Skip to content

chore(deps): bump the github-actions group with 7 updates - #105

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-a17d250ef9
Closed

chore(deps): bump the github-actions group with 7 updates#105
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-a17d250ef9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 7 updates:

Package From To
geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml 1 1.34.0
actions/checkout 7.0.0 7.0.1
geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml 1 1.34.0
geolonia/.github/.github/workflows/reusable-secret-leak-check.yml 1 1.34.0
geolonia/.github/.github/workflows/reusable-pinact-check.yml 1 1.34.0
zizmorcore/zizmor-action 0.5.7 0.6.0
geolonia/.github/.github/workflows/reusable-security-suite.yml 1 1.34.0

Updates geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml from 1 to 1.34.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml's releases.

v1.34.0

What's Changed

Full Changelog: v1...v1.34.0

v1.33.0

What's Changed

Full Changelog: v1...v1.33.0

v1.32.0

What's Changed

Full Changelog: v1.31...v1.32.0

v1.31.0

What's Changed

Full Changelog: v1...v1.31.0

v1.30.0

What's Changed

Full Changelog: v1...v1.30.0

v1.29.0

What's Changed

Full Changelog: v1...v1.29.0

v1.28.0

What's Changed

Full Changelog: v1...v1.28.0

v1.27.0

... (truncated)

Commits
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • See full diff in compare view

Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml from 1 to 1.34.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml's releases.

v1.34.0

What's Changed

Full Changelog: v1...v1.34.0

v1.33.0

What's Changed

Full Changelog: v1...v1.33.0

v1.32.0

What's Changed

Full Changelog: v1.31...v1.32.0

v1.31.0

What's Changed

Full Changelog: v1...v1.31.0

v1.30.0

What's Changed

Full Changelog: v1...v1.30.0

v1.29.0

What's Changed

Full Changelog: v1...v1.29.0

v1.28.0

What's Changed

Full Changelog: v1...v1.28.0

v1.27.0

... (truncated)

Commits
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • See full diff in compare view

Updates geolonia/.github/.github/workflows/reusable-secret-leak-check.yml from 1 to 1.34.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-secret-leak-check.yml's releases.

v1.34.0

What's Changed

Full Changelog: v1...v1.34.0

v1.33.0

What's Changed

Full Changelog: v1...v1.33.0

v1.32.0

What's Changed

Full Changelog: v1.31...v1.32.0

v1.31.0

What's Changed

Full Changelog: v1...v1.31.0

v1.30.0

What's Changed

Full Changelog: v1...v1.30.0

v1.29.0

What's Changed

Full Changelog: v1...v1.29.0

v1.28.0

What's Changed

Full Changelog: v1...v1.28.0

v1.27.0

... (truncated)

Commits
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • See full diff in compare view

Updates geolonia/.github/.github/workflows/reusable-pinact-check.yml from 1 to 1.34.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-pinact-check.yml's releases.

v1.34.0

What's Changed

Full Changelog: v1...v1.34.0

v1.33.0

What's Changed

Full Changelog: v1...v1.33.0

v1.32.0

What's Changed

Full Changelog: v1.31...v1.32.0

v1.31.0

What's Changed

Full Changelog: v1...v1.31.0

v1.30.0

What's Changed

Full Changelog: v1...v1.30.0

v1.29.0

What's Changed

Full Changelog: v1...v1.29.0

v1.28.0

What's Changed

Full Changelog: v1...v1.28.0

v1.27.0

... (truncated)

Commits
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • See full diff in compare view

Updates zizmorcore/zizmor-action from 0.5.7 to 0.6.0

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.0

zizmor 1.27.0 is now the default version used by the action.

What's Changed

New Contributors

Full Changelog: zizmorcore/zizmor-action@v0.5.7...v0.6.0

Commits

Updates geolonia/.github/.github/workflows/reusable-security-suite.yml from 1 to 1.34.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-security-suite.yml's releases.

v1.34.0

What's Changed

Full Changelog: v1...v1.34.0

v1.33.0

What's Changed

Full Changelog: v1...v1.33.0

v1.32.0

What's Changed

Full Changelog: v1.31...v1.32.0

v1.31.0

What's Changed

Full Changelog: v1...v1.31.0

v1.30.0

What's Changed

Full Changelog: v1...v1.30.0

v1.29.0

What's Changed

Full Changelog: v1...v1.29.0

v1.28.0

What's Changed

Full Changelog: v1...v1.28.0

v1.27.0

... (truncated)

Commits
  • 1dd4e2d feat: add summary report-mode + outputs to scanner reusables (#72)
  • 007ca57 docs(ci): document why cdk-deploy-monitor needs each permission (#70)
  • 676d763 ci(release): least-privilege caller in release-on-tag source (#69)
  • 419bfe9 ci(techdocs): make publish-techdocs template standalone by default (#68)
  • eb33e7f chore(deps): bump bumblebee default to v0.1.2 (#67)
  • d3a81ca chore(deps): bump the github-actions group across 1 directory with 3 updates ...
  • 5142150 chore(betterleaks): bump pinned image to v1.5.0 (#65)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml](https://github.com/geolonia/.github) | `1` | `1.34.0` |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` |
| [geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml](https://github.com/geolonia/.github) | `1` | `1.34.0` |
| [geolonia/.github/.github/workflows/reusable-secret-leak-check.yml](https://github.com/geolonia/.github) | `1` | `1.34.0` |
| [geolonia/.github/.github/workflows/reusable-pinact-check.yml](https://github.com/geolonia/.github) | `1` | `1.34.0` |
| [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.7` | `0.6.0` |
| [geolonia/.github/.github/workflows/reusable-security-suite.yml](https://github.com/geolonia/.github) | `1` | `1.34.0` |


Updates `geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml` from 1 to 1.34.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.34.0)

Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml` from 1 to 1.34.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.34.0)

Updates `geolonia/.github/.github/workflows/reusable-secret-leak-check.yml` from 1 to 1.34.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.34.0)

Updates `geolonia/.github/.github/workflows/reusable-pinact-check.yml` from 1 to 1.34.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.34.0)

Updates `zizmorcore/zizmor-action` from 0.5.7 to 0.6.0
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@192e21d...6599ee8)

Updates `geolonia/.github/.github/workflows/reusable-security-suite.yml` from 1 to 1.34.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](v1...v1.34.0)

---
updated-dependencies:
- dependency-name: geolonia/.github/.github/workflows/reusable-release-auto-on-tag.yml
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-bumblebee-scan.yml
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-secret-leak-check.yml
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-pinact-check.yml
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-security-suite.yml
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 27, 2026
@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 27a4cf5f-3544-49e2-9a32-e617063e3ac7

📥 Commits

Reviewing files that changed from the base of the PR and between 82fb51b and d064e82.

📒 Files selected for processing (10)
  • .github/workflows/release-auto-on-tag.yml
  • .github/workflows/reusable-backstage-techdocs.yml
  • .github/workflows/reusable-bumblebee-scan.yml
  • .github/workflows/reusable-pinact-check.yml
  • .github/workflows/reusable-release-auto-on-tag.yml
  • .github/workflows/reusable-secret-leak-check.yml
  • .github/workflows/reusable-security-suite.yml
  • .github/workflows/reusable-sync-team-access.yml
  • .github/workflows/security-suite.yml
  • .github/workflows/sync-workflow-template-pins.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/github-actions-a17d250ef9

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

🛡️ Security suite

Check Result
✅ Supply chain · bumblebee No exposure matches
✅ Secrets · betterleaks No secrets in diff
⚠️ Action pinning · pinact Unpinned or mismatched (warn-only; see run)
✅ Actions audit · zizmor No findings

Warning

Warnings only. These do not block the PR, but please review them.

Updated for d064e82 · workflow run

@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 3, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-a17d250ef9 branch August 3, 2026 03:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants