ci(deps): Bump the github-actions group with 4 updates - #105
Conversation
Bumps the github-actions group with 4 updates: [pnpm/action-setup](https://github.com/pnpm/action-setup), [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action). Updates `pnpm/action-setup` from 6.0.9 to 6.0.10 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@0ebf471...0977fd9) Updates `github/codeql-action/init` from 4.37.3 to 4.37.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...d1ba80a) Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...d1ba80a) Updates `zizmorcore/zizmor-action` from 0.6.1 to 0.6.2 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](zizmorcore/zizmor-action@6fc4b00...3dc1ecc) --- updated-dependencies: - dependency-name: pnpm/action-setup dependency-version: 6.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM — routine GitHub Actions dependency bump.
What was reviewed: verified each updated SHA pin matches its stated version comment (pnpm/action-setup v6.0.10, codeql-action/init and /analyze v4.37.5, zizmor-action v0.6.2) across ci.yml, codeql.yml, update-dist-on-label.yml, and zizmor.yml. No logic, permissions, or trigger conditions changed in any workflow.
Extended reasoning...
Overview
This PR is an automated Dependabot bump of the github-actions group, updating pinned commit SHAs (with version comments) for pnpm/action-setup (6.0.9→6.0.10), github/codeql-action/init and github/codeql-action/analyze (4.37.3→4.37.5), and zizmorcore/zizmor-action (0.6.1→0.6.2) across four workflow files. No workflow logic, permissions, triggers, or job structure changed — only the pinned SHA and its trailing version comment on each uses: line.
Security risks
None introduced. All actions are already pinned to full commit SHAs (best practice), and this PR only advances those pins to newer upstream commits corresponding to the stated version tags. The SHA/version-comment pairs in the diff match the versions described in the PR body for each dependency. No changes to permissions:, secrets handling, or trigger conditions in any of the four files.
Level of scrutiny
Low. This is the textbook case for a mechanical, low-risk change: purely a CI dependency version bump with no behavioral changes to the action itself beyond upstream bug fixes (e.g., codeql-action network-error handling, zizmor-action patch, pnpm/action-setup docs/cache tweaks per the release notes).
Other factors
No prior reviews or comments exist on this PR. The bug hunting system found no issues, and my own read of the diff and full file contents confirms the changes are limited to the four SHA/version pairs.
|
| Experiment | Status | Actions |
|---|---|---|
| Uppercase (py) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Uppercase (ts) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Mixed dir (node) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Mixed dir (python) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Regression fixture | ❌ Regression | View GitHub Action Run · View in Langfuse |
Details
wochinge
left a comment
There was a problem hiding this comment.
Verified the SHA-pinned Actions updates and their release notes. No workflow logic, permissions, or trigger changes; all checks are green.
Bumps the github-actions group with 4 updates: pnpm/action-setup, github/codeql-action/init, github/codeql-action/analyze and zizmorcore/zizmor-action.
Updates
pnpm/action-setupfrom 6.0.9 to 6.0.10Release notes
Sourced from pnpm/action-setup's releases.
Commits
0977fd9docs: Update README to include devEngines.packageManager (#273)48261acfix: update pnpm to v11.19.0 (#283)75677f7ci: use pnpm 11 forpr-check(#284)769ae71refactor: introduce restore keys for cache (#280)6fed91fdocs(README): point users to the successor pnpm/setup action (#282)Updates
github/codeql-action/initfrom 4.37.3 to 4.37.5Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5e74600bUpdate changelog for v4.37.51cd4d01Merge pull request #4061 from github/henrymercer/turbo-systemd2bfc30Merge pull request #4050 from github/mbg/status/registries68028fcMerge pull request #4062 from github/sam-robson/migrate-enterprise-release-patc29563eci: use federated enterprise release PAT155e522Link the PR from the changelog entry2d3b351Handle network errors when streaming the CodeQL bundle download5d3eb98Merge pull request #4055 from github/dependabot/npm_and_yarn/npm-minor-203262...c5f739bMerge branch 'main' into dependabot/npm_and_yarn/npm-minor-2032624187Updates
github/codeql-action/analyzefrom 4.37.3 to 4.37.5Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5e74600bUpdate changelog for v4.37.51cd4d01Merge pull request #4061 from github/henrymercer/turbo-systemd2bfc30Merge pull request #4050 from github/mbg/status/registries68028fcMerge pull request #4062 from github/sam-robson/migrate-enterprise-release-patc29563eci: use federated enterprise release PAT155e522Link the PR from the changelog entry2d3b351Handle network errors when streaming the CodeQL bundle download5d3eb98Merge pull request #4055 from github/dependabot/npm_and_yarn/npm-minor-203262...c5f739bMerge branch 'main' into dependabot/npm_and_yarn/npm-minor-2032624187Updates
zizmorcore/zizmor-actionfrom 0.6.1 to 0.6.2Release notes
Sourced from zizmorcore/zizmor-action's releases.
Commits
3dc1eccSync zizmor versions (#149)dc57e30chore(deps): bump the github-actions group with 3 updates (#147)d94880aREADME: bump pins (#146)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions