Skip to content

chore(deps): bump the github-actions group with 9 updates#96

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-906d6fbbf1
Closed

chore(deps): bump the github-actions group with 9 updates#96
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-906d6fbbf1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 9 updates:

Package From To
geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml 1.16.0 1.19.0
geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml 1 1.19.0
actions/setup-python 6.2.0 6.3.0
aws-actions/configure-aws-credentials 6.2.0 6.2.1
geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml 1 1.19.0
geolonia/.github/.github/workflows/reusable-secret-leak-check.yml 1 1.19.0
geolonia/.github/.github/workflows/reusable-pinact-check.yml 1 1.19.0
geolonia/.github/.github/workflows/reusable-route-issue.yml 1.16.0 1.19.0
geolonia/.github/.github/workflows/reusable-security-suite.yml 1 1.19.0

Updates geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml from 1.16.0 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

Commits
  • c98b846 feat: add Security Suite workflow (one-stop, ruleset-enforceable) (#71)
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml from 1 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

v1.16.0

What's Changed

Full Changelog: v1...v1.16.0

v1.15.1

... (truncated)

Commits
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • f9bead4 ci: SHA-pin all workflow templates + verify them in pinact (#60)
  • a0dda21 Add workflow to route issues to team board (#58)
  • 92c8c6d feat: route-issue reusable workflow + template (public dispatch leg) (#57)
  • 649b590 docs: split Reusable Workflow Templates into per-workflow pages (#55)
  • 9e5b10e docs: team best-practice guide for pinning GitHub Actions (#146) (#53)
  • f217e1e ci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)
  • 008b07e docs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)
  • c13a68c fix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)
  • Additional commits viewable in compare view

Updates actions/setup-python from 6.2.0 to 6.3.0

Release notes

Sourced from actions/setup-python's releases.

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6...v6.3.0

Commits

Updates aws-actions/configure-aws-credentials from 6.2.0 to 6.2.1

Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.2.1

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)
Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)

6.2.0 (2026-06-01)

Features

Bug Fixes

  • skip credential check on output-env-credentials: false (#1778) (58e7c47)
  • assumeRole failing from session tag size too large (#1808) (d6f5dc3)

6.1.3 (2026-05-28)

Bug Fixes

  • fix: allow kubelet token symlink in #1805

6.1.2 (2026-05-26)

Bug Fixes

6.1.1 (2026-05-05)

Miscellaneous Chores

  • various dependency updates

6.1.0 (2026-04-06)

Features

... (truncated)

Commits
  • 254c19b chore(main): release 6.2.1 (#1849)
  • a20cf82 chore: Update dist
  • 4d281fb fix: enforce allowed-account-ids on all auth paths (#1847)
  • e004cdc chore(deps-dev): bump @​smithy/property-provider from 4.4.0 to 4.4.2 (#1845)
  • 88aa369 chore: Update dist
  • 687331b chore(deps): bump @​aws-sdk/client-sts from 3.1069.0 to 3.1075.0 (#1841)
  • ea607be chore: Update dist
  • 6d13606 chore(deps): bump @​smithy/node-http-handler from 4.8.0 to 4.8.2 (#1842)
  • 71a32ae chore: Update dist
  • b290f2c chore(deps-dev): bump @​aws-sdk/credential-provider-env (#1844)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml from 1 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

v1.16.0

What's Changed

Full Changelog: v1...v1.16.0

v1.15.1

... (truncated)

Commits
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • f9bead4 ci: SHA-pin all workflow templates + verify them in pinact (#60)
  • a0dda21 Add workflow to route issues to team board (#58)
  • 92c8c6d feat: route-issue reusable workflow + template (public dispatch leg) (#57)
  • 649b590 docs: split Reusable Workflow Templates into per-workflow pages (#55)
  • 9e5b10e docs: team best-practice guide for pinning GitHub Actions (#146) (#53)
  • f217e1e ci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)
  • 008b07e docs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)
  • c13a68c fix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-secret-leak-check.yml from 1 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-secret-leak-check.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

v1.16.0

What's Changed

Full Changelog: v1...v1.16.0

v1.15.1

... (truncated)

Commits
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • f9bead4 ci: SHA-pin all workflow templates + verify them in pinact (#60)
  • a0dda21 Add workflow to route issues to team board (#58)
  • 92c8c6d feat: route-issue reusable workflow + template (public dispatch leg) (#57)
  • 649b590 docs: split Reusable Workflow Templates into per-workflow pages (#55)
  • 9e5b10e docs: team best-practice guide for pinning GitHub Actions (#146) (#53)
  • f217e1e ci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)
  • 008b07e docs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)
  • c13a68c fix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-pinact-check.yml from 1 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-pinact-check.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

v1.16.0

What's Changed

Full Changelog: v1...v1.16.0

v1.15.1

... (truncated)

Commits
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • f9bead4 ci: SHA-pin all workflow templates + verify them in pinact (#60)
  • a0dda21 Add workflow to route issues to team board (#58)
  • 92c8c6d feat: route-issue reusable workflow + template (public dispatch leg) (#57)
  • 649b590 docs: split Reusable Workflow Templates into per-workflow pages (#55)
  • 9e5b10e docs: team best-practice guide for pinning GitHub Actions (#146) (#53)
  • f217e1e ci: SHA-pin GitHub Actions + pinact gate, Dependabot, .pinact.yml (#51)
  • 008b07e docs(pinact): standard Dependabot cooldown is 8 days (one over min_age 7) (#50)
  • c13a68c fix(pinact): canonical .pinact.yml needs version 3 + geolonia exemption (#49)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-route-issue.yml from 1.16.0 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-route-issue.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

Full Changelog: v1...v1.17.1

v1.17.0

What's Changed

New Contributors

Full Changelog: v1...v1.17.0

Commits
  • c98b846 feat: add Security Suite workflow (one-stop, ruleset-enforceable) (#71)
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • feda067 chore(pinact): bump example CLI install hint to v4.1.0 (#64)
  • 0847099 docs(route-issue): simplify page, picker description + template comments (#61)
  • Additional commits viewable in compare view

Updates geolonia/.github/.github/workflows/reusable-security-suite.yml from 1 to 1.19.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-security-suite.yml's releases.

v1.19.0

What's Changed

Full Changelog: v1...v1.19.0

v1.18.0

What's Changed

Full Changelog: v1...v1.18.0

v1.17.1

What's Changed

  • chore(deps): bump bu...

    Description has been truncated

    Summary by CodeRabbit

    • Chores
      • Updated several GitHub Actions workflows to use newer pinned versions of shared automation.
      • Improved consistency by replacing floating references with fixed versions in release, security, routing, TechDocs, and deployment-related workflows.
      • Bumped a couple of workflow dependencies to newer patch releases for better reliability.

Bumps the github-actions group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml](https://github.com/geolonia/.github) | `1.16.0` | `1.19.0` |
| [geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` |
| [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` |
| [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.0` | `6.2.1` |
| [geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` |
| [geolonia/.github/.github/workflows/reusable-secret-leak-check.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` |
| [geolonia/.github/.github/workflows/reusable-pinact-check.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` |
| [geolonia/.github/.github/workflows/reusable-route-issue.yml](https://github.com/geolonia/.github) | `1.16.0` | `1.19.0` |
| [geolonia/.github/.github/workflows/reusable-security-suite.yml](https://github.com/geolonia/.github) | `1` | `1.19.0` |


Updates `geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml` from 1.16.0 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](92c8c6d...c98b846)

Updates `geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml` from 1 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.19.0)

Updates `actions/setup-python` from 6.2.0 to 6.3.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a309ff8...ece7cb0)

Updates `aws-actions/configure-aws-credentials` from 6.2.0 to 6.2.1
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](aws-actions/configure-aws-credentials@e7f100c...254c19b)

Updates `geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml` from 1 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.19.0)

Updates `geolonia/.github/.github/workflows/reusable-secret-leak-check.yml` from 1 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.19.0)

Updates `geolonia/.github/.github/workflows/reusable-pinact-check.yml` from 1 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.19.0)

Updates `geolonia/.github/.github/workflows/reusable-route-issue.yml` from 1.16.0 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](92c8c6d...c98b846)

Updates `geolonia/.github/.github/workflows/reusable-security-suite.yml` from 1 to 1.19.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.19.0)

---
updated-dependencies:
- dependency-name: geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-secret-leak-check.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-pinact-check.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-route-issue.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-security-suite.yml
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 6, 2026
@coderabbitai

coderabbitai Bot commented Jul 6, 2026

Copy link
Copy Markdown

Review Change Stack

Walkthrough

This PR updates pinned versions across GitHub Actions workflow files: reusable workflow references (publish-techdocs, release-auto-on-tag, route-issue, security-suite, reusable-security-suite) are bumped to v1.19.0, and third-party actions (actions/setup-python, aws-actions/configure-aws-credentials) are updated to newer pinned commits in techdocs and cdk-deploy-monitor workflows.

Changes

Workflow version bumps

Layer / File(s) Summary
Reusable workflow version pins to v1.19.0
.github/workflows/publish-techdocs.yml, .github/workflows/release-auto-on-tag.yml, .github/workflows/route-issue.yml, .github/workflows/security-suite.yml, .github/workflows/reusable-security-suite.yml
Updates uses: references from older pinned versions (v1.16.0) or floating tags (@v1) to pinned @v1.19.0 for reusable workflows and scanner jobs (supply-chain, secret-leak, action-pinning).
Third-party action version bumps
.github/workflows/reusable-backstage-techdocs.yml, .github/workflows/reusable-cdk-deploy-monitor.yml
Bumps actions/setup-python from v6.2.0 to v6.3.0, and aws-actions/configure-aws-credentials from v6.2.0 to v6.2.1 in both workflows.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

  • geolonia/.github#79: Both PRs bump the jobs.suite.uses reference to reusable-security-suite.yml in .github/workflows/security-suite.yml to a newer pinned version.
  • geolonia/.github#84: Both PRs update the same caller workflow's pinned version for reusable-security-suite.yml.
  • geolonia/.github#86: Both PRs modify the uses: references for bumblebee, secret-leak, and pinact jobs in reusable-security-suite.yml and its caller, though in opposite pinning directions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed It clearly summarizes the main change: bumping the github-actions group with nine updates.
Description check ✅ Passed It covers the update summary and affected packages, though it doesn't use the repository's exact section headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/github-actions-906d6fbbf1

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/security-suite.yml (1)

43-52: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Comment documents intentional floating on major tag; code now pins @v1.19.0.

The comment explains at length why this ref should float ("a floating reusable ref here is FINE", org pinact/zizmor exemptions for geolonia/* reusables at a major tag) so the suite auto-upgrades without a chain-bump PR. The Dependabot bump instead pinned to @v1.19.0, contradicting the documented policy and losing the "no chain-bump" auto-upgrade behavior this comment relies on.

🔧 Options
-    uses: geolonia/.github/.github/workflows/reusable-security-suite.yml@v1.19.0
+    uses: geolonia/.github/.github/workflows/reusable-security-suite.yml@v1

Or update the comment if pinning is now intended going forward.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/security-suite.yml around lines 43 - 52, The reusable
workflow reference in security-suite.yml is pinned to a release tag, but the
comment and policy in the workflow say this should stay floating on the major
tag for automatic upgrades. Update the `uses` reference in
`reusable-security-suite.yml` invocation back to `@v1` so the required workflow
continues to float without chain-bump PRs, or if pinning is now intended, revise
the surrounding comment to match the new policy.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release-auto-on-tag.yml:
- Around line 12-14: The reusable workflow reference in the release-auto-on-tag
workflow is now pinned to a specific version while the nearby comment still says
it should float on `@v1`. Update the workflow and the comment together in
release-auto-on-tag so they match: either restore the uses reference to `@v1`, or
revise/remove the “Float on `@v1`” note if pinning to v1.19.0 is the intended
policy.

---

Outside diff comments:
In @.github/workflows/security-suite.yml:
- Around line 43-52: The reusable workflow reference in security-suite.yml is
pinned to a release tag, but the comment and policy in the workflow say this
should stay floating on the major tag for automatic upgrades. Update the `uses`
reference in `reusable-security-suite.yml` invocation back to `@v1` so the
required workflow continues to float without chain-bump PRs, or if pinning is
now intended, revise the surrounding comment to match the new policy.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 18d95b97-4717-4434-9465-55c570b82a15

📥 Commits

Reviewing files that changed from the base of the PR and between 6793909 and db0d318.

📒 Files selected for processing (7)
  • .github/workflows/publish-techdocs.yml
  • .github/workflows/release-auto-on-tag.yml
  • .github/workflows/reusable-backstage-techdocs.yml
  • .github/workflows/reusable-cdk-deploy-monitor.yml
  • .github/workflows/reusable-security-suite.yml
  • .github/workflows/route-issue.yml
  • .github/workflows/security-suite.yml

Comment on lines 12 to +14
# Float on @v1 (this is a normal, non-required workflow) so we pick up the
# lightweight-tag peel fix and future release-workflow changes automatically.
uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1
uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Comment says "Float on @v1" but code now pins @v1.19.0.

The comment explains the intentional choice to float so the workflow auto-picks-up future fixes, but the Dependabot bump pinned it to a specific version, contradicting that documented rationale. Either restore floating on @v1 or update the comment to reflect the new pinning approach.

🔧 Options
-    # Float on `@v1` (this is a normal, non-required workflow) so we pick up the
-    # lightweight-tag peel fix and future release-workflow changes automatically.
-    uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0
+    uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1

Or, if pinning is now the desired strategy, remove/update the stale "Float on @v1" comment accordingly.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
# Float on @v1 (this is a normal, non-required workflow) so we pick up the
# lightweight-tag peel fix and future release-workflow changes automatically.
uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1
uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1.19.0
uses: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml@v1
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-auto-on-tag.yml around lines 12 - 14, The reusable
workflow reference in the release-auto-on-tag workflow is now pinned to a
specific version while the nearby comment still says it should float on `@v1`.
Update the workflow and the comment together in release-auto-on-tag so they
match: either restore the uses reference to `@v1`, or revise/remove the “Float on
`@v1`” note if pinning to v1.19.0 is the intended policy.

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 20, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-906d6fbbf1 branch July 20, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants