chore(deps): bump the github-actions group with 9 updates#96
chore(deps): bump the github-actions group with 9 updates#96dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions group with 9 updates: | Package | From | To | | --- | --- | --- | | [geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml](https://github.com/geolonia/.github) | `1.16.0` | `1.19.0` | | [geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.0` | `6.2.1` | | [geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` | | [geolonia/.github/.github/workflows/reusable-secret-leak-check.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` | | [geolonia/.github/.github/workflows/reusable-pinact-check.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` | | [geolonia/.github/.github/workflows/reusable-route-issue.yml](https://github.com/geolonia/.github) | `1.16.0` | `1.19.0` | | [geolonia/.github/.github/workflows/reusable-security-suite.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` | Updates `geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml` from 1.16.0 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](92c8c6d...c98b846) Updates `geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml` from 1 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](v1...v1.19.0) Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@a309ff8...ece7cb0) Updates `aws-actions/configure-aws-credentials` from 6.2.0 to 6.2.1 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@e7f100c...254c19b) Updates `geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml` from 1 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](v1...v1.19.0) Updates `geolonia/.github/.github/workflows/reusable-secret-leak-check.yml` from 1 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](v1...v1.19.0) Updates `geolonia/.github/.github/workflows/reusable-pinact-check.yml` from 1 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](v1...v1.19.0) Updates `geolonia/.github/.github/workflows/reusable-route-issue.yml` from 1.16.0 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](92c8c6d...c98b846) Updates `geolonia/.github/.github/workflows/reusable-security-suite.yml` from 1 to 1.19.0 - [Release notes](https://github.com/geolonia/.github/releases) - [Commits](v1...v1.19.0) --- updated-dependencies: - dependency-name: geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.2.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-secret-leak-check.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-pinact-check.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-route-issue.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: geolonia/.github/.github/workflows/reusable-security-suite.yml dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
WalkthroughThis PR updates pinned versions across GitHub Actions workflow files: reusable workflow references (publish-techdocs, release-auto-on-tag, route-issue, security-suite, reusable-security-suite) are bumped to v1.19.0, and third-party actions (actions/setup-python, aws-actions/configure-aws-credentials) are updated to newer pinned commits in techdocs and cdk-deploy-monitor workflows. ChangesWorkflow version bumps
Estimated code review effort: 1 (Trivial) | ~5 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/security-suite.yml (1)
43-52: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winComment documents intentional floating on major tag; code now pins
@v1.19.0.The comment explains at length why this ref should float (
"a floating reusable ref here is FINE", org pinact/zizmor exemptions for geolonia/* reusables at a major tag) so the suite auto-upgrades without a chain-bump PR. The Dependabot bump instead pinned to@v1.19.0, contradicting the documented policy and losing the "no chain-bump" auto-upgrade behavior this comment relies on.🔧 Options
- uses: geolonia/.github/.github/workflows/reusable-security-suite.yml@v1.19.0 + uses: geolonia/.github/.github/workflows/reusable-security-suite.yml@v1Or update the comment if pinning is now intended going forward.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/security-suite.yml around lines 43 - 52, The reusable workflow reference in security-suite.yml is pinned to a release tag, but the comment and policy in the workflow say this should stay floating on the major tag for automatic upgrades. Update the `uses` reference in `reusable-security-suite.yml` invocation back to `@v1` so the required workflow continues to float without chain-bump PRs, or if pinning is now intended, revise the surrounding comment to match the new policy.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release-auto-on-tag.yml:
- Around line 12-14: The reusable workflow reference in the release-auto-on-tag
workflow is now pinned to a specific version while the nearby comment still says
it should float on `@v1`. Update the workflow and the comment together in
release-auto-on-tag so they match: either restore the uses reference to `@v1`, or
revise/remove the “Float on `@v1`” note if pinning to v1.19.0 is the intended
policy.
---
Outside diff comments:
In @.github/workflows/security-suite.yml:
- Around line 43-52: The reusable workflow reference in security-suite.yml is
pinned to a release tag, but the comment and policy in the workflow say this
should stay floating on the major tag for automatic upgrades. Update the `uses`
reference in `reusable-security-suite.yml` invocation back to `@v1` so the
required workflow continues to float without chain-bump PRs, or if pinning is
now intended, revise the surrounding comment to match the new policy.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 18d95b97-4717-4434-9465-55c570b82a15
📒 Files selected for processing (7)
.github/workflows/publish-techdocs.yml.github/workflows/release-auto-on-tag.yml.github/workflows/reusable-backstage-techdocs.yml.github/workflows/reusable-cdk-deploy-monitor.yml.github/workflows/reusable-security-suite.yml.github/workflows/route-issue.yml.github/workflows/security-suite.yml
| # Float on @v1 (this is a normal, non-required workflow) so we pick up the | ||
| # lightweight-tag peel fix and future release-workflow changes automatically. | ||
| uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1 | ||
| uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0 |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Comment says "Float on @v1" but code now pins @v1.19.0.
The comment explains the intentional choice to float so the workflow auto-picks-up future fixes, but the Dependabot bump pinned it to a specific version, contradicting that documented rationale. Either restore floating on @v1 or update the comment to reflect the new pinning approach.
🔧 Options
- # Float on `@v1` (this is a normal, non-required workflow) so we pick up the
- # lightweight-tag peel fix and future release-workflow changes automatically.
- uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0
+ uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1Or, if pinning is now the desired strategy, remove/update the stale "Float on @v1" comment accordingly.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| # Float on @v1 (this is a normal, non-required workflow) so we pick up the | |
| # lightweight-tag peel fix and future release-workflow changes automatically. | |
| uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1 | |
| uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0 | |
| uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1 |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/release-auto-on-tag.yml around lines 12 - 14, The reusable
workflow reference in the release-auto-on-tag workflow is now pinned to a
specific version while the nearby comment still says it should float on `@v1`.
Update the workflow and the comment together in release-auto-on-tag so they
match: either restore the uses reference to `@v1`, or revise/remove the “Float on
`@v1`” note if pinning to v1.19.0 is the intended policy.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the github-actions group with 9 updates:
1.16.01.19.011.19.06.2.06.3.06.2.06.2.111.19.011.19.011.19.01.16.01.19.011.19.0Updates
geolonia/.github/.github/workflows/reusable-backstage-techdocs.ymlfrom 1.16.0 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml's releases.
Commits
c98b846feat: add Security Suite workflow (one-stop, ruleset-enforceable) (#71)1dd4e2dfeat: add summary report-mode + outputs to scanner reusables (#72)007ca57docs(ci): document why cdk-deploy-monitor needs each permission (#70)676d763ci(release): least-privilege caller in release-on-tag source (#69)419bfe9ci(techdocs): make publish-techdocs template standalone by default (#68)eb33e7fchore(deps): bump bumblebee default to v0.1.2 (#67)d3a81cachore(deps): bump the github-actions group across 1 directory with 3 updates ...5142150chore(betterleaks): bump pinned image to v1.5.0 (#65)feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)Updates
geolonia/.github/.github/workflows/reusable-release-auto-on-tag.ymlfrom 1 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml's releases.
... (truncated)
Commits
feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)f9bead4ci: SHA-pin all workflow templates + verify them in pinact (#60)a0dda21Add workflow to route issues to team board (#58)92c8c6dfeat: route-issue reusable workflow + template (public dispatch leg) (#57)649b590docs: split Reusable Workflow Templates into per-workflow pages (#55)9e5b10edocs: team best-practice guide for pinning GitHub Actions (#146) (#53)f217e1eci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)008b07edocs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)c13a68cfix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)Updates
actions/setup-pythonfrom 6.2.0 to 6.3.0Release notes
Sourced from actions/setup-python's releases.
Commits
ece7cb0Fix pip cache error handling on Windows. (#1040)1d18d7aUpdate advanced-usage.md (#811)d2b357aUpdate dependency versions and test workflow configuration (#1322)8f639b1Merge pull request #1324 from jasongin/update-actions-cache-5.1.06731c2bResolve high-severity audit issues0cb1a84Add RHEL support and include Linux distro in cache keys (#1323)dc6eab6Update dist6f4b74bStrict equalityfa8bde1Bump@actions/cacheto 5.1.0, log cache write deniedc8813baUpgrade@actionsdependencies and update licenses (#1303)Updates
aws-actions/configure-aws-credentialsfrom 6.2.0 to 6.2.1Release notes
Sourced from aws-actions/configure-aws-credentials's releases.
Changelog
Sourced from aws-actions/configure-aws-credentials's changelog.
... (truncated)
Commits
254c19bchore(main): release 6.2.1 (#1849)a20cf82chore: Update dist4d281fbfix: enforce allowed-account-ids on all auth paths (#1847)e004cdcchore(deps-dev): bump@smithy/property-providerfrom 4.4.0 to 4.4.2 (#1845)88aa369chore: Update dist687331bchore(deps): bump@aws-sdk/client-stsfrom 3.1069.0 to 3.1075.0 (#1841)ea607bechore: Update dist6d13606chore(deps): bump@smithy/node-http-handlerfrom 4.8.0 to 4.8.2 (#1842)71a32aechore: Update distb290f2cchore(deps-dev): bump@aws-sdk/credential-provider-env(#1844)Updates
geolonia/.github/.github/workflows/reusable-bumblebee-scan.ymlfrom 1 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml's releases.
... (truncated)
Commits
feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)f9bead4ci: SHA-pin all workflow templates + verify them in pinact (#60)a0dda21Add workflow to route issues to team board (#58)92c8c6dfeat: route-issue reusable workflow + template (public dispatch leg) (#57)649b590docs: split Reusable Workflow Templates into per-workflow pages (#55)9e5b10edocs: team best-practice guide for pinning GitHub Actions (#146) (#53)f217e1eci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)008b07edocs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)c13a68cfix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)Updates
geolonia/.github/.github/workflows/reusable-secret-leak-check.ymlfrom 1 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-secret-leak-check.yml's releases.
... (truncated)
Commits
feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)f9bead4ci: SHA-pin all workflow templates + verify them in pinact (#60)a0dda21Add workflow to route issues to team board (#58)92c8c6dfeat: route-issue reusable workflow + template (public dispatch leg) (#57)649b590docs: split Reusable Workflow Templates into per-workflow pages (#55)9e5b10edocs: team best-practice guide for pinning GitHub Actions (#146) (#53)f217e1eci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)008b07edocs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)c13a68cfix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)Updates
geolonia/.github/.github/workflows/reusable-pinact-check.ymlfrom 1 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-pinact-check.yml's releases.
... (truncated)
Commits
feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)f9bead4ci: SHA-pin all workflow templates + verify them in pinact (#60)a0dda21Add workflow to route issues to team board (#58)92c8c6dfeat: route-issue reusable workflow + template (public dispatch leg) (#57)649b590docs: split Reusable Workflow Templates into per-workflow pages (#55)9e5b10edocs: team best-practice guide for pinning GitHub Actions (#146) (#53)f217e1eci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)008b07edocs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)c13a68cfix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)Updates
geolonia/.github/.github/workflows/reusable-route-issue.ymlfrom 1.16.0 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-route-issue.yml's releases.
Commits
c98b846feat: add Security Suite workflow (one-stop, ruleset-enforceable) (#71)1dd4e2dfeat: add summary report-mode + outputs to scanner reusables (#72)007ca57docs(ci): document why cdk-deploy-monitor needs each permission (#70)676d763ci(release): least-privilege caller in release-on-tag source (#69)419bfe9ci(techdocs): make publish-techdocs template standalone by default (#68)eb33e7fchore(deps): bump bumblebee default to v0.1.2 (#67)d3a81cachore(deps): bump the github-actions group across 1 directory with 3 updates ...5142150chore(betterleaks): bump pinned image to v1.5.0 (#65)feda067chore(pinact): bump example CLI install hint to v4.1.0 (#64)0847099docs(route-issue): simplify page, picker description + template comments (#61)Updates
geolonia/.github/.github/workflows/reusable-security-suite.ymlfrom 1 to 1.19.0Release notes
Sourced from geolonia/.github/.github/workflows/reusable-security-suite.yml's releases.