Skip to content

chore(deps): bump the github-actions group across 1 directory with 5 updates - #109

Merged
dkastl merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-c7d574adf6
Aug 3, 2026
Merged

chore(deps): bump the github-actions group across 1 directory with 5 updates#109
dkastl merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-c7d574adf6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 5 updates in the / directory:

Package From To
geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml 1.34.0 1.36.0
actions/checkout 7.0.0 7.0.1
aws-actions/configure-aws-credentials 6.2.2 6.2.3
zizmorcore/zizmor-action 0.5.7 0.6.1
geolonia/.github/.github/workflows/reusable-route-issue.yml 1.34.0 1.36.0

Updates geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml from 1.34.0 to 1.36.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml's releases.

v1.36.0

What's Changed

New Contributors

Full Changelog: v1.35.0...v1.36.0

v1.35.0

What's Changed

Full Changelog: v1...v1.35.0

Commits
  • 82fb51b refactor(secret-leak): delete duplicate betterleaks/default.toml; dependabot ...
  • b6b8240 feat(security-suite): single source of truth for scanner configs (phase 1: be...
  • 06c2d7f chore: sync workflow-template reusable pins to v1.35.0 (#101)
  • d8154ae ci: scheduled Sync workflow-template pins job (#100)
  • 236b83c chore(betterleaks): bump v1.5.0 -> v1.6.1 (#99)
  • 7ae6278 chore(deps): bump the github-actions group across 1 directory with 4 updates ...
  • abd473b harden sync-team-access workflow template (explicit perms + secrets) (#98)
  • See full diff in compare view

Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3

Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.2.3

6.2.3 (2026-07-22)

Bug Fixes

  • attach git credentials before Tag Major Version push (#1877) (9ae780b)
  • PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)
Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.2.3 (2026-07-22)

Bug Fixes

  • attach git credentials before Tag Major Version push (#1877) (9ae780b)
  • PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)

6.2.2 (2026-07-07)

Miscellaneous Chores

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)

6.2.0 (2026-06-01)

Features

Bug Fixes

  • skip credential check on output-env-credentials: false (#1778) (58e7c47)
  • assumeRole failing from session tag size too large (#1808) (d6f5dc3)

6.1.3 (2026-05-28)

Bug Fixes

  • fix: allow kubelet token symlink in #1805

6.1.2 (2026-05-26)

... (truncated)

Commits
  • e6de054 chore(main): release 6.2.3 (#1878)
  • ab3b2ba chore: Update dist
  • fa8d6a5 fix: PackedPolicyTooLarge detection in STS tags (#1899)
  • 42e118a chore(deps-dev): bump markdownlint-cli from 0.49.0 to 0.49.1 (#1896)
  • d86ddfc chore: Update dist
  • 874aaac chore(deps): bump @​aws-sdk/client-sts from 3.1086.0 to 3.1091.0 (#1892)
  • d4341b6 chore: Update dist
  • fe51823 chore(deps-dev): bump @​aws-sdk/credential-provider-env (#1894)
  • a8be382 chore(deps-dev): bump @​biomejs/biome from 2.5.3 to 2.5.4 (#1893)
  • e000376 chore: Update dist
  • Additional commits viewable in compare view

Updates zizmorcore/zizmor-action from 0.5.7 to 0.6.1

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.1

zizmor 1.28.0 is now the default version used by the action.

v0.6.0

zizmor 1.27.0 is now the default version used by the action.

What's Changed

New Contributors

Full Changelog: zizmorcore/zizmor-action@v0.5.7...v0.6.0

Commits

Updates geolonia/.github/.github/workflows/reusable-route-issue.yml from 1.34.0 to 1.36.0

Release notes

Sourced from geolonia/.github/.github/workflows/reusable-route-issue.yml's releases.

v1.36.0

What's Changed

New Contributors

Full Changelog: v1.35.0...v1.36.0

v1.35.0

What's Changed

Full Changelog: v1...v1.35.0

Commits
  • 82fb51b refactor(secret-leak): delete duplicate betterleaks/default.toml; dependabot ...
  • b6b8240 feat(security-suite): single source of truth for scanner configs (phase 1: be...
  • 06c2d7f chore: sync workflow-template reusable pins to v1.35.0 (#101)
  • d8154ae ci: scheduled Sync workflow-template pins job (#100)
  • 236b83c chore(betterleaks): bump v1.5.0 -> v1.6.1 (#99)
  • 7ae6278 chore(deps): bump the github-actions group across 1 directory with 4 updates ...
  • abd473b harden sync-team-access workflow template (explicit perms + secrets) (#98)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated automated workflow components to newer pinned releases.
    • Improved the reliability and security of documentation, deployment, scanning, release, and access-management workflows.
    • Refreshed reusable workflow references across issue routing and TechDocs automation.

…updates

Bumps the github-actions group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml](https://github.com/geolonia/.github) | `1.34.0` | `1.36.0` |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` |
| [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.2` | `6.2.3` |
| [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.7` | `0.6.1` |
| [geolonia/.github/.github/workflows/reusable-route-issue.yml](https://github.com/geolonia/.github) | `1.34.0` | `1.36.0` |



Updates `geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml` from 1.34.0 to 1.36.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](6793909...82fb51b)

Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9c091bb...3d3c42e)

Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](aws-actions/configure-aws-credentials@517a711...e6de054)

Updates `zizmorcore/zizmor-action` from 0.5.7 to 0.6.1
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@192e21d...6fc4b00)

Updates `geolonia/.github/.github/workflows/reusable-route-issue.yml` from 1.34.0 to 1.36.0
- [Release notes](https://github.com/geolonia/.github/releases)
- [Commits](6793909...82fb51b)

---
updated-dependencies:
- dependency-name: geolonia/.github/.github/workflows/reusable-backstage-techdocs.yml
  dependency-version: 1.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: geolonia/.github/.github/workflows/reusable-route-issue.yml
  dependency-version: 1.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The pull request updates pinned reusable workflow references and GitHub Actions across repository workflows. TechDocs and issue-routing references move to v1.36.0. Checkout, AWS credentials, and zizmor pins move to newer versions.

Changes

Workflow dependency pin updates

Layer / File(s) Summary
Reusable workflow references
.github/workflows/publish-techdocs.yml, .github/workflows/route-issue.yml
TechDocs and issue-routing workflows now reference reusable workflow version v1.36.0.
GitHub Action pins
.github/workflows/reusable-*.yml, .github/workflows/sync-workflow-template-pins.yml
Checkout, AWS credentials, and zizmor action pins were updated to the specified newer commits.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

Suggested reviewers: dkastl

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the grouped GitHub Actions dependency updates.
Description check ✅ Passed The description clearly summarizes all five dependency updates and includes relevant release details, but omits optional checklist and issue sections.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/github-actions-c7d574adf6

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🛡️ Security suite

Check Result
✅ Supply chain · bumblebee No exposure matches
✅ Secrets · betterleaks No secrets in diff
✅ Action pinning · pinact All actions pinned
✅ Actions audit · zizmor No findings

Note

All security checks passed.

Updated for a2c7e93 · workflow run

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/reusable-security-suite.yml (1)

128-149: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Update the stale zizmor version comment. zizmor-action@v0.6.1 supports the explicit 1.26.1 pin, so replace v0.5.7 with v0.6.1. No CLI pin change is needed.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/reusable-security-suite.yml around lines 128 - 149, Update
the version reference in the comment above the zizmor action’s version input
from v0.5.7 to v0.6.1. Keep the explicit CLI pin at 1.26.1 unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/reusable-security-suite.yml:
- Around line 128-149: Update the version reference in the comment above the
zizmor action’s version input from v0.5.7 to v0.6.1. Keep the explicit CLI pin
at 1.26.1 unchanged.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: fca5169d-de6f-4f4f-b359-a0dcbd35a5f3

📥 Commits

Reviewing files that changed from the base of the PR and between 32191d4 and a2c7e93.

📒 Files selected for processing (11)
  • .github/workflows/publish-techdocs.yml
  • .github/workflows/reusable-backstage-techdocs.yml
  • .github/workflows/reusable-bumblebee-scan.yml
  • .github/workflows/reusable-cdk-deploy-monitor.yml
  • .github/workflows/reusable-pinact-check.yml
  • .github/workflows/reusable-release-auto-on-tag.yml
  • .github/workflows/reusable-secret-leak-check.yml
  • .github/workflows/reusable-security-suite.yml
  • .github/workflows/reusable-sync-team-access.yml
  • .github/workflows/route-issue.yml
  • .github/workflows/sync-workflow-template-pins.yml

@dkastl
dkastl merged commit 5d463bd into main Aug 3, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-c7d574adf6 branch August 3, 2026 03:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant