chore(deps): Update GitHub Actions - #78
Conversation
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (1)
WalkthroughPinned references were refreshed across GitHub Actions workflow files. The updates cover direct actions, reusable workflows, and the Redis service image. Workflow logic and configuration remain unchanged. ChangesCI Dependency Pin Updates
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related issues
Possibly related PRs
Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dependency ReviewThe following issues were found:
License Issues.github/workflows/performance-regression.yml
OpenSSF Scorecard
Scanned Files
|
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
There was a problem hiding this comment.
Pull request overview
Updates GitHub Actions and org-level reusable workflow pins across this repository’s CI/security/docs pipelines to pick up patch-level fixes and security updates while preserving existing workflow behavior.
Changes:
- Bump
actions/checkoutfromv6.0.2tov6.0.3(SHA-pinned) wherever it’s used directly. - Bump
github/codeql-actionfromv4.36.0tov4.36.1(SHA-pinned) in the CodeQL workflow. - Update callers of
ByronWilliamsCPA/.githubreusable workflows to the latest pinned digest.
Reviewed changes
Copilot reviewed 22 out of 22 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/sonarcloud.yml | Updates org reusable SonarCloud workflow digest pin. |
| .github/workflows/security-analysis.yml | Updates org reusable security-analysis workflow digest pin. |
| .github/workflows/scorecard.yml | Updates org reusable scorecard workflow digest pin. |
| .github/workflows/sbom.yml | Updates org reusable SBOM workflow digest pin. |
| .github/workflows/reuse.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned) for REUSE checks. |
| .github/workflows/release.yml | Updates org reusable release workflow digest pin. |
| .github/workflows/release-sign.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned) for signing workflow. |
| .github/workflows/qlty.yml | Updates org reusable Qlty coverage workflow digest pin. |
| .github/workflows/python-compatibility.yml | Updates org reusable compatibility workflow digest pin. |
| .github/workflows/publish-pypi.yml | Updates org reusable PyPI publish workflow digest pin. |
| .github/workflows/pr-validation.yml | Updates org reusable CI workflow digest pin; bumps actions/checkout to v6.0.3 (SHA-pinned) in additional jobs. |
| .github/workflows/postman-api-tests.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned). |
| .github/workflows/performance-regression.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned) and updates org reusable perf workflow digest pin. |
| .github/workflows/mutation-testing.yml | Updates org reusable mutation testing workflow digest pin. |
| .github/workflows/fips-compatibility.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned) in FIPS jobs. |
| .github/workflows/docs.yml | Updates org reusable docs workflow digest pin. |
| .github/workflows/dependency-review.yml | Bumps actions/checkout to v6.0.3 (SHA-pinned). |
| .github/workflows/coverage.yml | Updates org reusable Qlty coverage workflow digest pin. |
| .github/workflows/container-security.yml | Updates org reusable container security workflow digest pin. |
| .github/workflows/codeql.yml | Bumps actions/checkout to v6.0.3 and github/codeql-action to v4.36.1 (both SHA-pinned). |
| .github/workflows/codecov.yml | Updates org reusable Codecov workflow digest pin. |
| .github/workflows/ci.yml | Updates org reusable CI workflow digest pin; bumps actions/checkout to v6.0.3 (SHA-pinned). |
2370c17 to
b2b7ac8
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
b2b7ac8 to
cc8a6cc
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
cc8a6cc to
566de1e
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
566de1e to
3733bba
Compare
|
No dependency changes detected. Learn more about Socket for GitHub. 👍 No dependency changes detected in pull request |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
3733bba to
f206cc8
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
f206cc8 to
a911d9d
Compare
🎉 Performance Regression CheckStatus: PERFORMANCE IMPROVED
Threshold: +/-10% allowed regression ✅ Great work!: Performance has improved. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
a911d9d to
19f938e
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
19f938e to
900c818
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
900c818 to
425aa68
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
fd11b67 to
116e9b3
Compare
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
🎉 Performance Regression CheckStatus: PERFORMANCE IMPROVED
Threshold: +/-10% allowed regression ✅ Great work!: Performance has improved. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
🎉 Performance Regression CheckStatus: PERFORMANCE IMPROVED
Threshold: +/-10% allowed regression ✅ Great work!: Performance has improved. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
🎉 Performance Regression CheckStatus: PERFORMANCE IMPROVED
Threshold: +/-10% allowed regression ✅ Great work!: Performance has improved. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
🎉 Performance Regression CheckStatus: PERFORMANCE IMPROVED
Threshold: +/-10% allowed regression ✅ Great work!: Performance has improved. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 62-63: Disable credential persistence on every listed checkout
step by adding persist-credentials: false: .github/workflows/ci.yml lines 62-63;
.github/workflows/dependency-review.yml lines 35-36;
.github/workflows/fips-compatibility.yml lines 63-64 and 200-201;
.github/workflows/performance-regression.yml lines 61-62;
.github/workflows/postman-api-tests.yml lines 65-66;
.github/workflows/pr-validation.yml lines 58-59, 101-102, and 135-136; and
.github/workflows/release-sign.yml lines 25-26.
- Around line 60-61: Resolve the expired egress-policy deferrals by validating
required endpoints and changing the audit settings to block at
.github/workflows/ci.yml lines 60-61, .github/workflows/pr-validation.yml lines
55-56, and .github/workflows/pr-validation.yml lines 98-99; if blocking cannot
be enabled, renew each exception with an owner and a new expiry.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e7e1a5a5-da84-4b38-b103-2d034252005d
📒 Files selected for processing (24)
.github/workflows/ci.yml.github/workflows/codecov.yml.github/workflows/codeql.yml.github/workflows/container-security.yml.github/workflows/coverage.yml.github/workflows/dependency-review.yml.github/workflows/docs.yml.github/workflows/fips-compatibility.yml.github/workflows/mutation-testing.yml.github/workflows/performance-regression.yml.github/workflows/postman-api-tests.yml.github/workflows/pr-title.yml.github/workflows/pr-validation.yml.github/workflows/publish-pypi.yml.github/workflows/python-compatibility.yml.github/workflows/qlty.yml.github/workflows/release-sign.yml.github/workflows/release.yml.github/workflows/reuse.yml.github/workflows/sbom.yml.github/workflows/scorecard.yml.github/workflows/security-analysis.yml.github/workflows/slsa-provenance.yml.github/workflows/sonarcloud.yml
| # egress-policy: block -- enabled 2026-05-23 (compliance audit). If a CI run fails on a network call, switch this single occurrence back to audit and capture the missing endpoint in the issue tracker. | ||
| egress-policy: audit # TODO: switch to block after 2026-06-30 (compliance audit deferral) |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== workflow snippets =="
for f in .github/workflows/ci.yml .github/workflows/pr-validation.yml; do
if [ -f "$f" ]; then
echo "-- $f --"
nl -ba "$f" | sed -n '45,65p;90,105p'
else
echo "MISSING $f"
fi
done
echo
echo "== date context =="
python3 - <<'PY'
from datetime import datetime, timezone
now = datetime.now(timezone.utc).strftime("%Y-%m-%d")
print("current_utc", now)
print("expired_after_2026-06-30", now > "2026-06-30")
PY
echo
echo "== harden-runner occurrences =="
rg -n "harden-runner|egress-policy" .github/workflows || trueRepository: ByronWilliamsCPA/rag-processor
Length of output: 263
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== workflow snippets =="
for f in .github/workflows/ci.yml .github/workflows/pr-validation.yml; do
if [ -f "$f" ]; then
echo "-- $f --"
awk '{printf "%5d\t%s\n", NR, $0}' "$f" | sed -n '45,65p;90,105p'
else
echo "MISSING $f"
fi
done
echo
echo "== date context =="
python3 - <<'PY'
from datetime import datetime, timezone
now = datetime.now(timezone.utc).date().isoformat()
print("current_utc", now)
print("expired_after_2026-06-30", now > "2026-06-30")
PY
echo
echo "== harden-runner occurrences =="
grep -nE "harden-runner|egress-policy" .github/workflows || trueRepository: ByronWilliamsCPA/rag-processor
Length of output: 4206
Resolve the expired harden-runner egress deferrals.
These workflow steps remain in egress-policy: audit even though the inline comments require switching to block after June 30, 2026. Enable blocking after validating required endpoints, or renew the exception with an owner and a new expiry.
Suggested patch
- egress-policy: audit # TODO: switch to block after 2026-06-30 (compliance audit deferral)
+ egress-policy: block.github/workflows/pr-validation.yml#L55-L56: Expired dead-code egress deferral..github/workflows/pr-validation.yml#L98-L99: Expired link-check egress deferral..github/workflows/ci.yml#L60-L61: Expired Playwright/CI egress deferral.
📍 Affects 2 files
.github/workflows/ci.yml#L60-L61(this comment).github/workflows/pr-validation.yml#L55-L56.github/workflows/pr-validation.yml#L98-L99
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml around lines 60 - 61, Resolve the expired
egress-policy deferrals by validating required endpoints and changing the audit
settings to block at .github/workflows/ci.yml lines 60-61,
.github/workflows/pr-validation.yml lines 55-56, and
.github/workflows/pr-validation.yml lines 98-99; if blocking cannot be enabled,
renew each exception with an owner and a new expiry.
Sources: Coding guidelines, Path instructions
| - name: Checkout | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 |
There was a problem hiding this comment.
Disable credential persistence on every modified checkout.
These checkout steps still use the default credential persistence behavior. Add persist-credentials: false to each step.
Suggested patch
- name: Checkout repository
uses: actions/checkout@...
+ with:
+ persist-credentials: false.github/workflows/ci.yml#L62-L63: Harden the Playwright checkout..github/workflows/dependency-review.yml#L35-L36: Harden the dependency-review checkout..github/workflows/fips-compatibility.yml#L63-L64: Harden the FIPS checkout..github/workflows/fips-compatibility.yml#L200-L201: Harden the runtime-test checkout..github/workflows/performance-regression.yml#L61-L62: Harden the benchmark checkout..github/workflows/postman-api-tests.yml#L65-L66: Harden the Newman checkout..github/workflows/pr-validation.yml#L58-L59: Harden the dead-code checkout..github/workflows/pr-validation.yml#L101-L102: Harden the link-check checkout..github/workflows/pr-validation.yml#L135-L136: Harden the dependency-validation checkout..github/workflows/release-sign.yml#L25-L26: Harden the release-signing checkout.
Based on learnings: modified checkout steps in touched workflows must explicitly disable credential persistence; as per path instructions, this is required workflow security hardening, and zizmor reports the same warning.
🧰 Tools
🪛 zizmor (1.28.0)
[warning] 62-63: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
📍 Affects 7 files
.github/workflows/ci.yml#L62-L63(this comment).github/workflows/dependency-review.yml#L35-L36.github/workflows/fips-compatibility.yml#L63-L64.github/workflows/fips-compatibility.yml#L200-L201.github/workflows/performance-regression.yml#L61-L62.github/workflows/postman-api-tests.yml#L65-L66.github/workflows/pr-validation.yml#L58-L59.github/workflows/pr-validation.yml#L101-L102.github/workflows/pr-validation.yml#L135-L136.github/workflows/release-sign.yml#L25-L26
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml around lines 62 - 63, Disable credential
persistence on every listed checkout step by adding persist-credentials: false:
.github/workflows/ci.yml lines 62-63; .github/workflows/dependency-review.yml
lines 35-36; .github/workflows/fips-compatibility.yml lines 63-64 and 200-201;
.github/workflows/performance-regression.yml lines 61-62;
.github/workflows/postman-api-tests.yml lines 65-66;
.github/workflows/pr-validation.yml lines 58-59, 101-102, and 135-136; and
.github/workflows/release-sign.yml lines 25-26.
Sources: Path instructions, Learnings, Linters/SAST tools
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
There was a problem hiding this comment.
♻️ Duplicate comments (2)
.github/workflows/ci.yml (2)
60-61: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy liftResolve all expired egress-policy deferrals.
The listed steps still use
egress-policy: auditwith TODOs that expired after June 30, 2026. The current date is August 2, 2026.
.github/workflows/ci.yml#L60-L61: validate endpoints and change the Playwright policy toblock, or renew the exception..github/workflows/pr-validation.yml#L55-L56: validate endpoints and change the dead-code policy toblock, or renew the exception..github/workflows/pr-validation.yml#L98-L99: validate endpoints and change the link-check policy toblock, or renew the exception..github/workflows/pr-validation.yml#L132-L133: validate endpoints and change the dependency-validation policy toblock, or renew the exception.As per path instructions: review GitHub Actions workflows for security best practices. These findings remain from previous review comments.
Suggested patch
- egress-policy: audit # TODO: switch to block after 2026-06-30 (compliance audit deferral) + egress-policy: blockApply the change after validating required endpoints. Otherwise, record an owner and a new expiry for each exception.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/ci.yml around lines 60 - 61, Resolve all expired egress-policy deferrals by validating required endpoints and changing the Playwright policy at .github/workflows/ci.yml lines 60-61, plus the dead-code, link-check, and dependency-validation policies at .github/workflows/pr-validation.yml lines 55-56, 98-99, and 132-133, from audit to block. If any exception must remain, document its owner and a new expiry at each affected site.Source: Path instructions
62-63: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winDisable credential persistence on all modified checkout steps.
Each listed checkout uses the default credential behavior. Add
persist-credentials: falseat every site.
.github/workflows/ci.yml#L62-L63: add the setting to the Playwright checkout..github/workflows/dependency-review.yml#L35-L36: add the setting to the dependency-review checkout..github/workflows/fips-compatibility.yml#L63-L64: add the setting to the FIPS check checkout..github/workflows/fips-compatibility.yml#L200-L201: add the setting to the FIPS runtime checkout..github/workflows/performance-regression.yml#L61-L62: add the setting to the benchmark checkout..github/workflows/postman-api-tests.yml#L65-L66: add the setting to the Newman checkout..github/workflows/pr-validation.yml#L58-L59: add the setting to the dead-code checkout..github/workflows/pr-validation.yml#L101-L102: add the setting to the link-check checkout..github/workflows/pr-validation.yml#L135-L136: add the setting to the dependency-validation checkout..github/workflows/release-sign.yml#L25-L26: add the setting to the release checkout.Based on learnings: every modified checkout in
.github/workflowsmust setpersist-credentials: false. As per path instructions: review workflow security best practices. These findings were also reported by previous reviews andzizmor.Suggested patch
- name: Checkout repository uses: actions/checkout@... + with: + persist-credentials: falseApply this setting to every listed checkout step.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/ci.yml around lines 62 - 63, Disable credential persistence on every listed actions/checkout step by adding persist-credentials: false: .github/workflows/ci.yml#L62-L63, .github/workflows/dependency-review.yml#L35-L36, .github/workflows/fips-compatibility.yml#L63-L64 and `#L200-L201`, .github/workflows/performance-regression.yml#L61-L62, .github/workflows/postman-api-tests.yml#L65-L66, .github/workflows/pr-validation.yml#L58-L59, `#L101-L102`, and `#L135-L136`, and .github/workflows/release-sign.yml#L25-L26.Sources: Path instructions, Learnings, Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In @.github/workflows/ci.yml:
- Around line 60-61: Resolve all expired egress-policy deferrals by validating
required endpoints and changing the Playwright policy at
.github/workflows/ci.yml lines 60-61, plus the dead-code, link-check, and
dependency-validation policies at .github/workflows/pr-validation.yml lines
55-56, 98-99, and 132-133, from audit to block. If any exception must remain,
document its owner and a new expiry at each affected site.
- Around line 62-63: Disable credential persistence on every listed
actions/checkout step by adding persist-credentials: false:
.github/workflows/ci.yml#L62-L63,
.github/workflows/dependency-review.yml#L35-L36,
.github/workflows/fips-compatibility.yml#L63-L64 and `#L200-L201`,
.github/workflows/performance-regression.yml#L61-L62,
.github/workflows/postman-api-tests.yml#L65-L66,
.github/workflows/pr-validation.yml#L58-L59, `#L101-L102`, and `#L135-L136`, and
.github/workflows/release-sign.yml#L25-L26.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 06c85bdb-4317-432d-b54e-5a2c0bf86260
📒 Files selected for processing (24)
.github/workflows/ci.yml.github/workflows/codecov.yml.github/workflows/codeql.yml.github/workflows/container-security.yml.github/workflows/coverage.yml.github/workflows/dependency-review.yml.github/workflows/docs.yml.github/workflows/fips-compatibility.yml.github/workflows/mutation-testing.yml.github/workflows/performance-regression.yml.github/workflows/postman-api-tests.yml.github/workflows/pr-title.yml.github/workflows/pr-validation.yml.github/workflows/publish-pypi.yml.github/workflows/python-compatibility.yml.github/workflows/qlty.yml.github/workflows/release-sign.yml.github/workflows/release.yml.github/workflows/reuse.yml.github/workflows/sbom.yml.github/workflows/scorecard.yml.github/workflows/security-analysis.yml.github/workflows/slsa-provenance.yml.github/workflows/sonarcloud.yml
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
|
There was a problem hiding this comment.
♻️ Duplicate comments (1)
.github/workflows/ci.yml (1)
60-61: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winResolve the expired egress-policy deferrals.
The listed jobs still use
egress-policy: auditafter June 30, 2026. Set each policy toblockafter validating required endpoints, or renew each exception with an owner and a new expiry.
.github/workflows/ci.yml#L60-L61: replace the expired Playwright deferral..github/workflows/pr-validation.yml#L55-L56: replace the expired dead-code deferral..github/workflows/pr-validation.yml#L98-L99: replace the expired link-check deferral..github/workflows/pr-validation.yml#L132-L133: replace the expired dependency-validation deferral.Suggested patch
- egress-policy: audit # TODO: switch to block after 2026-06-30 (compliance audit deferral) + egress-policy: blockAs per path instructions: review GitHub Actions workflows for security best practices and validate actual security configuration values.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/ci.yml around lines 60 - 61, Expired egress-policy audit deferrals remain in four workflow jobs; validate their required endpoints and set each policy to block. Update .github/workflows/ci.yml lines 60-61, .github/workflows/pr-validation.yml lines 55-56, 98-99, and 132-133; if any exception cannot be closed, renew it with an owner and new expiry instead.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In @.github/workflows/ci.yml:
- Around line 60-61: Expired egress-policy audit deferrals remain in four
workflow jobs; validate their required endpoints and set each policy to block.
Update .github/workflows/ci.yml lines 60-61, .github/workflows/pr-validation.yml
lines 55-56, 98-99, and 132-133; if any exception cannot be closed, renew it
with an owner and new expiry instead.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 0c7c016a-1d56-465c-b9f2-3d5caf511a13
📒 Files selected for processing (24)
.github/workflows/ci.yml.github/workflows/codecov.yml.github/workflows/codeql.yml.github/workflows/container-security.yml.github/workflows/coverage.yml.github/workflows/dependency-review.yml.github/workflows/docs.yml.github/workflows/fips-compatibility.yml.github/workflows/mutation-testing.yml.github/workflows/performance-regression.yml.github/workflows/postman-api-tests.yml.github/workflows/pr-title.yml.github/workflows/pr-validation.yml.github/workflows/publish-pypi.yml.github/workflows/python-compatibility.yml.github/workflows/qlty.yml.github/workflows/release-sign.yml.github/workflows/release.yml.github/workflows/reuse.yml.github/workflows/sbom.yml.github/workflows/scorecard.yml.github/workflows/security-analysis.yml.github/workflows/slsa-provenance.yml.github/workflows/sonarcloud.yml
✅ Performance Regression CheckStatus: PERFORMANCE OK
Threshold: +/-10% allowed regression ✅ Performance is within acceptable range. Additional Metrics
About Performance Regression TestingThis automated check compares
To reproduce locally: uv run --frozen python scripts/benchmark.py --iterations 1000 |
|



Summary
Why
Scheduled patch update, bug fixes and security patches with no API changes.
Changes
This PR contains the following updates:
74c633a→7d12f54v6.0.2→v6.1.0v6.4.0→v6.5.0v6.2.0→v6.3.0v8.1.0→v8.3.2v4.36.0→v4.37.4v2.8.0→v2.9.00916059→978f0e0v2.19.4→v2.20.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Impact
Acceptance Criteria
Testing
Notes
Release Notes
actions/checkout (actions/checkout)
v6.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v6 by @aiqiaoy in #2500https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: actions/checkout@v6.0.3...v6.1.0
v6.0.3Compare Source
actions/setup-node (actions/setup-node)
v6.5.0Compare Source
What's Changed
Full Changelog: actions/setup-node@v6.4.0...v6.5.0
actions/setup-python (actions/setup-python)
v6.3.0Compare Source
What's Changed
Enhancement
Dependency update
Documentation
New Contributors
Full Changelog: actions/setup-python@v6.2.0...v6.3.0
astral-sh/setup-uv (astral-sh/setup-uv)
v8.3.2: 🌈 update known checksums for 0.11.28Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.3.1: 🌈 update known checksums for 0.11.27Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
v8.3.0: 🌈 Support uv.lock as a version-file sourceCompare Source
Changes
Thanks to @somaz94 you can now use the pinned version of uv itself in
uv.lock. It gets picked up automatically.If you have pinned another version of uv in your
uv.lockyou can use the inputsversionorversion-sourceto override this.🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.2.0: 🌈 New inputsquietanddownload-from-astral-mirrorCompare Source
Changes
This release brings two new inputs and a few bug fixes.
New inputs
Lets talk about the new inputs first.
quiet
Pretty simple. It turns of all
infologgings. Useful if you use this in a composite action and are not interested in all the details.In the upcoming releases we will add log groups to fully implement support for "less noise"
download-from-astral-mirror
In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting
download-from-astral-mirror: falseallows you to do that.Bugfixes
When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.
We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.
🐛 Bug fixes
🚀 Enhancements
download-from-astral-mirrorinput @eifinger (#897)🧰 Maintenance
⬆️ Dependency updates
github/codeql-action (github/codeql-action)
v4.37.4Compare Source
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037v4.37.3Compare Source
No user facing changes.
v4.37.2Compare Source
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023v4.37.1Compare Source
v4.37.0Compare Source
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@​ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3Compare Source
No user facing changes.
v4.36.2Compare Source
v4.36.1Compare Source
No user facing changes.
lycheeverse/lychee-action (lycheeverse/lychee-action)
v2.9.0Compare Source
Summary
This release updates the default lychee version from
v0.23.0tov0.24.2.The main reason for this release is compatibility with the new lychee
0.24.xrelease artifacts. Starting with lycheev0.24.0, the archive layout changed, and thelycheebinary may now be packaged inside a subdirectory.lychee-actionnow detects that layout automatically, so users can upgrade without changing their workflows.If you use:
you will get the new version once the floating
v2tag has been updated. If you pin exact versions, update to:What’s new from lychee
v0.24.xBetter diagnostics
lychee now reports line and column numbers for detected links. This makes broken link reports easier to act on, especially in larger documentation sites or generated reports.
Text fragment checking
lychee can now check URL text fragments, such as links containing
#:~:text=.... This helps catch links that point to a valid page but no longer points to the intended highlighted text.Sitemap support
lychee can now read
sitemap.xmlinputs. This is useful for checking published websites or generated documentation sites where the sitemap is the easiest source of URLs to validate.JUnit output
lychee now supports JUnit output. This makes it easier to integrate link checking results with CI systems and test reporting tools that understand JUnit XML.
Redirect and remap visibility
lychee can now show redirects and remaps more clearly. This helps explain why a URL was checked as a different final URL and makes debugging link-checking behavior easier.
Multiple config files
lychee now supports multiple configuration files and expanded config handling. This is useful for repositories that split documentation, website, or package-specific link-checking settings.
Timeout handling
lychee can now accept timeouts explicitly. This gives users more control over how strict their link checks should be for flaky or slow endpoints.
Fixes and reliability improvements
Fixed lychee
0.24.xarchive compatibilitylychee-actionnow handles the new lychee release archive layout by detecting whether thelycheebinary is inside a subdirectory.This fixes compatibility with lychee
0.24.x.More stable installation path
The action now installs lychee into
$RUNNER_TEMP/lychee/bininstead of$HOME.This avoids failures on runners where
$HOMEdiffers between composite action steps. In those environments, the action could add one directory toPATHbut install the binary somewhere else, causinglychee: command not found.Safer automatic lychee version updates
The workflow that checks for new lychee releases now guards against
nullrelease versions before creating update PRs. This prevents invalid automated PRs such as “Update lycheeVersion to null”.Dependency updates
actions/checkoutfromv6tov7actions/cachefromv5tov6Upstream lychee changelog
For the full lychee changelog, see:
What’s Changed
$RUNNER_TEMPinstead of$HOMEby @mre in #338Full Changelog: lycheeverse/lychee-action@v2.8.0...v2.9.0
step-security/harden-runner (step-security/harden-runner)
v2.20.0Compare Source
What's Changed
Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.