ci: Bump the gh-actions group with 6 updates - #397
Merged
Oliver Borchert (borchero) merged 1 commit intoSep 1, 2026
Merged
Conversation
Bumps the gh-actions group with 6 updates: | Package | From | To | | --- | --- | --- | | [prefix-dev/setup-pixi](https://github.com/prefix-dev/setup-pixi) | `0.10.0` | `0.10.1` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.1` | `1.14.2` | | [release-drafter/release-drafter/autolabeler](https://github.com/release-drafter/release-drafter) | `7.6.0` | `7.7.0` | | [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) | `2.9.1` | `2.9.2` | | [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) | `7.6.0` | `7.7.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.3` | `4.37.8` | Updates `prefix-dev/setup-pixi` from 0.10.0 to 0.10.1 - [Release notes](https://github.com/prefix-dev/setup-pixi/releases) - [Commits](prefix-dev/setup-pixi@a09b624...f00437f) Updates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@ba38be9...dc37677) Updates `release-drafter/release-drafter/autolabeler` from 7.6.0 to 7.7.0 - [Release notes](https://github.com/release-drafter/release-drafter/releases) - [Commits](release-drafter/release-drafter@eada3c9...34d8067) Updates `Swatinem/rust-cache` from 2.9.1 to 2.9.2 - [Release notes](https://github.com/swatinem/rust-cache/releases) - [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md) - [Commits](Swatinem/rust-cache@c193711...6323deb) Updates `release-drafter/release-drafter` from 7.6.0 to 7.7.0 - [Release notes](https://github.com/release-drafter/release-drafter/releases) - [Commits](release-drafter/release-drafter@eada3c9...34d8067) Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...db488dd) --- updated-dependencies: - dependency-name: prefix-dev/setup-pixi dependency-version: 0.10.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions - dependency-name: release-drafter/release-drafter/autolabeler dependency-version: 7.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-actions - dependency-name: Swatinem/rust-cache dependency-version: 2.9.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions - dependency-name: release-drafter/release-drafter dependency-version: 7.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: gh-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: gh-actions ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
requested a review
from Oliver Borchert (borchero)
as a code owner
September 1, 2026 11:39
dependabot
Bot
requested review from
Andreas Albert (AndreasAlbertQC) and
Daniel Elsner (delsner)
as code owners
September 1, 2026 11:39
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
Pull request overview
This PR updates pinned GitHub Actions revisions in the repository’s workflows (the “gh-actions” dependabot group) to pick up upstream fixes and maintenance releases while keeping actions pinned to immutable SHAs.
Changes:
- Bump
prefix-dev/setup-pixifrom v0.10.0 → v0.10.1 across CI-related workflows. - Bump
Swatinem/rust-cachefrom v2.9.1 → v2.9.2 where Rust caching is used. - Bump release/publishing/security tooling actions (
release-drafter,gh-action-pypi-publish,codeql-action/upload-sarif) to their latest patch releases.
File summaries
| File | Description |
|---|---|
| .github/workflows/scorecard.yml | Updates github/codeql-action/upload-sarif pin to v4.37.8. |
| .github/workflows/release-drafter.yml | Updates release-drafter/release-drafter pin to v7.7.0. |
| .github/workflows/nightly.yml | Updates prefix-dev/setup-pixi pin to v0.10.1 for nightly runs. |
| .github/workflows/copilot-setup-steps.yml | Updates setup-pixi to v0.10.1 and rust-cache to v2.9.2. |
| .github/workflows/ci.yml | Updates setup-pixi to v0.10.1 and rust-cache to v2.9.2 in lint/unit-test jobs. |
| .github/workflows/chore.yml | Updates release-drafter autolabeler pin to v7.7.0. |
| .github/workflows/build.yml | Updates setup-pixi to v0.10.1 and gh-action-pypi-publish to v1.14.2. |
Review details
- Files reviewed: 7/7 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Oliver Borchert (borchero)
approved these changes
Sep 1, 2026
Oliver Borchert (borchero)
deleted the
dependabot/github_actions/gh-actions-28e16a6cae
branch
September 1, 2026 14:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the gh-actions group with 6 updates:
0.10.00.10.11.14.11.14.27.6.07.7.02.9.12.9.27.6.07.7.04.37.34.37.8Updates
prefix-dev/setup-pixifrom 0.10.0 to 0.10.1Release notes
Sourced from prefix-dev/setup-pixi's releases.
Commits
f00437fUpdate dependencies and add pnpm workspace configuration (#279)d0c199dchore(deps): bump the gh-actions group with 3 updates (#276)2253d9cchore(deps): bump the gh-actions group with 3 updates (#273)c5359a3chore(deps): bump the nodejs group with 6 updates (#274)Updates
pypa/gh-action-pypi-publishfrom 1.14.1 to 1.14.2Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
... (truncated)
Commits
dc37677Merge pull request #417 from trail-of-forks/ft/bump-deps8b2f234Bumppypi-attestationsandsigstore78b72dbMerge pull request #416 from takluyver/twine-v792f4d2aUpdate twine to v7Updates
release-drafter/release-drafter/autolabelerfrom 7.6.0 to 7.7.0Release notes
Sourced from release-drafter/release-drafter/autolabeler's releases.
Commits
34d8067chore: release v7.7.0cd773d2style: format and lint docs14d2d94feat: no new contributor template (#1687)94daa9echore: update references to branch master to main (#1686)b195e66ci: rely on conventional pr titles (#1685)246878abuild(deps-dev): bump postcss from 8.5.17 to 8.5.23 (#1683)c3acaa7fix: preserve proxy-aware fetch in octokit client (#1682)22a22c8chore(deps): update npm tool constraint to 12.0.1 (#1668)133e592chore(deps): update npm tool constraint to 11.18.0 (#1665)b806fc0chore(deps): update node.js to v24.18.0 (#1664)Updates
Swatinem/rust-cachefrom 2.9.1 to 2.9.2Release notes
Sourced from Swatinem/rust-cache's releases.
Changelog
Sourced from Swatinem/rust-cache's changelog.
... (truncated)
Commits
6323deb2.9.2b16e8d7bump rollup and rebuild3bf42acinvert target/profile check in cleanup6e5b278correctly sort and dedupe Rust versions5adc05fBump the actions group across 1 directory with 3 updates (#368)66b1e95fix: support Cargo V2 build dir layout (#371)72d126eMerge pull request #367 from Swatinem/dependabot/npm_and_yarn/dev-patch-2b495...48968d2Bump the dev-patch group with 2 updates9f151acupdate dependencies, rebuild0e24e5dBump the actions group across 1 directory with 6 updates (#364)Updates
release-drafter/release-drafterfrom 7.6.0 to 7.7.0Release notes
Sourced from release-drafter/release-drafter's releases.
Commits
34d8067chore: release v7.7.0cd773d2style: format and lint docs14d2d94feat: no new contributor template (#1687)94daa9echore: update references to branch master to main (#1686)b195e66ci: rely on conventional pr titles (#1685)246878abuild(deps-dev): bump postcss from 8.5.17 to 8.5.23 (#1683)c3acaa7fix: preserve proxy-aware fetch in octokit client (#1682)22a22c8chore(deps): update npm tool constraint to 12.0.1 (#1668)133e592chore(deps): update npm tool constraint to 11.18.0 (#1665)b806fc0chore(deps): update node.js to v24.18.0 (#1664)Updates
github/codeql-action/upload-sariffrom 4.37.3 to 4.37.8Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
db488ddMerge pull request #4102 from github/update-v4.37.8-9ee088e131845f5bUpdate changelog for v4.37.89ee088eMerge pull request #4080 from github/henrymercer/studious-giggle1aef003Address review feedback on overlay disk flags508b83bMerge main into overlay minimum disk feature branchd97b342Merge pull request #4098 from github/mbg/permission-error-as-configuration-error47fa622MakeEACCESaConfigurationError45693ccRefactorENOSPCcheck intoisDiskConfigurationErrorfunctionc2fd8f5Merge pull request #4081 from github/mario-campos/version-cache-to-diskc56f48eLog unexpected conditions during caching CLI outputDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions