chore(deps): bump the gh-actions-packages group across 1 directory with 9 updates#18173
chore(deps): bump the gh-actions-packages group across 1 directory with 9 updates#18173dependabot[bot] wants to merge 1 commit into
Conversation
…th 9 updates Bumps the gh-actions-packages group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [DataDog/commit-headless](https://github.com/datadog/commit-headless) | `2.0.3` | `3.3.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.1.0` | | [pypa/cibuildwheel](https://github.com/pypa/cibuildwheel) | `3.4.0` | `3.4.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `8.1.0` | `8.1.1` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` | | [actions/github-script](https://github.com/actions/github-script) | `8.0.0` | `9.0.0` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.0.0` | `8.1.0` | | [DataDog/system-tests/.github/workflows/system-tests.yml](https://github.com/datadog/system-tests) | `9777e7b43d6bca435236d9e231bf9bd42a6b6bb5` | `5e9a56359a711e590e43a825459a076c9543fa09` | Updates `DataDog/commit-headless` from 2.0.3 to 3.3.0 - [Changelog](https://github.com/DataDog/commit-headless/blob/main/CHANGELOG.md) - [Commits](DataDog/commit-headless@05d7b7e...567f7ee) Updates `docker/build-push-action` from 7.0.0 to 7.1.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@d08e5c3...bcafcac) Updates `pypa/cibuildwheel` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/pypa/cibuildwheel/releases) - [Changelog](https://github.com/pypa/cibuildwheel/blob/main/docs/changelog.md) - [Commits](pypa/cibuildwheel@ee02a15...8d2b08b) Updates `actions/upload-artifact` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@bbbca2d...043fb46) Updates `peter-evans/create-pull-request` from 8.1.0 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@c0f553f...5f6978f) Updates `actions/setup-node` from 6.3.0 to 6.4.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@53b8394...48b55a0) Updates `actions/github-script` from 8.0.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@ed59741...3a2844b) Updates `astral-sh/setup-uv` from 8.0.0 to 8.1.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@cec2083...0880764) Updates `DataDog/system-tests/.github/workflows/system-tests.yml` from 9777e7b43d6bca435236d9e231bf9bd42a6b6bb5 to 5e9a56359a711e590e43a825459a076c9543fa09 - [Changelog](https://github.com/DataDog/system-tests/blob/main/CHANGELOG.md) - [Commits](DataDog/system-tests@9777e7b...5e9a563) --- updated-dependencies: - dependency-name: DataDog/commit-headless dependency-version: 3.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gh-actions-packages - dependency-name: docker/build-push-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-actions-packages - dependency-name: pypa/cibuildwheel dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions-packages - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions-packages - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions-packages - dependency-name: actions/setup-node dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-actions-packages - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: gh-actions-packages - dependency-name: astral-sh/setup-uv dependency-version: 8.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-actions-packages - dependency-name: DataDog/system-tests/.github/workflows/system-tests.yml dependency-version: 5e9a56359a711e590e43a825459a076c9543fa09 dependency-type: direct:production dependency-group: gh-actions-packages ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codeowners resolved as |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b06a64b1bc
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
|
||
| - name: Push Commit | ||
| uses: DataDog/commit-headless@05d7b7ee023e2c7d01c47832d420c2503cd416f3 # action/v2.0.3 | ||
| uses: DataDog/commit-headless@567f7eedac58750aa573f48fd60cfe478abc65bd # action/v3.3.0 |
There was a problem hiding this comment.
Update backport push args for commit-headless v3
This bump switches DataDog/commit-headless to v3.3.0, but the backport step still depends on the old commits input (with.commits in the same step), which the v3 release removed for command: push (the action now auto-detects commits). In backport runs, this can either fail validation or change behavior by ignoring the explicit commit selection, causing the push phase to fail or push an unexpected commit range when branches are re-run/diverged.
Useful? React with 👍 / 👎.
Bumps the gh-actions-packages group with 9 updates in the / directory:
2.0.33.3.07.0.07.1.03.4.03.4.17.0.07.0.18.1.08.1.16.3.06.4.08.0.09.0.08.0.08.1.09777e7b43d6bca435236d9e231bf9bd42a6b6bb55e9a56359a711e590e43a825459a076c9543fa09Updates
DataDog/commit-headlessfrom 2.0.3 to 3.3.0Changelog
Sourced from DataDog/commit-headless's changelog.
Commits
567f7eeaction: feat: add --reset flag to push command (#55)e47356eaction: chore: swap CODEOWNERS from defunct commit-signing team (#56)92c4fe9action: chore: bump alecthomas/kong to v1.15.0ad36686action: fix: encode binary content over rest api with base64 instead of utf-8...8fca57daction: chore: bump deps, including Go toolchain (#51)3b0f460action: feat: use GraphQL when possible, fall back to REST if necessary (#46)3e3353faction: release!: v3 (#37)Updates
docker/build-push-actionfrom 7.0.0 to 7.1.0Release notes
Sourced from docker/build-push-action's releases.
Commits
bcafcacMerge pull request #1509 from docker/dependabot/npm_and_yarn/vite-7.3.218e62f1Merge pull request #1510 from docker/dependabot/npm_and_yarn/lodash-4.18.146580d2chore: update generated content3f80b25chore(deps): Bump lodash from 4.17.23 to 4.18.1efeec95Merge pull request #1505 from crazy-max/refactor-git-contextddf04b0Merge pull request #1511 from docker/dependabot/github_actions/crazy-max-dot-...db08d97chore(deps): Bump the crazy-max-dot-github group with 2 updatesef1fb96Merge pull request #1508 from docker/dependabot/github_actions/docker/login-a...2d8f2a1chore: update generated content919ac7bfix test since secrets are not written to temp path anymoreUpdates
pypa/cibuildwheelfrom 3.4.0 to 3.4.1Release notes
Sourced from pypa/cibuildwheel's releases.
Changelog
Sourced from pypa/cibuildwheel's changelog.
... (truncated)
Commits
8d2b08bBump version: v3.4.154b8a01deprecation: cp313t (#2787)097806btests: fully type the test suite (#2794)643b30cfix: avoid PYTHON_VERSION breaking uv if set (#2795)fffe2cachore(deps): bump j178/prek-action from 1.1.1 to 2.0.0 in the actions group (...6111948fix: zizmor "code injection via template expansion" (#2784)e478767chore: remove some string types (#2798)caf433b[Bot] Update dependencies (#2789)a257a3fchore: remove remaining future annotations (#2799)6df84dachore: some cleanup and checks (#2792)Updates
actions/upload-artifactfrom 7.0.0 to 7.0.1Release notes
Sourced from actions/upload-artifact's releases.
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)Updates
peter-evans/create-pull-requestfrom 8.1.0 to 8.1.1Release notes
Sourced from peter-evans/create-pull-request's releases.
Commits
5f6978ffix: retry post-creation API calls on 422 eventual consistency errors (#4356)d32e88dbuild(deps-dev): bump the npm group with 3 updates (#4349)8170bccbuild(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#4344)0041819build(deps): bump picomatch (#4339)b993918build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (#4334)36d7c84build(deps-dev): bump undici from 6.23.0 to 6.24.0 (#4328)a45d1fbbuild(deps): bump@tootallnate/onceand jest-environment-jsdom (#4323)3499eb6build(deps): bump the github-actions group with 2 updates (#4316)3f3b473build(deps): bump minimatch (#4311)6699836build(deps-dev): bump the npm group with 2 updates (#4305)Updates
actions/setup-nodefrom 6.3.0 to 6.4.0Release notes
Sourced from actions/setup-node's releases.
Commits
48b55a0Update Node.js versions in versions.yml and bump package to v6.4.0 (#1533)ab72c7eUpgrade@actionsdependencies (#1525)Updates
actions/github-scriptfrom 8.0.0 to 9.0.0Release notes
Sourced from actions/github-script's releases.
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionUpdates
astral-sh/setup-uvfrom 8.0.0 to 8.1.0Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
0880764fix: grant contents:write to validate-release job (#860)717d6abAdd a release-gate step to the release workflow (#859)5a911ebDraft commitish releases (#858)080c31eAdd action-types.yml to instructions (#857)b3e97d2Add input no-project in combination with activate-environment (#856)7dd591dchore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0 (#855)1541b77chore: update known checksums for 0.11.7 (#853)cdfb2eeRefactor version resolving (#852)cb84d12chore: update known checksums for 0.11.6 (#850)1912cc6chore: update known checksums for 0.11.5 (#845)Updates
DataDog/system-tests/.github/workflows/system-tests.ymlfrom 9777e7b43d6bca435236d9e231bf9bd42a6b6bb5 to 5e9a56359a711e590e43a825459a076c9543fa09Changelog
Sourced from DataDog/system-tests/.github/workflows/system-tests.yml's changelog.
... (truncated)
Commits
5e9a563[rust] update rust version to 1.87 to support new MSRV (#6970)ce3ecccExclude FEATURE_FLAGGING_AND_EXPERIMENTATION from dev (#6968)16a8e10[nodejs] activate Test_SecurityTestingHeaders from v5.104.0 (#6961)7e46500[python] activate capture expressions tests with version gate (DEBUG-5601) (#...165b9ab[python] enable global variable in span decoration probe (DEBUG-2708) (#6907)1efa532[rust] generate a dev version and install prod version from crates.io (#6764)ef0f748[nodejs] Response content headers always sent when Appsec is enabled (#6939)48202e4Separate OTLP Runtime Metrics Tests into 2 Tests (#6955)d57c05cAuto-activate ruby easy wins for apm-idm (#6658)cc1cb44Auto-activate ruby easy wins for asm-libraries (#6960)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions