Skip to content

chore(deps): bump the github-actions group across 1 directory with 9 updates - #118

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-69e623cb84
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-69e623cb84

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown

Bumps the github-actions group with 9 updates in the / directory:

Package From To
actions/checkout 3 7
actions/setup-python 5 7
nf-core/setup-nextflow 2 3
pietrobolcato/action-read-yaml 1.0.0 1.1.0
docker/login-action 2 4
docker/build-push-action 4 7
CCBR/actions 0.2 0.7
actions/create-github-app-token 2 3
actions/add-to-project 1.0.2 2.0.0

Updates actions/checkout from 3 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-python from 5 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates nf-core/setup-nextflow from 2 to 3

Release notes

Sourced from nf-core/setup-nextflow's releases.

v3.0.0

Breaking Change

  • Upgraded Node.js version from 20 to 24 (#219)

Added

  • secrets input to set Nextflow secrets (KEY=VALUE format, one per line) (#202)
  • Test to verify /dist is up-to-date
  • Pull request template
  • Contributing documentation

Changed

  • Updated ESLint to v9 with flat config format
  • Migrated codebase to ES Modules (ESM)
  • Simplified action.yml by flattening the composite action structure
Changelog

Sourced from nf-core/setup-nextflow's changelog.

[3.0.1] - 2026-07-21

Fixed

  • Resolve fully specified Nextflow versions without relying on nf-core metadata (#242)
  • Preserve archive selection across the Nextflow 24.10.0 distribution boundary (#242)
  • Report malformed or incomplete nf-core metadata with actionable errors (#242)

[3.0.0] - 2024-04-17

Breaking Change

  • Upgraded Node.js version from 20 to 24 (#219)

Added

  • secrets input to set Nextflow secrets (KEY=VALUE format, one per line) (#202)
  • Test to verify /dist is up-to-date
  • Pull request template
  • Contributing documentation

Changed

  • Updated ESLint to v9 with flat config format
  • Migrated codebase to ES Modules (ESM)
  • Simplified action.yml by flattening the composite action structure

[2.1.4] - 2024-12-05

  • Fix ref handling in nested GitHub Actions

[2.1.3] - 2024-12-05

  • remove unnecessary build step

[2.1.2] - 2024-12-05

  • Fix checkout step in main action.yml

[2.1.1] - 2024-12-05

  • Don't print nextflow help output by default, only on debug mode (#173)

[2.1.1] - 2024-12-05

  • Add checkout step to main action.yml (#178)

[2.1.0] - 2024-12-04

Changed

... (truncated)

Commits

Updates pietrobolcato/action-read-yaml from 1.0.0 to 1.1.0

Release notes

Sourced from pietrobolcato/action-read-yaml's releases.

v1.1.0

What's Changed

Full Changelog: pietrobolcato/action-read-yaml@1.0.0...1.1.0

Commits
  • 9f13718 merge pull request #3 from pietrobolcato/develop
  • c380cd6 fix: dot notation members access
  • 4ce5379 merge pull request #2 from pietrobolcato/feature/nested-values
  • 81d1d08 chore: updated readme
  • b18db15 feat: updated examples
  • dc1698c feat: added support for nested values
  • See full diff in compare view

Updates docker/login-action from 2 to 4

Release notes

Sourced from docker/login-action's releases.

v4.0.0

Full Changelog: docker/login-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/login-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/login-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/login-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/login-action@v3.3.0...v3.4.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates docker/build-push-action from 4 to 7

Release notes

Sourced from docker/build-push-action's releases.

v7.0.0

Full Changelog: docker/build-push-action@v6.19.2...v7.0.0

v6.19.2

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

v6.18.0

[!NOTE] Build summary is now supported with Docker Build Cloud.

Full Changelog: docker/build-push-action@v6.17.0...v6.18.0

v6.17.0

[!NOTE] Build record is now exported using the buildx history export command instead of the legacy export-build tool.

Full Changelog: docker/build-push-action@v6.16.0...v6.17.0

v6.16.0

... (truncated)

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

Updates CCBR/actions from 0.2 to 0.7

Release notes

Sourced from CCBR/actions's releases.

actions 0.7.0

actions 0.6.2

actions 0.6.1

  • Fix changed-files: do not use pip cache with setup-python since the repo is not checked out. (#158, @​kelly-sovacool)
  • Fix forgotten actions that were missed when previously bumping to the latest versions in anticipation of the node.js 20 deprecation. (#159, @​kelly-sovacool)

actions 0.6.0

  • New action: changed-files to detect files that changed matching a pattern. (#152, @​kelly-sovacool)
    • Can compare the most recent commit only or the entire PR changes by setting the comparison-mode option. (#156, @​kelly-sovacool)
  • Bump actions versions to the latest release in anticipation of the node.js 20 deprecation. (#149, @​kelly-sovacool)
  • Improve build-docker example workflows to prevent excessive docker updates. (#153, @​kelly-sovacool)

actions 0.5.3

  • Improve maintain-milestones:

actions 0.5.2

actions 0.5.1

  • fix build-docker to properly use the path to the print versions script and support dockerfiles with entrypoints set. (#126, @​kelly-sovacool)

actions 0.5.0

  • fix build-docker - refactor the print versions script to use bash so it can run even if python isn't installed. (#111, @​kelly-sovacool)
  • post-release - update sliding tags instead of branches. (#119, @​kelly-sovacool)

... (truncated)

Changelog

Sourced from CCBR/actions's changelog.

actions development version

actions 0.8.0

New

Fixes

  • Clarify ccbr-actions-version behavior for containerized actions and document the CCBR_ACTIONS_VERSION build argument used by build-docker. (#221, @​kelly-sovacool, @​copilot)
  • Fixes for the draft-release action:
    • Fix draft-release to accept a manually provided version when conventional commits do not determine a version bump. (#213, @​kelly-sovacool, @​copilot)
    • Fix the draft-release example workflow docs (correct typo, Python 3.14, actions/checkout@v7) and rename examples/R-CMD-check.yaml to .yml so it appears in the published examples docs. (#215, @​kelly-sovacool)
    • Match the dev_header in draft-release changelogs case-insensitively so capitalized headers (e.g. ## Development version) are updated correctly. (#220, @​kelly-sovacool, @​copilot)
  • Set up testing infrastructure for github actions and related fixes: (#216, @​kelly-sovacool, @​copilot)
    • Includes host/container integration coverage, dry-run support for release actions, actionlint validation, and contract tests for example workflows.
    • Fix container detection in draft-release, post-release, changed-files, mkdocs-mike, and review-pre-commit-pr: the CCBR_ACTIONS_DOCKER variable baked into the ccbr_actions image is not visible to the env context, so Python/R setup steps (including cache: pip, which fails in container jobs) were still running inside the container. Detection now happens in a shell step whose output gates the setup steps. (#216, @​kelly-sovacool)
    • Fix build-docker: the push_success output now reports false when pushing is disabled. (#216, @​kelly-sovacool, @​copilot)
    • Fix draft-release and post-release: the dry-run input rendered as lowercase true/false in the Python step, raising NameError. (#216, @​kelly-sovacool, @​copilot)
    • New dry-run input for mkdocs-mike to print the mike deploy command instead of deploying the docs website. (#216, @​kelly-sovacool)

actions 0.7.2

  • New commands list-rulesets and copy-ruleset, plus a copy-ruleset action, for copying GitHub rulesets between repositories. (#183, @​kelly-sovacool, @​copilot)
  • Fix build-docker action: fix bash suffix conditional so an empty suffix (and main) leaves the docker tag unchanged. (#199, @​kelly-sovacool)

actions 0.7.1

actions 0.7.0

actions 0.6.2

  • Fix...

    Description has been truncated

…updates

Bumps the github-actions group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `3` | `7` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` |
| [nf-core/setup-nextflow](https://github.com/nf-core/setup-nextflow) | `2` | `3` |
| [pietrobolcato/action-read-yaml](https://github.com/pietrobolcato/action-read-yaml) | `1.0.0` | `1.1.0` |
| [docker/login-action](https://github.com/docker/login-action) | `2` | `4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `4` | `7` |
| [CCBR/actions](https://github.com/ccbr/actions) | `0.2` | `0.7` |
| [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `2` | `3` |
| [actions/add-to-project](https://github.com/actions/add-to-project) | `1.0.2` | `2.0.0` |



Updates `actions/checkout` from 3 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v3...v7)

Updates `actions/setup-python` from 5 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

Updates `nf-core/setup-nextflow` from 2 to 3
- [Release notes](https://github.com/nf-core/setup-nextflow/releases)
- [Changelog](https://github.com/nf-core/setup-nextflow/blob/master/CHANGELOG.md)
- [Commits](nf-core/setup-nextflow@v2...v3)

Updates `pietrobolcato/action-read-yaml` from 1.0.0 to 1.1.0
- [Release notes](https://github.com/pietrobolcato/action-read-yaml/releases)
- [Commits](pietrobolcato/action-read-yaml@1.0.0...1.1.0)

Updates `docker/login-action` from 2 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v2...v4)

Updates `docker/build-push-action` from 4 to 7
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v4...v7)

Updates `CCBR/actions` from 0.2 to 0.7
- [Release notes](https://github.com/ccbr/actions/releases)
- [Changelog](https://github.com/CCBR/actions/blob/main/CHANGELOG.md)
- [Commits](CCBR/actions@v0.2...v0.7)

Updates `actions/create-github-app-token` from 2 to 3
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)
- [Commits](actions/create-github-app-token@v2...v3)

Updates `actions/add-to-project` from 1.0.2 to 2.0.0
- [Release notes](https://github.com/actions/add-to-project/releases)
- [Commits](actions/add-to-project@v1.0.2...v2.0.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: nf-core/setup-nextflow
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: pietrobolcato/action-read-yaml
  dependency-version: 1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: CCBR/actions
  dependency-version: '0.7'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/create-github-app-token
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/add-to-project
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 8, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-69e623cb84 branch October 8, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants