Skip to content

chore(deps): bump the github-actions group across 1 directory with 5 updates - #103

Merged
kelly-sovacool merged 3 commits into
mainfrom
dependabot/github_actions/github-actions-e1d4ad0ee4
Sep 28, 2026
Merged

kelly-sovacool merged 3 commits into
mainfrom
dependabot/github_actions/github-actions-e1d4ad0ee4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 5 updates in the / directory:

Package From To
actions/checkout 4 7
actions/setup-python 5 7
CCBR/actions 0.3 0.7
actions/create-github-app-token 2 3
actions/add-to-project 1.0.2 2.0.0

Updates actions/checkout from 4 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-python from 5 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates CCBR/actions from 0.3 to 0.7

Release notes

Sourced from CCBR/actions's releases.

actions 0.7.0

actions 0.6.2

actions 0.6.1

  • Fix changed-files: do not use pip cache with setup-python since the repo is not checked out. (#158, @​kelly-sovacool)
  • Fix forgotten actions that were missed when previously bumping to the latest versions in anticipation of the node.js 20 deprecation. (#159, @​kelly-sovacool)

actions 0.6.0

  • New action: changed-files to detect files that changed matching a pattern. (#152, @​kelly-sovacool)
    • Can compare the most recent commit only or the entire PR changes by setting the comparison-mode option. (#156, @​kelly-sovacool)
  • Bump actions versions to the latest release in anticipation of the node.js 20 deprecation. (#149, @​kelly-sovacool)
  • Improve build-docker example workflows to prevent excessive docker updates. (#153, @​kelly-sovacool)

actions 0.5.3

  • Improve maintain-milestones:

actions 0.5.2

actions 0.5.1

  • fix build-docker to properly use the path to the print versions script and support dockerfiles with entrypoints set. (#126, @​kelly-sovacool)

actions 0.5.0

  • fix build-docker - refactor the print versions script to use bash so it can run even if python isn't installed. (#111, @​kelly-sovacool)
  • post-release - update sliding tags instead of branches. (#119, @​kelly-sovacool)

... (truncated)

Changelog

Sourced from CCBR/actions's changelog.

actions development version

  • New action: review-post-release-pr to automatically review post-release cleanup PRs and approve them (approving pending workflow runs and enabling auto-merge) when the version file was actually bumped and every changed file's new content is a valid, field-specific bump matching an actual release tag, or request a human reviewer otherwise. Approvals are pinned to the validated commit and re-validated if the PR's head changes afterward (e.g. after an auto-format push). (#227, @​kelly-sovacool, @​copilot)
    • Require the PR's synchronize event to come from the bot (not just any pusher) before re-running the automatic review, and pass action inputs to the embedded Python scripts via env: instead of splicing ${{ inputs.* }} directly into the script text, in review-pre-commit-pr and review-post-release-pr. (#227, @​kelly-sovacool, @​copilot)
  • Fix review-pre-commit-pr to post a comment instead of requesting changes when a pre-commit.ci autoupdate PR needs human review. (#226, @​kelly-sovacool, @​copilot)

actions 0.8.0

New

Fixes

  • Clarify ccbr-actions-version behavior for containerized actions and document the CCBR_ACTIONS_VERSION build argument used by build-docker. (#221, @​kelly-sovacool, @​copilot)
  • Fixes for the draft-release action:
    • Fix draft-release to accept a manually provided version when conventional commits do not determine a version bump. (#213, @​kelly-sovacool, @​copilot)
    • Fix the draft-release example workflow docs (correct typo, Python 3.14, actions/checkout@v7) and rename examples/R-CMD-check.yaml to .yml so it appears in the published examples docs. (#215, @​kelly-sovacool)
    • Match the dev_header in draft-release changelogs case-insensitively so capitalized headers (e.g. ## Development version) are updated correctly. (#220, @​kelly-sovacool, @​copilot)
  • Set up testing infrastructure for github actions and related fixes: (#216, @​kelly-sovacool, @​copilot)
    • Includes host/container integration coverage, dry-run support for release actions, actionlint validation, and contract tests for example workflows.
    • Fix container detection in draft-release, post-release, changed-files, mkdocs-mike, and review-pre-commit-pr: the CCBR_ACTIONS_DOCKER variable baked into the ccbr_actions image is not visible to the env context, so Python/R setup steps (including cache: pip, which fails in container jobs) were still running inside the container. Detection now happens in a shell step whose output gates the setup steps. (#216, @​kelly-sovacool)
    • Fix build-docker: the push_success output now reports false when pushing is disabled. (#216, @​kelly-sovacool, @​copilot)
    • Fix draft-release and post-release: the dry-run input rendered as lowercase true/false in the Python step, raising NameError. (#216, @​kelly-sovacool, @​copilot)
    • New dry-run input for mkdocs-mike to print the mike deploy command instead of deploying the docs website. (#216, @​kelly-sovacool)

actions 0.7.2

  • New commands list-rulesets and copy-ruleset, plus a copy-ruleset action, for copying GitHub rulesets between repositories. (#183, @​kelly-sovacool, @​copilot)
  • Fix build-docker action: fix bash suffix conditional so an empty suffix (and main) leaves the docker tag unchanged. (#199, @​kelly-sovacool)

actions 0.7.1

actions 0.7.0

... (truncated)

Commits
  • e3fa967 chore: 🤖 prepare release v0.7.2
  • b1aeb5b [pre-commit.ci] pre-commit autoupdate (#202)
  • 8ab4457 [pre-commit.ci] pre-commit autoupdate (#200)
  • d0554f4 chore: 🤖 sync copilot instructions - 2026-08-12 (#201)
  • 7a4ba8d chore(deps): bump the github-actions group across 10 directories with 10 upda...
  • dc53149 Merge pull request #193 from CCBR/pre-commit-ci-update-config
  • c08c012 fix(build-docker): handle empty suffix (#199)
  • 2593541 Merge branch 'main' into pre-commit-ci-update-config
  • 5ad7d55 chore: setup Pixi for dev deps (#197)
  • 3c689b3 chore(dependabot): manage all composite and example github actions workflows ...
  • Additional commits viewable in compare view

Updates actions/create-github-app-token from 2 to 3

Release notes

Sourced from actions/create-github-app-token's releases.

v3.0.0

3.0.0 (2026-03-14)

Bug Fixes

BREAKING CHANGES

  • Custom proxy handling has been removed. If you use HTTP_PROXY or HTTPS_PROXY, you must now also set NODE_USE_ENV_PROXY=1 on the action step.
  • Requires Actions Runner v2.327.1 or later if you are using a self-hosted runner.

v3.0.0-beta.6

3.0.0-beta.6 (2026-03-13)

Bug Fixes

  • deps: bump @​actions/core from 1.11.1 to 3.0.0 (#337) (b044133)
  • deps: bump minimatch from 9.0.5 to 9.0.9 (#335) (5cbc656)
  • deps: bump the production-dependencies group with 4 updates (#336) (6bda5bc)
  • deps: bump undici from 7.16.0 to 7.18.2 (#323) (b4f638f)

v3.0.0-beta.5

3.0.0-beta.5 (2026-03-13)

  • fix!: require NODE_USE_ENV_PROXY for proxy support (#342) (d53a1cd)

BREAKING CHANGES

  • Custom proxy handling has been removed. If you use HTTP_PROXY or HTTPS_PROXY, you must now also set NODE_USE_ENV_PROXY=1 on the action step.

v3.0.0-beta.4

3.0.0-beta.4 (2026-03-13)

Bug Fixes

  • deps: bump @​octokit/auth-app from 7.2.1 to 8.0.1 (#257) (bef1eaf)
  • deps: bump @​octokit/request from 9.2.3 to 10.0.2 (#256) (5d7307b)
  • deps: bump glob from 10.4.5 to 10.5.0 (#305) (5480f43)
  • deps: bump p-retry from 6.2.1 to 7.1.0 (#294) (dce3be8)

... (truncated)

Changelog

Sourced from actions/create-github-app-token's changelog.

Changelog

3.2.0 (2026-05-12)

Features

  • add support for enterprise-level GitHub Apps (#263) (952a2a7)
  • support full repository names in repositories input (#372) (85eb8dd)

Bug Fixes

  • deps: bump @​actions/core from 3.0.0 to 3.0.1 in the production-dependencies group (#364) (43e5c34)
  • validate private-key input (#376) (f24bbd8)
Commits
  • bcd2ba4 chore(main): release 3.2.0 (#370)
  • f24bbd8 fix: validate private-key input (#376)
  • 363531b docs: capitalize Git as a proper noun in README (#374)
  • fd28011 docs: update procedure to configure Git (#287)
  • 85eb8dd feat: support full repository names in repositories input (#372)
  • c9aabb8 build(deps-dev): bump yaml from 2.8.3 to 2.8.4 in the development-dependencie...
  • e02e816 build(deps-dev): bump undici from 7.24.6 to 8.2.0 (#366)
  • 8d835bf build(deps-dev): bump esbuild from 0.27.4 to 0.28.0 in the development-depend...
  • 952a2a7 feat: add support for enterprise-level GitHub Apps (#263)
  • 43e5c34 fix(deps): bump @​actions/core from 3.0.0 to 3.0.1 in the production-dependenc...
  • Additional commits viewable in compare view

Updates actions/add-to-project from 1.0.2 to 2.0.0

Release notes

Sourced from actions/add-to-project's releases.

v2

What's Changed

... (truncated)

Commits
  • 5afcf98 Merge pull request Description has been truncated

…updates

Bumps the github-actions group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` |
| [CCBR/actions](https://github.com/ccbr/actions) | `0.3` | `0.7` |
| [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2` | `3` |
| [actions/add-to-project](https://github.com/actions/add-to-project) | `1.0.2` | `2.0.0` |



Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

Updates `actions/setup-python` from 5 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

Updates `CCBR/actions` from 0.3 to 0.7
- [Release notes](https://github.com/ccbr/actions/releases)
- [Changelog](https://github.com/CCBR/actions/blob/main/CHANGELOG.md)
- [Commits](CCBR/actions@v0.3...v0.7)

Updates `actions/create-github-app-token` from 2 to 3
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)
- [Commits](actions/create-github-app-token@v2...v3)

Updates `actions/add-to-project` from 1.0.2 to 2.0.0
- [Release notes](https://github.com/actions/add-to-project/releases)
- [Commits](actions/add-to-project@v1.0.2...v2.0.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: CCBR/actions
  dependency-version: '0.7'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/create-github-app-token
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/add-to-project
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@kelly-sovacool
kelly-sovacool enabled auto-merge (squash) September 28, 2026 19:55
@kelly-sovacool
kelly-sovacool merged commit b1e2fb1 into main Sep 28, 2026
4 checks passed
@kelly-sovacool
kelly-sovacool deleted the dependabot/github_actions/github-actions-e1d4ad0ee4 branch September 28, 2026 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant