f9)
  • ci: adopt Hoolicy v0.3.2 action check (#107) (6ed727c)
  • ci: adopt Hoonarqube v0.8.2 analyze action (#108) (878d667)
  • deps: bump tower-http from 0.6.11 to 0.7.1 (#109) (25a8cf2)
  • deps: bump sha2 from 0.10.9 to 0.11.0 (#110) (e3bc6df)
  • deps: bump spdx from 0.10.9 to 0.13.5 (#111) (cbfe559)
  • deps: bump jsonschema from 0.47.0 to 0.56.0 (#112) (0575b91)
  • deps: bump zip from 4.6.1 to 8.6.0 (#113) (cac74fa)
  • release: adopt Hooversion v1.1.2 for squash-suffix release resume (#114) (91b32d6) Hooray-OCI-Digest: ghcr.io/openhoo/hooray@sha256:50e7e99304cd7345538a88caa4582f2d462f52f021035cf8ab1355267b8d3119

hooray 0.6.6

0.6.6 (2026-09-08)

Bug Fixes

... (truncated)

Changelog

Sourced from openhoo/hooray/actions/scan's changelog.

Changelog

0.8.0 (2026-09-18)

Features

  • cli: add --offline flag matching documented behavior (#34) (4097058)
  • parsers: support Bun text lockfiles (#38) (945dda9)
  • parsers: add Chart.lock, composer.lock, and NuGet CPM/csproj/packages.config parsers (#52) (3b51a20)
  • parsers: add Gradle lockfile, Maven pom.xml, and Go stdlib toolchain coverage (#84) (62f91f6)
  • parsers: inventory Cabal dependencies and freeze pins (#103) (bc68185)
  • parsers: add Mix lockfile parser for Hex dependencies (#101) (e8ec136)
  • parsers: inventory Gradle version catalog declarations (#104) (190b85f)

Bug Fixes

  • scanner: exclude VCS metadata directories from repository walk (#35) (4a55ccd)
  • scanner: honor usedforsecurity=False in Python weak-hash rules (#36) (92f1172)
  • parsers: anchor asset identity to root lockfile (#37) (200232a)
  • scanners: tolerate JSONC/BOM IaC JSON, detect encrypted PEMs, skip regex literals (#51) (5e275b1)
  • parsers: pnpm v9 edges/scopes, specifier phantoms, bun asset identity (#53) (191e043)
  • core: OCI layer decompression, shared dependency-path index, honest introduced:0 (#54) (b5c2ca7)
  • cli: scope --format enums per subcommand; fix monitor target display and errors (#80) (b5a389c)
  • parsers: tolerate versionless SBOM entries, ./ tar roots, compressed tarballs (#82) (d3e7f2e)
  • parsers: indent-aware bundler/pod specs, poetry groups, honest unpinned versions (#81) (3961a76)
  • scanners: IaC anchoring/coverage, secret placeholder filtering, polyglot and SAST FPs (#83) (e5bb809)
  • parsers: preserve Composer lockfile licenses (#97) (228d4a8)
  • parsers: retain versioned yarn descriptor identities (#98) (57ea15f)
  • scanners: structure-aware PE recognition, escaped PEM detection, credential-shape suppression (#100) (82303be)
  • parsers: support legacy per-configuration Gradle lockfiles (#99) (f086600)
  • parsers: preserve Composer lockfile dependency edges (#102) (0c9de34)
  • parsers: exclude Maven template placeholders and record unresolved declarations (#105) (8d1085a)

Other Changes

  • issues: port issue governance and exploratory-smoke campaign skills (#28) (e6533f9)
  • ci: adopt Hoolicy v0.3.2 action check (#107) (6ed727c)
  • ci: adopt Hoonarqube v0.8.2 analyze action (#108) (878d667)
  • deps: bump tower-http from 0.6.11 to 0.7.1 (#109) (25a8cf2)
  • deps: bump sha2 from 0.10.9 to 0.11.0 (#110) (e3bc6df)
  • deps: bump spdx from 0.10.9 to 0.13.5 (#111) (cbfe559)
  • deps: bump jsonschema from 0.47.0 to 0.56.0 (#112) (0575b91)
  • deps: bump zip from 4.6.1 to 8.6.0 (#113) (cac74fa)
  • release: adopt Hooversion v1.1.2 for squash-suffix release resume (#114) (91b32d6)

0.7.0 (2026-09-18)

Features

  • cli: add --offline flag matching documented behavior (#34) (4097058)

... (truncated)

Commits
  • e7374b1 chore(release): hooray 0.8.0
  • 91b32d6 ci(release): adopt Hooversion v1.1.2 for squash-suffix release resume (#114)
  • cac74fa chore(deps): bump zip from 4.6.1 to 8.6.0 (#113)
  • 0575b91 chore(deps): bump jsonschema from 0.47.0 to 0.56.0 (#112)
  • cbfe559 chore(deps): bump spdx from 0.10.9 to 0.13.5 (#111)
  • e3bc6df chore(deps): bump sha2 from 0.10.9 to 0.11.0 (#110)
  • 25a8cf2 chore(deps): bump tower-http from 0.6.11 to 0.7.1 (#109)
  • 878d667 chore(ci): adopt Hoonarqube v0.8.2 analyze action (#108)
  • 6ed727c chore(ci): adopt Hoolicy v0.3.2 action check (#107)
  • 738711d chore(release): hooray 0.7.0 (#106)
  • Additional commits viewable in compare view

Updates openhoo/hoonarqube/actions/analyze from 0.3.1 to 0.8.2

Release notes

Sourced from openhoo/hoonarqube/actions/analyze's releases.

hoonarqube 0.8.2

0.8.2 (2026-09-11)

Bug Fixes

  • hoonarqube: harden analysis boundaries and quick fixes (e7add58)

hoonarqube 0.8.1

0.8.1 (2026-09-10)

Bug Fixes

  • hoonarqube: qualify remaining parity and guarded fixes (e71a7e6)

hoonarqube 0.8.0

0.8.0 (2026-09-10)

Features

  • hoonarqube: complete analysis capabilities and evidence boundaries (d6048e6)

hoonarqube 0.7.1

0.7.1 (2026-09-09)

Bug Fixes

  • hoonarqube: correct real-project analyzer findings (#84) (cf6a668)

hoonarqube 0.7.0

0.7.0 (2026-09-08)

Features

  • cli: cache unchanged file analysis (#33) (036baa2)

hoonarqube 0.6.0

0.6.0 (2026-09-08)

Features

  • cli: add native GitLab Code Quality reports (a47fcf7)

hoonarqube 0.5.1

0.5.1 (2026-09-08)

Performance

  • hoonarqube: optimize duplication coverage and benchmark scaling (3dd0d68)

hoonarqube 0.5.0

... (truncated)

Changelog

Sourced from openhoo/hoonarqube/actions/analyze's changelog.

Changelog

0.9.0 (2026-09-20)

Features

  • jsts: add S7719, S7722, S7723, S7724, S7726 detectors for pinned anchors (#308) (dad91fe)
  • catalog: add java and ruby sonar surfaces from community captures (#307) (7ba72d1)
  • python: add S3415 S5778 S5779 S5863 S5958 test detectors (#154-#158) (#309) (ae685a9)
  • catalog: add supplement mode for already-frozen catalog languages (#310) (a854095)
  • catalog: supplement javascript and typescript S7719-S7726 keys from fresh capture (#311) (fc6151d)
  • python: add S8502 S8510 S8513 S8714 S8786 reference detectors (#159-#163) (#313) (16604de)
  • jsts: add S7737, S7741, S7744, S7746, S7751 detectors for pinned anchors (#314) (275e946)
  • catalog: supplement javascript and typescript S7737-S7751 keys from fresh capture (#316) (1735995)
  • python: add S8997 S9000 S9001 S9073 test detectors (#164-#167) (#317) (662115d)
  • jsts: add S7754 S7755 S7765 S7766 S7770 detectors for pinned anchors (#320) (4fe72ed)
  • jsts: add S7773 S7776 S7780 S7781 S7786 detectors for pinned anchors (#323) (78e50fb)
  • python: add S9075 S9078 S9083 detectors, widen S2245, add py/file-not-closed (#324) (23cd6f7)
  • jsts: implement four GitHub Code Quality detectors (#144-147) (#327) (c391c2c)
  • go: register 17 catalog-claimed gcq quality queries (#422) (0af8393)
  • java: register 15 single-file-provable gcq quality queries (#426) (b9d307d)
  • python: add S1721 keyword-parentheses and S6538 return-type-hint coverage (#423) (fb92af5)
  • python: add S8992 autouse+params fixture detector, supplement key (#361) (#430) (934c430)
  • java: register 17 single-file-provable gcq quality queries (#429) (840ef50)
  • csharp: close S2486/S3415 coverage, extend S1128/S3218/S2931 single-file subsets (#431) (96d4285)
  • ruby: open sonar-parity route with ruby:S1192 duplicate-literal detector (#433) (4523678)
  • jsts: add S7728 S7721 S5906 S7772 detectors with catalog keys (#436) (6d36f62)
  • csharp: verify S1128/S3218/S2931 partials, extend six coverage-tail rules (#437) (ad4c6e6)
  • java: open sonar-parity route with S1117 S1854 S2143 S2211 detectors (#438) (51474f2)
  • ruby: add S1067 S126 S134 S1764 sonar-parity detectors (#440) (20b4879)
  • jsts: add eight S77xx/S8754/S6437 detectors with catalog keys (#439) (7f3ebd2)
  • jsts: add seven S77xx/S5914/S1244 detectors with catalog keys (#441) (2f630c9)
  • jsts: add S7735 S8786 detectors with catalog keys (#442) (9b07fc9)
  • csharp: add S8969 redundant null-forgiving detector with catalog key (#443) (d7ee2f2)
  • csharp: close S1200 S3261 S2245 S6608 S1006 dapper false negatives (#444) (8eb55a6)
  • hoonarqube-jsts: add S7763 S7767 detectors with catalog keys (#572) (22ba9d1)
  • python: add S8994/S8998/S9074/S9076/S9077/S9084/S9116 detectors for catalog parity (#682) (#739) (2fec434)
  • python: add S8492/S8495/S8500/S8507/S8509/S8512/S8514 detectors (#682) (#740) (5b0d51e)
  • python: add S8517-S8521/S8554/S8572 idiom detectors for catalog parity (#682) (#741) (21a3087)
  • python: add S7931/S7941/S7942/S7943/S7945/S8490/S8493/S8494 detectors (#682) (#742) (ec618a2)
  • python: add S6965/S8401/S8412-S8415 web framework detectors (#682) (#743) (e1a6d93)
  • python: add S8396/S8953/S8963/S8966/S8971/S8973 Pydantic detectors (#682) (#744) (ce6f84d)
  • python: add S6863/S8370/S8371/S8374/S8375/S8385/S8400 web-framework detectors (#682) (#745) (a1fe6db)
  • python: add S8389/S8397/S8405/S8409-S8411 FastAPI detectors (#682) (#746) (e529ff7)
  • python: add S7618-S7622 AWS Lambda operational detectors (#682) (#747) (0bc23f1)
  • python: add S7608/S7609/S7613/S7614/S7617 boto3/Lambda detectors (#682) (#748) (fb13c5a)
  • python: add S8900/S8903-S8906 BeautifulSoup detectors (#682) (#750) (92d7c54)
  • python: add S6243/S6246/S6249/S6262/S7625 AWS core detectors (#682) (#749) (0b23e4f)
  • python: add S5976/S8993/S8999 pytest detectors (#682) (#751) (5d4e8af)
  • python: add S8392/S8503-S8505/S8508/S8974/S8978 detectors (#682) (#752) (0760903)

... (truncated)

Commits
  • 5ea3135 chore(release): hoonarqube 0.8.2
  • e7add58 fix(hoonarqube): harden analysis boundaries and quick fixes
  • 36c6036 chore(release): hoonarqube 0.8.1
  • e71a7e6 fix(hoonarqube): qualify remaining parity and guarded fixes
  • bc243da chore(release): hoonarqube 0.8.0
  • d6048e6 feat(hoonarqube): complete analysis capabilities and evidence boundaries
  • 7732e40 chore(release): hoonarqube 0.7.1
  • cf6a668 fix(hoonarqube): correct real-project analyzer findings (#84)
  • 91eea1f chore(release): hoonarqube 0.7.0
  • 036baa2 feat(cli): cache unchanged file analysis (#33)
  • Additional commits viewable in compare view

Updates openhoo/hooversion/actions/prepare-release from 1.1.1 to 1.1.2

Release notes

Sourced from openhoo/hooversion/actions/prepare-release's releases.

v1.1.2

What's Changed

Full Changelog: openhoo/hooversion@v1.1.1...v1.1.2

Changelog

Sourced from openhoo/hooversion/actions/prepare-release's changelog.

@​openhoo/hooversion Changelog

1.1.2 (2026-09-18)

Bug Fixes

  • release: tolerate squash-merge subject suffix in resume derivation (#43) (9c0eb80)

Other Changes

  • ci: adopt Hooversion v1.1.1 (d500d01)
  • ci: adopt Hoonarqube v0.3.1 (96783b9)

1.1.1 (2026-09-03)

Bug Fixes

  • release: harden automation and webhook delivery (15f35c2)

Other Changes

  • ci: update Hoostack tool pins (#33) (1526329)
  • ci: update HooNeedsUpdates to v0.3.0 (3153886)
  • ci: enable manual CI recovery (#35) (9a87cd8)
  • policy: allow generated release branches (7c5d4a1)

1.1.0 (2026-08-31)

Features

  • verify: add published release verification (#30) (75d3a4b)

1.0.7 (2026-08-31)

Bug Fixes

  • align Hoostack policy and release supply chain (#27) (29e0517)
  • release: support protected release pull requests (8eff47f)

1.0.6 (2026-08-30)

Bug Fixes

  • release: include license in binary archives (#25) (0410989)

1.0.5 (2026-08-30)

Bug Fixes

  • release: publish prepared tag after protected PR (#23) (07e8654)

... (truncated)

Commits
  • f0a37cc chore(release): hooversion 1.1.2
  • 9c0eb80 fix(release): tolerate squash-merge subject suffix in resume derivation (#43)
  • 96783b9 chore(ci): adopt Hoonarqube v0.3.1
  • d500d01 chore(ci): adopt Hooversion v1.1.1
  • See full diff in compare view

Updates openhoo/hooversion/actions/release from 1.1.1 to 1.1.2

Release notes

Sourced from openhoo/hooversion/actions/release's releases.

v1.1.2

What's Changed

Full Changelog: openhoo/hooversion@v1.1.1...v1.1.2

Changelog

Sourced from openhoo/hooversion/actions/release's changelog.

@​openhoo/hooversion Changelog

1.1.2 (2026-09-18)

Bug Fixes

  • release: tolerate squash-merge subject suffix in resume derivation (#43) (9c0eb80)

Other Changes

  • ci: adopt Hooversion v1.1.1 (d500d01)
  • ci: adopt Hoonarqube v0.3.1 (96783b9)

1.1.1 (2026-09-03)

Bug Fixes

  • release: harden automation and webhook delivery (15f35c2)

Other Changes

  • ci: update Hoostack tool pins (#33) (1526329)
  • ci: update HooNeedsUpdates to v0.3.0 (3153886)
  • ci: enable manual CI recovery (#35) (9a87cd8)
  • policy: allow generated release branches (7c5d4a1)

1.1.0 (2026-08-31)

Features

  • verify: add published release verification (#30) (75d3a4b)

1.0.7 (2026-08-31)

Bug Fixes

  • align Hoostack policy and release supply chain (#27) (29e0517)
  • release: support protected release pull requests (8eff47f)

1.0.6 (2026-08-30)

Bug Fixes

  • release: include license in binary archives (#25) (0410989)

1.0.5 (2026-08-30)

Bug Fixes

  • release: publish prepared tag after protected PR (#23) (07e8654)

... (truncated)

Commits
  • f0a37cc chore(release): hooversion 1.1.2
  • 9c0eb80 fix(release): tolerate squash-merge subject suffix in resume derivation (#43)
  • 96783b9 chore(ci): adopt Hoonarqube v0.3.1
  • d500d01 chore(ci): adopt Hooversion v1.1.1
  • See full diff in compare view

Updates docker/build-push-action from 7.3.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.

v7.4.0

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [openhoo/hooversion/actions/lint](https://github.com/openhoo/hooversion) | `1.1.1` | `1.1.2` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |
| [openhoo/hoolicy/actions/check](https://github.com/openhoo/hoolicy) | `0.3.1` | `0.3.2` |
| [openhoo/hooray/actions/scan](https://github.com/openhoo/hooray) | `0.6.5` | `0.8.0` |
| [openhoo/hoonarqube/actions/analyze](https://github.com/openhoo/hoonarqube) | `0.3.1` | `0.8.2` |
| [openhoo/hooversion/actions/prepare-release](https://github.com/openhoo/hooversion) | `1.1.1` | `1.1.2` |
| [openhoo/hooversion/actions/release](https://github.com/openhoo/hooversion) | `1.1.1` | `1.1.2` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |



Updates `openhoo/hooversion/actions/lint` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/openhoo/hooversion/releases)
- [Changelog](https://github.com/openhoo/hooversion/blob/main/CHANGELOG.md)
- [Commits](openhoo/hooversion@ac503b2...f0a37cc)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

Updates `openhoo/hoolicy/actions/check` from 0.3.1 to 0.3.2
- [Release notes](https://github.com/openhoo/hoolicy/releases)
- [Changelog](https://github.com/openhoo/hoolicy/blob/main/CHANGELOG.md)
- [Commits](openhoo/hoolicy@46529a9...17cac34)

Updates `openhoo/hooray/actions/scan` from 0.6.5 to 0.8.0
- [Release notes](https://github.com/openhoo/hooray/releases)
- [Changelog](https://github.com/openhoo/hooray/blob/main/CHANGELOG.md)
- [Commits](openhoo/hooray@f2b28d7...e7374b1)

Updates `openhoo/hoonarqube/actions/analyze` from 0.3.1 to 0.8.2
- [Release notes](https://github.com/openhoo/hoonarqube/releases)
- [Changelog](https://github.com/openhoo/hoonarqube/blob/main/CHANGELOG.md)
- [Commits](openhoo/hoonarqube@03b34bc...5ea3135)

Updates `openhoo/hooversion/actions/prepare-release` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/openhoo/hooversion/releases)
- [Changelog](https://github.com/openhoo/hooversion/blob/main/CHANGELOG.md)
- [Commits](openhoo/hooversion@ac503b2...f0a37cc)

Updates `openhoo/hooversion/actions/release` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/openhoo/hooversion/releases)
- [Changelog](https://github.com/openhoo/hooversion/blob/main/CHANGELOG.md)
- [Commits](openhoo/hooversion@ac503b2...f0a37cc)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: openhoo/hooversion/actions/lint
  dependency-version: 1.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: openhoo/hoolicy/actions/check
  dependency-version: 0.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: openhoo/hooray/actions/scan
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: openhoo/hoonarqube/actions/analyze
  dependency-version: 0.8.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: openhoo/hooversion/actions/prepare-release
  dependency-version: 1.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: openhoo/hooversion/actions/release
  dependency-version: 1.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@github-code-quality

Copy link
Copy Markdown

Code Coverage Overview

Languages: Go

Go / code-coverage/go

The overall line coverage in commit 9849d94 in the dependabot/github_ac... branch remains at 75%, unchanged from commit 24217a1 in the main branch.

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-ec39a05952 branch October 5, 2026 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants