Skip to content

chore(github-actions): update ppat/github-workflows (v4.4.0 -> v5.0.0) - #876

Open
ppat-self-hosted-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/ppat-github-workflows-5.x
Open

chore(github-actions): update ppat/github-workflows (v4.4.0 -> v5.0.0)#876
ppat-self-hosted-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/ppat-github-workflows-5.x

Conversation

@ppat-self-hosted-renovate-bot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
ppat/github-workflows action major v4.4.0v5.0.0

Release Notes

ppat/github-workflows (ppat/github-workflows)

v5.0.0

Compare Source

🧹 Miscellaneous
  • dev-tools: update alessandrojcm/commitlint-pre-commit-hook (non-major) (#​530) (b0ec9b0)
  • dev-tools: update aquaproj/aqua (v2.59.0 -> v2.59.1) (#​483) (c6ebcbf)
  • dev-tools: update aquaproj/aqua (v2.59.1 -> v2.60.0) (#​501) (df84b91)
  • dev-tools: update aquaproj/aqua (v2.60.0 -> v2.60.1) (#​502) (748c60b)
  • dev-tools: update astral-sh/uv (0.11.16 -> 0.11.17) (#​489) (db1f79a)
  • dev-tools: update astral-sh/uv (0.11.17 -> 0.11.18) (#​490) (7c8f07e)
  • dev-tools: update astral-sh/uv (0.11.18 -> 0.11.19) (#​493) (e468140)
  • dev-tools: update astral-sh/uv (0.11.19 -> 0.11.21) (#​498) (6a66cc8)
  • dev-tools: update astral-sh/uv (0.11.21 -> 0.11.22) (#​503) (91cf84e)
  • dev-tools: update astral-sh/uv (github-actions dependency) (0.11.22 -> 0.11.23) (#​504) (957090e)
  • dev-tools: update kindest/node (v1.35.1 -> v1.35.5) (#​492) (56675fb)
  • dev-tools: update kubernetes (v1.35.6 -> v1.36.0) (#​506) (6605eee)
  • dev-tools: update kubernetes-sigs/kind (v0.31.0 -> v0.32.0) (#​495) (506c2bf)
  • dev-tools: update kubernetes/kubernetes (v1.35.1 -> v1.35.5) (#​484) (75915c5)
  • dev-tools: update kubernetes/kubernetes (v1.35.5 -> v1.35.6) (#​499) (d78fe6f)
  • dev-tools: update lockfile bun (#​488) (292c6cd)
  • dev-tools: update lockfile bun (#​500) (bed5d4a)
  • dev-tools: update lockfile bun (#​533) (89a1813)
  • dev-tools: update renovatebot/renovate (43.195.0 -> 43.227.1) (#​486) (196a343)
  • dev-tools: update renovatebot/renovate (github-actions dependency) (43.227.1 -> 43.233.3) (#​507) (57a73d2)
  • dev-tools: update terraform-linters/tflint (v0.62.1 -> v0.63.1) (#​496) (cf96372)
  • github-actions: update actions/checkout (v4 -> v7.0.0) and actions/create-github-app-token (v2 -> v3.2.0) (#​514) (08975ad)
  • github-actions: update renovatebot/github-action (v44.2.6 -> v46.1.17) (#​515) (9e6b7e6)
  • release: set next release version (5bb10c9)
✨ Features
  • dev-tools: update kindest/node (v1.35.5 -> v1.36.1) (#​531) (e1784d7)
  • github-actions: add zizmor static analysis security gate (#​535) (7926396)
  • github-actions: update docker/build-push-action (v6.18.0 -> v7.2.0) (#​521) (8a94a05)
  • github-actions: update docker/login-action (v3.6.0 -> v4.2.0) (#​522) (47c1dd4)
  • github-actions: update docker/metadata-action (v5.10.0 -> v6.1.0) (#​523) (3286626)
  • github-actions: update docker/setup-buildx-action (v3.11.1 -> v4.1.0) (#​524) (fea51eb)
  • github-actions: update docker/setup-qemu-action (v3.7.0 -> v4.1.0) (#​525) (dc53535)
  • github-actions: update googleapis/release-please-action (v4.4.0 -> v5.0.0) (#​526) (0f16be6)
  • github-actions: update peter-evans/dockerhub-description (v4.0.2 -> v5.0.0) (#​527) (bc815ad)
  • github-actions: update ppat/homelab-ops-actions (v1.0.4 -> v2.0.0) (#​511) (1a578a6)
  • github-actions: update tailscale/github-action (v3.3.0 -> v4.1.2) (#​528) (495b096)
  • github-actions: update tj-actions/changed-files (v46.0.5 -> v47.0.6) (#​529) (fd206fe)
  • github-actions: update trusted github-actions (#​516) (d5cd138)
  • update commitlint packages (#​494) (82fa85b)
  • update commitlint packages (21.0.2 -> 21.1.0) (#​520) (f74959b)
  • update commitlint packages (21.1.0 -> 21.2.0) (#​536) (d2e6b84)
  • update conventional-changelog-conventionalcommits (9.3.1 -> 10.2.0) (#​532) (e4c8986)
🚀 Enhancements + Bug Fixes

Configuration

📅 Schedule: (in timezone US/Eastern)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

ppat added a commit that referenced this pull request Aug 20, 2026
#877)

* chore(github-actions): update ppat/github-workflows (v4.4.0 -> v5.0.1)

Bumps every ppat/github-workflows ref (renovate.yaml, lint.yaml x11,
release.yaml x2) to the v5.0.1 tag. No workflow_call.inputs used by this
repo were renamed or removed between v4.4.0 and v5.0.1.

Supersedes #876 (the Renovate PR proposing v4.4.0 -> v5.0.0), which is
left untouched.

* ci(github-actions): fix shellcheck findings surfaced by actionlint -shellcheck

v5's lint-github-actions.yaml turns on actionlint's shellcheck integration
(actionlint v1.7.4 -> v1.7.12), which was previously inert. That surfaces
the first real shellcheck pass over this repo's own workflow `run:`
blocks (lint.yaml, release.yaml) - actionlint appends --norc, so
.shellcheckrc does not filter these.

18 findings total, all fixed by quoting or declare/assign-separation,
never by changing what arguments a command receives:

- lint.yaml (terraform-dirs job): 1x SC2086 on `>> $GITHUB_OUTPUT`. This
  is a redirection target, not argv, so bash never word-splits it -
  quoting is behavior-preserving.
- release.yaml (Login to Coder step): 4x SC2086 on `${CODER_URL}`
  (curl/coder login args) + 2x SC2155 on `export VAR=$(curl ...)`.
  CODER_URL is a single secret URL, never a list, so quoting cannot
  change argv count; declare/assign-separation only changes when the
  subshell's exit status would be masked, and nothing here checks it.
- release.yaml (Publish template step): 8x SC2086 on
  ${TEMPLATE_DIR}/${TEMPLATE_VERSION}/${TEMPLATE_NAME}/${WORKSPACE_IMAGE}
  (all scalars, never space-separated lists) + 3x SC2155 on `export
  VAR=$(...)`. Verified with an argv-echoing stub that `coder template
  push` and the `curl`/jq calls receive byte-identical argv before and
  after, for representative values.

`--var test_mode=${TEST_MODE}` was left unquoted deliberately: shellcheck
does not flag it (TEST_MODE is only ever assigned the literal `true` or
`false`), and quoting it would be an unrequested change with no finding
behind it.

No inline `# shellcheck disable=` was needed: none of this repo's local
run: blocks build an argv list from a space-separated variable the way
upstream's ${ACTIONS_FILES}/${SHELLSCRIPT_FILES}-style callers do, so
none of the findings fall under the word-splitting-is-intentional
carve-out.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants