ci(deps): bump the github-actions group across 1 directory with 3 updates#723
ci(deps): bump the github-actions group across 1 directory with 3 updates#723dependabot[bot] wants to merge 2 commits into
Conversation
…ates Bumps the github-actions group with 3 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action), [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [MarcoIeni/release-plz-action](https://github.com/marcoieni/release-plz-action). Updates `github/codeql-action` from 4.35.2 to 4.35.4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@95e58e9...68bde55) Updates `ruby/setup-ruby` from 1.306.0 to 1.307.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](ruby/setup-ruby@c4e5b13...6aaa311) Updates `MarcoIeni/release-plz-action` from 0.5.128 to 0.5.129 - [Release notes](https://github.com/marcoieni/release-plz-action/releases) - [Commits](release-plz/action@1528104...064f4d1) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.35.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: ruby/setup-ruby dependency-version: 1.307.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: MarcoIeni/release-plz-action dependency-version: 0.5.129 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
|
@copilot Validate thoroughly that the dependency update is safe and secure. |
Validated thoroughly: all three action updates are pinned to immutable commit SHAs and match their expected upstream release tags ( |
Bumps the github-actions group with 3 updates in the / directory: github/codeql-action, ruby/setup-ruby and MarcoIeni/release-plz-action.
Updates
github/codeql-actionfrom 4.35.2 to 4.35.4Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
68bde55Merge pull request #3885 from github/update-v4.35.4-803d9e8c39739ad2Update changelog for v4.35.4803d9e8Merge pull request #3883 from github/mbg/test/macro-wrapper0fd9c7dMerge pull request #3882 from github/dependabot/github_actions/dot-github/wor...922d6fbUsemakeMacroinstead oftest.macrodf77e87Update test macro snippet6e3f985Add wrapper fortest.macroe7a347dMerge pull request #3881 from github/update-bundle/codeql-bundle-v2.25.417eabb2Rebuildaaef09cBump ruby/setup-rubyUpdates
ruby/setup-rubyfrom 1.306.0 to 1.307.0Release notes
Sourced from ruby/setup-ruby's releases.
Commits
6aaa311Add ruby-4.0.4f02c009Fix docs.github.com URLs to avoid 301 redirects98bfeb1Remove EOL Ruby versions from matrix example in README59a7680Update Ruby version examples in README to include 4.06459287Replace outdated help.github.com URLs with docs.github.comUpdates
MarcoIeni/release-plz-actionfrom 0.5.128 to 0.5.129Release notes
Sourced from MarcoIeni/release-plz-action's releases.
... (truncated)
Commits
064f4d1chore(deps): update dependency obi1kenobi/cargo-semver-checks to v0.47 (#397)4f2dca0fix cargo-semver-checks renovate update (#396)39f5787Update to 0.3.158 (#395)bb36e14chore(deps): update dependency taiki-e/install-action to v2.77.4 (#394)3711471chore(deps): update dependency taiki-e/install-action to v2.77.3 (#393)b234371chore(deps): update dependency taiki-e/install-action to v2.77.2 (#392)3427ba6chore(deps): update dependency cargo-bins/cargo-binstall to v1.19.1 (#391)37e90aachore(deps): update dependency taiki-e/install-action to v2.77.1 (#390)eef2a46chore(deps): update dependency taiki-e/install-action to v2.77.0 (#389)eb60137chore(deps): update dependency taiki-e/install-action to v2.76.0 (#388)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions