Skip to content

chore(deps): update non-major github actions#172

Open
nbl-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-github-actions
Open

chore(deps): update non-major github actions#172
nbl-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-github-actions

Conversation

@nbl-renovate

@nbl-renovate nbl-renovate Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
actions/attest-build-provenance action patch v4.1.0v4.1.1
astral-sh/setup-uv action minor v8.2.0v8.3.2
docker/build-push-action action minor v7.2.0v7.3.0
docker/login-action action minor v4.2.0v4.4.0
docker/setup-buildx-action action minor v4.1.0v4.2.0
github/codeql-action action minor v4.36.2v4.37.0 v4.37.1

Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v4.1.1

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.0...v4.1.1

astral-sh/setup-uv (astral-sh/setup-uv)

v8.3.2: 🌈 update known checksums for 0.11.28

Compare Source

Changes

Just a maintenance release

🧰 Maintenance
📚 Documentation
⬆️ Dependency updates

v8.3.1: 🌈 update known checksums for 0.11.27

Compare Source

Changes

Just a maintenance release

🧰 Maintenance
📚 Documentation

v8.3.0: 🌈 Support uv.lock as a version-file source

Compare Source

Changes

Thanks to @​somaz94 you can now use the pinned version of uv itself in uv.lock. It gets picked up automatically.
If you have pinned another version of uv in your uv.lock you can use the inputs version or version-source to override this.

🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
docker/build-push-action (docker/build-push-action)

v7.3.0

Compare Source

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

docker/login-action (docker/login-action)

v4.4.0

Compare Source

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.2.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

github/codeql-action (github/codeql-action)

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@​ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "before 4am on Monday,Tuesday,Wednesday,Thursday,Friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@nbl-renovate nbl-renovate Bot added the dependencies Pull requests that update a dependency file label Jul 6, 2026
@nbl-renovate nbl-renovate Bot added the dependencies Pull requests that update a dependency file label Jul 6, 2026
@nbl-renovate
nbl-renovate Bot force-pushed the renovate/non-major-github-actions branch from 96382ce to d48a9e1 Compare July 8, 2026 15:55
@nbl-renovate nbl-renovate Bot changed the title chore(deps): update actions/attest-build-provenance action to v4.1.1 chore(deps): update non-major github actions Jul 8, 2026
@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Vulnerability Scan: Passed

Image: netbox-mcp-server:scan

Source Library CVE Severity Installed Fixed Title
Python pydantic-settings GHSA-4xgf-cpjx-pc3j 🟡 MEDIUM 2.14.1 2.14.2 pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_

Commit: 0bd29db

@nbl-renovate
nbl-renovate Bot force-pushed the renovate/non-major-github-actions branch 5 times, most recently from 1e8d5d3 to a0927a3 Compare July 15, 2026 09:44
@nbl-renovate
nbl-renovate Bot force-pushed the renovate/non-major-github-actions branch from a0927a3 to 1001615 Compare July 15, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants