diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..da58a776f --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,29 @@ +# The workflows pin actions to a moving major tag, which only advances +# when someone goes looking. Dependabot opens the pull request instead, +# so a new major is a decision to take rather than a discovery to make. + +version: 2 + +updates: + - package-ecosystem: "github-actions" + # For Actions this is the documented value rather than a literal + # path: Dependabot searches `.github/workflows` and a root + # `action.yml`. + directory: "/" + schedule: + interval: "monthly" + commit-message: + # Dependabot appends the colon, giving `CI: bump ...`, which is + # the subject convention for infrastructure changes here. + prefix: "CI" + groups: + # Minor and patch updates need no migration, so they travel + # together. Major updates deliberately match no group: each one + # gets its own pull request, and can be reviewed, held back or + # reverted without disturbing the others. + actions-minor-and-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch" diff --git a/.github/workflows/code-projects-type-check.yml b/.github/workflows/code-projects-type-check.yml index b9ad71d21..515b98a85 100644 --- a/.github/workflows/code-projects-type-check.yml +++ b/.github/workflows/code-projects-type-check.yml @@ -20,9 +20,9 @@ jobs: python-version: ['3.14'] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - name: Install pyright diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b06f6996a..4f1c18566 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -28,11 +28,11 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -43,7 +43,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 # â„šī¸ Command-line programs to run using the OS shell. # 📚 https://git.io/JvXDl @@ -57,4 +57,4 @@ jobs: # make release - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 diff --git a/.github/workflows/eslint.js.yml b/.github/workflows/eslint.js.yml index 417044d17..4ed59644a 100644 --- a/.github/workflows/eslint.js.yml +++ b/.github/workflows/eslint.js.yml @@ -22,11 +22,11 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' diff --git a/.github/workflows/publish-learn-latest.yml b/.github/workflows/publish-learn-latest.yml index 893b871a0..1ac8b2e7b 100644 --- a/.github/workflows/publish-learn-latest.yml +++ b/.github/workflows/publish-learn-latest.yml @@ -28,7 +28,7 @@ jobs: echo "content_run_id=$content_run_id" >> $GITHUB_OUTPUT - name: Download HTML artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-html path: unzipped_html @@ -36,7 +36,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Download PDF books artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-pdf-books path: unzipped_pdf_books @@ -44,7 +44,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Download EPUB books artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-epub-books path: unzipped_epub_books @@ -52,7 +52,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Checkout learn-latest-html-pages - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: AdaCore/learn-latest-html-pages ref: gh-pages diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index a6839388b..8c443efb7 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -17,16 +17,16 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' @@ -71,7 +71,7 @@ jobs: - name: Build PDF books including build/runtime output run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" pdf_books - name: Archive PDF books in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-pdf-books path: | @@ -82,7 +82,7 @@ jobs: - name: Build EPUB books including build/runtime output run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" epub_books - name: Archive EPUB books in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-epub-books path: | diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index b39f64d6d..840ace68a 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -17,16 +17,16 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' @@ -57,7 +57,7 @@ jobs: - name: Build HTML content run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" cleanall webpack-production sphinx-production - name: Archive HTML content in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-html path: | diff --git a/.github/workflows/sphinx-plugin-tests.js.yml b/.github/workflows/sphinx-plugin-tests.js.yml index e9bda4912..ca4cc9cb1 100644 --- a/.github/workflows/sphinx-plugin-tests.js.yml +++ b/.github/workflows/sphinx-plugin-tests.js.yml @@ -23,9 +23,9 @@ jobs: python-version: ['3.14'] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - name: Install OS Deps diff --git a/.github/workflows/typescript-tests.js.yml b/.github/workflows/typescript-tests.js.yml index ba9d738a9..7491ae772 100644 --- a/.github/workflows/typescript-tests.js.yml +++ b/.github/workflows/typescript-tests.js.yml @@ -24,16 +24,16 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' diff --git a/.github/workflows/vagrantfile-validation.yml b/.github/workflows/vagrantfile-validation.yml index f40051fa5..e419316f1 100644 --- a/.github/workflows/vagrantfile-validation.yml +++ b/.github/workflows/vagrantfile-validation.yml @@ -21,7 +21,7 @@ jobs: runs-on: ubuntu-26.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Check Ruby syntax run: ruby -c Vagrantfile @@ -42,7 +42,7 @@ jobs: runs-on: ubuntu-26.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 # Ubuntu's archive carries no `vagrant` package, so the release is # fetched from HashiCorp and pinned, the way the box version is.