chore(deps): bump the actions-deps group with 5 updates - #1865
Open
dependabot[bot] wants to merge 2 commits into
Open
chore(deps): bump the actions-deps group with 5 updates#1865dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps the actions-deps group with 5 updates: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.1` | `2.21.0` | | [sbt/setup-sbt](https://github.com/sbt/setup-sbt) | `1.5.6` | `1.5.7` | | [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | `9.6.0` | `10.0.0` | | [scala-steward-org/scala-steward-action](https://github.com/scala-steward-org/scala-steward-action) | `2.95.0` | `2.96.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.6` | `4.37.7` | Updates `step-security/harden-runner` from 2.20.1 to 2.21.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@b09bb98...05e3151) Updates `sbt/setup-sbt` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/sbt/setup-sbt/releases) - [Commits](sbt/setup-sbt@bfea3c5...8feba82) Updates `oxsecurity/megalinter` from 9.6.0 to 10.0.0 - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@ef3e84b...15e5b45) Updates `scala-steward-org/scala-steward-action` from 2.95.0 to 2.96.0 - [Release notes](https://github.com/scala-steward-org/scala-steward-action/releases) - [Commits](scala-steward-org/scala-steward-action@3e385b8...6162b21) Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@5595cca...ff2f1c6) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: sbt/setup-sbt dependency-version: 1.5.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: oxsecurity/megalinter dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: scala-steward-org/scala-steward-action dependency-version: 2.96.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Contributor
Contributor
Unit Test Results113 files ±0 113 suites ±0 1h 2m 15s ⏱️ + 2m 50s For more details on these failures, see this check. Results for commit a0af3dc. ± Comparison against base commit df5d48d. ♻️ This comment has been updated with latest results. |
patextreme
approved these changes
Aug 19, 2026
patextreme
left a comment
Contributor
There was a problem hiding this comment.
dep-bump-merger auto-approval: diff judged to be a purely version-only dependency bump by the dep-bump-merger skill rubric.
|
Contributor
|
dep-bump-merger could not auto-merge this PR. Reason: checks not green: check Build and unit tests: FAILURE |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the actions-deps group with 5 updates:
2.20.12.21.01.5.61.5.79.6.010.0.02.95.02.96.04.37.64.37.7Updates
step-security/harden-runnerfrom 2.20.1 to 2.21.0Release notes
Sourced from step-security/harden-runner's releases.
Commits
05e3151Merge pull request #684 from step-security/rc-420f37afafix: ignore denied-endpoints on non-enterprise tier93b58eefix: resolve cache host read-first and never downgrade egress policye7399ddfix: align deny-list mode detection with agent and log when both endpoint inp...c16689ftest: add denied_endpoints to Configuration fixtures and cover deny-list merge40b99cfMerge pull request #682 from rohan-stepsecurity/rp/feat/codebuild-self-v2fedec02Merge branch 'rc-42' into rp/feat/codebuild-self-v25361fb1feat: add build artifacts286474ffeat: Support Bravo agent install on CodeBuild runners051ec05Merge pull request #683 from h0x0er/jatin/deny-listUpdates
sbt/setup-sbtfrom 1.5.6 to 1.5.7Release notes
Sourced from sbt/setup-sbt's releases.
Commits
8feba82Merge pull request #123 from scala-steward/update/sbt-2.0.6d54acfdRegenerated action.yml85ff7eaUpdate sbt to 2.0.649d5174Merge pull request #122 from scala-steward/update/sbt-2.0.5793d186Regenerated action.yml14cf55aUpdate sbt to 2.0.5Updates
oxsecurity/megalinterfrom 9.6.0 to 10.0.0Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
15e5b45Release MegaLinter v10.0.0861855amegalinter-setup skill: enforce ghcr.io image references in upgrade mode (#8694)572dc81[automation] Auto-update linters version, help and documentation (#8695)2f62977Refresh OX Security PR comment banner and home page banner (#8692)3b8c632chore(deps): update dependency mongodb/kingfisher to v1.112.0 (#8691)7efac01chore(deps): update mstruebing/editorconfig-checker docker tag to v3.10.0 (#8...8cea326Make custom flavor generator output pass MegaLinter (#8686)a057dcb[automation] Auto-update linters version, help and documentation (#8690)6dece72chore(deps): update dependency virtualenv to v21.7.2 (#8683)08a6d16docs: highlight impactful contributors in the Special thanks section (#8688)Updates
scala-steward-org/scala-steward-actionfrom 2.95.0 to 2.96.0Release notes
Sourced from scala-steward-org/scala-steward-action's releases.
Commits
6162b21Release v2.96.09d2a051Merge pull request #854 from exoego/build/tsdown-oxlint-ts7b76217cMerge branch 'master' into build/tsdown-oxlint-ts7d9ac530Merge pull request #855 from exoego/fix/restore-dist-gitignore9589833Restore the dist entry in .gitignore2f2b578build: adopt TypeScript 7 with tsdown, oxlint and oxfmtUpdates
github/codeql-action/upload-sariffrom 4.37.6 to 4.37.7Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
ff2f1c6Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8951a133Update changelog for v4.37.7be7a3dbMerge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334Merge pull request #4086 from github/mbg/thread-action-state-to-codeqlb4d8a54Rebuildab5db25Bump the npm-minor group across 1 directory with 8 updates38055a3DroploggerfromdatabaseInitClusterin interface1f87aedMerge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3dc1b98aMakeloggeravailable togetCodeQLForCmd6f0220eMerge pull request #4084 from github/navntoft/bump-undiciDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions