Bump the monthly-batch group with 5 updates - #592
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the monthly-batch group with 5 updates: | Package | From | To | | --- | --- | --- | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.8` | `4.38.2` | | [actions/setup-java](https://github.com/actions/setup-java) | `6.0.0` | `6.0.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.8` | `4.38.2` | | [github/gh-aw/actions/setup-cli](https://github.com/github/gh-aw) | `0.87.3` | `0.89.21` | | [github/gh-aw/actions/setup](https://github.com/github/gh-aw) | `9a2569183fd5ca0d10c2fa359359b47b4c1b2a96` | `1f75ecc37b268e2a6a94d9f1ad0163e7db6fca89` | Updates `github/codeql-action/init` from 4.37.8 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...2892aa5) Updates `actions/setup-java` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@dd06d9c...de7274f) Updates `github/codeql-action/analyze` from 4.37.8 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...2892aa5) Updates `github/gh-aw/actions/setup-cli` from 0.87.3 to 0.89.21 - [Release notes](https://github.com/github/gh-aw/releases) - [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md) - [Commits](github/gh-aw@466b8ad...c353937) Updates `github/gh-aw/actions/setup` from 9a2569183fd5ca0d10c2fa359359b47b4c1b2a96 to 1f75ecc37b268e2a6a94d9f1ad0163e7db6fca89 - [Release notes](https://github.com/github/gh-aw/releases) - [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md) - [Commits](github/gh-aw@9a25691...1f75ecc) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: monthly-batch - dependency-name: actions/setup-java dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: monthly-batch - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: monthly-batch - dependency-name: github/gh-aw/actions/setup-cli dependency-version: 0.89.21 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: monthly-batch - dependency-name: github/gh-aw/actions/setup dependency-version: 1f75ecc37b268e2a6a94d9f1ad0163e7db6fca89 dependency-type: direct:production dependency-group: monthly-batch ... Signed-off-by: dependabot[bot] <support@github.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the monthly-batch group with 5 updates:
4.37.84.38.26.0.06.0.14.37.84.38.20.87.30.89.219a2569183fd5ca0d10c2fa359359b47b4c1b2a961f75ecc37b268e2a6a94d9f1ad0163e7db6fca89Updates
github/codeql-action/initfrom 4.37.8 to 4.38.2Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
actions/setup-javafrom 6.0.0 to 6.0.1Release notes
Sourced from actions/setup-java's releases.
Commits
de7274fAvoid macOS GPG socket overflow on long runner paths (#1266)134912aFix import-safe checks when scripts are run from a path with symlinks (#1265)0781fc6Fix alpine failures by switching default back to only warn on verification fa...4889c4aFix Temurin EA E2E signature verification (#1260)8fd3240[WIP] Fix failing GitHub Actions job for temurin 17 (#1259)2732291chore(deps-dev): update eslint and globals (#1256)1a8f22bchore: streamline Dependabot updates (#1255)85030b7docs: complete v6 release highlights (#1254)Updates
github/codeql-action/analyzefrom 4.37.8 to 4.38.2Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
github/gh-aw/actions/setup-clifrom 0.87.3 to 0.89.21Release notes
Sourced from github/gh-aw/actions/setup-cli's releases.
... (truncated)
Changelog
Sourced from github/gh-aw/actions/setup-cli's changelog.
... (truncated)
Commits
c353937Report gateway steering events in audit output (#62943)7f9138dFix cancelled daily AIC component accounting (#62984)9ef513cSupport native web-search on the Copilot engine (#62957)73bc75dDocument stale agentic workflow lock detection (#62947)d424601Allow${{ inputs.* }}expressions insafe-outputs.failure-issue-repofor ...403aefeAdd Agent of the Day blog post for 2026-09-23: Daily Caveman Optimizer (#62969)bd6aa2eUse portable path for OTLP helper guidance (#62940)7334b08[actions] Update GitHub Actions versions - 2026-09-23 (#62899)273c72cUpdate package specifications for parser, repoutil, semverutil, sliceutil (#6...606cfabdocs: unbloat repo assist example (#62822)Updates
github/gh-aw/actions/setupfrom 9a2569183fd5ca0d10c2fa359359b47b4c1b2a96 to 1f75ecc37b268e2a6a94d9f1ad0163e7db6fca89Changelog
Sourced from github/gh-aw/actions/setup's changelog.
... (truncated)
Commits
1f75eccMove ledger compaction into Agentic Maintenance (untrusted plan job / trusted...55f35d4docs: unbloat multi-repo gallery page (#64639)f7e82bfdocs: document missing CLI flags and json-schema command in cli.md (#64596)057d2c9Support AWF task-level model routing in the Copilot engine (#64593)856e7faSurface threat-detection outcomes in usage artifacts and audit reports (#64506)03debd3Honorruntimes.nodeaction override in threat-detection and evals Setup Nod...f346220Surface ledger transactions in conclusion usage and audit results (#64509)a98c5d2Update stale CLI and scanner image pins (#64500)c010c72Remove dynamic eval from update-release tests (#64502)f7443f4Recognize consequence-based empty-catch rationale (#64501)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions