Skip to content

chore: bump nginx/angie/action/linter pins (2026-08-31) - #116

Open
eilandert wants to merge 1 commit into
mainfrom
bump/versions-20260831
Open

chore: bump nginx/angie/action/linter pins (2026-08-31)#116
eilandert wants to merge 1 commit into
mainfrom
bump/versions-20260831

Conversation

@eilandert

Copy link
Copy Markdown
Member

Automated weekly version check (ci/tools/bump-versions.sh). Review the diff and let required CI checks gate the merge.

Automated weekly version check (ci/tools/bump-versions.sh).
@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 26b4c8b2-8ad4-4cf0-b15a-59a9de543ad1

📥 Commits

Reviewing files that changed from the base of the PR and between 683ddb2 and f0df819.

📒 Files selected for processing (11)
  • .github/versions.env
  • .github/workflows/asan.yml
  • .github/workflows/build-test.yml
  • .github/workflows/bump.yml
  • .github/workflows/ci-deep.yml
  • .github/workflows/codeql.yml
  • .github/workflows/fuzzing.yml
  • .github/workflows/lint.yml
  • .github/workflows/security-scanners.yml
  • .github/workflows/valgrind.yml
  • .github/workflows/windows-build.yml

Included review availability: Your plan provides up to 5 included reviews per hour; 3 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: Build&Test / C line coverage
  • GitHub Check: Fuzzing / Fuzz regression (120s scan + 60s xff)
  • GitHub Check: ASan soak / ASan/UBSan soak (60s)
  • GitHub Check: Build&Test / ASan and UBSan
  • GitHub Check: Build&Test / Test::Nginx
  • GitHub Check: Valgrind / Memcheck lite (60s soak)
  • GitHub Check: MinGW-w64 x64 dynamic build and runtime
🔇 Additional comments (12)
.github/versions.env (2)

26-27: LGTM!


38-39: LGTM!

.github/workflows/asan.yml (1)

25-25: LGTM!

Also applies to: 52-52

.github/workflows/build-test.yml (1)

25-25: LGTM!

Also applies to: 95-95, 195-195, 250-250, 303-303, 329-329, 392-392, 451-451, 548-548

.github/workflows/bump.yml (1)

36-36: LGTM!

Also applies to: 76-76

.github/workflows/valgrind.yml (1)

10-10: LGTM!

Also applies to: 33-33

.github/workflows/windows-build.yml (1)

34-34: LGTM!

Also applies to: 205-205

.github/workflows/ci-deep.yml (1)

35-41: LGTM!

Also applies to: 83-83, 208-208, 335-335, 377-377, 419-419

.github/workflows/codeql.yml (1)

34-34: LGTM!

Also applies to: 49-49, 75-75

.github/workflows/fuzzing.yml (1)

18-19: LGTM!

Also applies to: 42-42

.github/workflows/lint.yml (1)

22-22: LGTM!

.github/workflows/security-scanners.yml (1)

9-15: LGTM!

Also applies to: 35-35


Summary by CodeRabbit

  • Chores
    • Updated supported NGINX and Angie versions to newer releases.
    • Improved the reliability and consistency of automated builds, testing, security scanning, and Windows validation.
    • Refreshed code-quality and security analysis tooling used during automated checks.
    • Standardized source retrieval and artifact handling across CI workflows for more reproducible results.

Walkthrough

Changes

The CI configuration updates pinned NGINX and Angie releases. GitHub Actions checkout references now use v5.1.0. CodeQL actions use v4.37.9, and Semgrep uses 1.175.0.

CI dependency pins

Layer / File(s) Summary
NGINX and Angie release pins
.github/versions.env
The pinned NGINX and Angie versions now use updated SHA256 digests.
Checkout action pins
.github/workflows/*.yml
Workflow checkout steps and documentation now reference the pinned actions/checkout v5.1.0 commit.
Security tool pins
.github/workflows/ci-deep.yml, .github/workflows/security-scanners.yml, .github/workflows/codeql.yml
Semgrep updates to 1.175.0. CodeQL initialization and analysis update to v4.37.9 commits.

Merge Risk: ⚪ Minimal · up to f0df8

This PR updates pinned CI tool and action versions without changing product runtime behavior; no actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the version-pin updates for NGINX, Angie, GitHub Actions, and linters. It matches the changeset and includes the update date.
Description check ✅ Passed The description identifies the automated weekly version-check process and directs reviewers to validate the diff and CI results. It is directly related to the changeset.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bump/versions-20260831
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch bump/versions-20260831

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant