dependabot[bot]
6608a9f05e
ci(deps): bump the github-actions group across 1 directory with 11 updates ( #763 )
...
Bumps the github-actions group with 11 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout ) | `6` | `7` |
| [actions/setup-python](https://github.com/actions/setup-python ) | `6.2.0` | `7.0.0` |
| [actions/setup-java](https://github.com/actions/setup-java ) | `5.2.0` | `5.6.0` |
| [actions/setup-go](https://github.com/actions/setup-go ) | `6.4.0` | `7.0.0` |
| [actions/setup-dotnet](https://github.com/actions/setup-dotnet ) | `5.2.0` | `6.0.0` |
| [actions/setup-node](https://github.com/actions/setup-node ) | `6.4.0` | `7.0.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action ) | `4.35.2` | `4.37.3` |
| [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) | `1.306.0` | `1.321.0` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action ) | `4.35.2` | `4.37.3` |
| [MarcoIeni/release-plz-action](https://github.com/marcoieni/release-plz-action ) | `0.5.128` | `0.5.131` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) | `4.35.2` | `4.37.3` |
Updates `actions/checkout` from 6 to 7
- [Release notes](https://github.com/actions/checkout/releases )
- [Commits](https://github.com/actions/checkout/compare/v6...v7 )
Updates `actions/setup-python` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](a309ff8b42...5fda3b95a4 )
Updates `actions/setup-java` from 5.2.0 to 5.6.0
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](be666c2fcd...03ad4de099 )
Updates `actions/setup-go` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](4a3601121d...b7ad1dad31 )
Updates `actions/setup-dotnet` from 5.2.0 to 6.0.0
- [Release notes](https://github.com/actions/setup-dotnet/releases )
- [Commits](c2fa09f4bd...a98b56852c )
Updates `actions/setup-node` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](48b55a011b...8207627860 )
Updates `github/codeql-action/init` from 4.35.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](95e58e9a2c...e4fba868fa )
Updates `ruby/setup-ruby` from 1.306.0 to 1.321.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](c4e5b13161...95ef2b042f )
Updates `github/codeql-action/analyze` from 4.35.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](95e58e9a2c...e4fba868fa )
Updates `MarcoIeni/release-plz-action` from 0.5.128 to 0.5.131
- [Release notes](https://github.com/marcoieni/release-plz-action/releases )
- [Commits](1528104d2c...2eb1d8bcb7 )
Updates `github/codeql-action/upload-sarif` from 4.35.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](95e58e9a2c...e4fba868fa )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-dotnet
dependency-version: 5.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/setup-go
dependency-version: 6.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/setup-java
dependency-version: 5.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/setup-node
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-python
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: MarcoIeni/release-plz-action
dependency-version: 0.5.131
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: ruby/setup-ruby
dependency-version: 1.318.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 18:19:20 -07:00
Anand Krishnamoorthi
c312e30372
build(deps): update all Rust dependencies and fix lockfile refresh workflow ( #704 )
...
* build(deps): update all Rust dependencies to latest versions
Bulk-update all Cargo.lock files across the workspace and bindings
to their latest compatible versions. This supersedes the individual
per-directory dependabot PRs (#678-#682) that fail CI due to version
skew when only one lockfile is updated.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
* ci: refresh ALL Cargo lockfiles on dependabot PRs
Dependabot security updates bypass the grouped-updates config and
create per-directory PRs (one per Cargo.lock). This causes version
skew — e.g. rand gets bumped in bindings/ruby but stays old elsewhere,
breaking the build.
Fix by unconditionally refreshing all lockfiles whenever any Cargo
manifest or lockfile changes, rather than only the affected directory.
Also harden the workflow against expression injection:
- Move head.ref and base_ref to env vars (not inline ${{ }})
- Validate refs via git check-ref-format --branch
- Validate SHA format (hex, 40 chars) before use
- Fetch base branch by ref (not bare SHA) for reliable diffing
- Add security boundary comment on untrusted code checkout
- Add version comment on pinned checkout action SHA
Ref: https://github.com/dependabot/dependabot-core/issues/7547
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-05-04 15:20:05 -05:00
Anand Krishnamoorthi
f9d54cd436
ci(dependabot): fix cargo config quoting ( #632 )
2026-03-26 11:18:09 -05:00
Anand Krishnamoorthi
f69974dc1b
ci(dependabot): fix cargo workspace updates and refresh lockfiles ( #629 )
...
* ci(dependabot): fix cargo workspace updates and refresh lockfiles
Remove nested Cargo workspace members from Dependabot's cargo directories to avoid manifest resolution failures during grouped updates.
Add a Dependabot-only workflow that refreshes affected Cargo lockfiles, including the no_std target-specific resolution path, so CI can continue enforcing --locked and --frozen builds.
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com >
* ci(dependabot): address workflow review comments
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com >
* ci(dependabot): address workflow permission and toolchain comments
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com >
* ci(dependabot): stage no-std lockfile refresh
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com >
* ci(dependabot): harden refresh workflow
* ci(dependabot): refine workflow gating and staging
* ci(dependabot): harden workflow git operations
---------
Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com >
2026-03-25 16:58:29 -05:00