Thanks to visit codestin.com
Credit goes to github.com

Skip to content

chore(deps): bump the github-actions group with 2 updates - #159

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-e74cfd82ff
Open

chore(deps): bump the github-actions group with 2 updates#159
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-e74cfd82ff

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates: NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml and NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml.

Updates NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml from c078ddcbcfb771f56a334184b7b6399cfd9c39c4 to c113d4c9b0265bcefeb756489da9a06c8c1b9e5f

Changelog

Sourced from NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml's changelog.

Changelog

Unreleased

  • Provider v0.1.5-nddev.130 is .129 rebuilt on the raised AWS SDK minor and patch releases. No provider behaviour changes; the version moves because the binary does, and the release manifest records which source commit and which bytes. Root go.mod changes cannot ship under the previous derivative version - that is how two hosts once ran different binaries under one name.

  • Observer schema 17 labels the oldest queued waiter per scale set and the oldest assigned waiter with journal job_id. lifecycle_queued_delivery_stall, queue_wait_slow_burn and lifecycle_assigned_stall aggregate max by (job_id, scale_set) so {subject} is that GUID. A cancelled or advanced waiter dropping out of the gauge is a new incident, not a quieter reading of the previous one. The global Telegram template is unchanged. queue_started_wait_slow_burn still names the scale set. Deploy the observer before reconciling OpenObserve: the assigned stall stream is new.

  • GARM v0.2.1-nddev.94 binds stale scale-set job mutation to exact identity: check-run external_id, workflow_job.check_run_url, repository, exact attempt, numeric job ID and source SHA. A job name is never terminal proof. Missing fields, incomplete pagination, omitted or changing page totals, another attempt, a non-Actions producer and no exact match retain the intent. check_run_url and the check URL must share an https origin and repos/{owner}/{repo}/check-runs/{id} path; a missing check URL or a foreign host does not bind. GitHub 404 retains the intent and does not start the 15-minute access-refusal backoff used for 403/429. Scaling uses the latest MESSAGE statistics.TotalAssignedJobs; idle retirement requires a recent MESSAGE with messageID > 0 and re-checks that observation before RemoveRunner. Session-create zeros and 202/nil long-polls are not idle evidence. Start failure deletes the new message session and cancels the listener context. Listener JobCompleted with an empty runner name ends a delivery reservation and is not a REST workflow-job terminal; REST still-queued exact identity can clear that tombstone. A later same-run/name GUID is not aliased onto it. JobStarted of another GUID does not delete or rename an assigned waiter or copy its FIFO clock. A request-less JobAssigned yields occupancy only when a dispatchable JobAvailable would actually fit after that yield, including while that reservation is still unexpired; a quota-blocked available job does not evict a useful foreign bootstrap reservation. The original waiter and FIFO stay in the journal. Same-GUID JobAvailable keeps occupancy. An official build preserves the source tree when container stop is not proven. A replayed MESSAGE with the same session and messageID does not refresh idle-retirement freshness. A late message from a replaced session does not overwrite current demand. golang.org/x/text is v0.39.0. The .92 and .93 patches are unchanged. This is a source/artifact candidate, not a fleet rollout.

... (truncated)

Commits
  • c113d4c Merge pull request #457 from NDDev-OpenNetwork/fix/reconcile-orphaned-queue-i...
  • dbaa4ac fix: reconcile terminal queue orphans and preserve workers during maintenance
  • 3d8b898 build: update the provider network dependency
  • 22bde32 Merge pull request #456 from NDDev-OpenNetwork/fix/refresh-incomplete-incus-i...
  • 966d1b4 chore: record the reproducible provider 132 release and rollout contract
  • 7a82d68 fix(provider): refresh a complete inventory snapshot before retrying
  • deb7eb1 fix(provider): refresh incomplete inventory after lease transitions
  • 68264ad Merge pull request #455 from NDDev-OpenNetwork/chore/ignore-feedback-python-c...
  • e00edfa chore(git): ignore generated feedback Python caches
  • 2e07dce Merge pull request #454 from NDDev-OpenNetwork/chore/benchmark-dependency-con...
  • Additional commits viewable in compare view

Updates NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml from bc9c7919de1c39d947a8709a92856925051bae05 to a624689c897c5f4733cf475159e77bba3a2b98c7

Changelog

Sourced from NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml's changelog.

Changelog

This file is a release ledger: every heading below is a real release, and scripts/check_release_ledger.py enforces that in both directions.

The project follows Semantic Versioning.

[Unreleased]

  • Re-verify GitLab Free and Open Source allowances against current primary sources, with separate review deadlines and explicit eligibility conditions.

  • Preserve complete redacted private security evidence in a bounded, checksummed run-log ZIP when artifact upload fails. Scanner enforcement and failed fallback remain blocking; no new token permission or external storage is required.

  • Add optional check_name to the private-free security bundle so callers can retain an existing required check identity when migrating away from SARIF publication, with all four scanners and evidence artifacts preserved.

  • Synchronize pins by catalog action family, preserving independent subpath actions and reusable workflows in the same repository. Apply the reviewed dependency updates from #92 with matching catalog and transitive-image records; historical evidence digests are no longer rewritten by an unrelated action update.

  • Stop treating the publisher as an Enterprise Cloud buyer of Code Security, Secret Protection and Code Quality. Paid programmes stay explicitly selectable; public CodeQL, SARIF, Scorecard and attestations stay. Private repositories without those purchases use the private-free programme. A live GitHub plan belongs to one organization and is not copied between accounts. Consumer adoption resolves the programme from the immutable release being pinned, not from main. Private attestations stay an Enterprise Cloud plan gate, independent of the three add-ons.

  • Dependabot catalog convergence commits only catalog and generated docs, so the default GITHUB_TOKEN can push without workflows permission. Catalog-only follows the unique workflow pin per action and fails closed when identities are mixed, so the catalog cannot describe a pin the tree does not share. Ordinary merge in this repository does not require a general CI status check; ci-gate stays truthful advisory evidence. Authored skill metadata: mappings stay mappings.

  • Re-verify four vendor allowance records with staggered review dates, correct Ubicloud's monthly credit and Harness's conditional CI credit semantics, and align the disclosed Checkov image tag with the existing pinned action.

  • Publish unsuccessful completed self-workflow attempts as unassigned, repository-local CI evidence; preserve actual conclusions and exact attempts.

  • Accept exact matching development-commit comments and correct nested action pin validation and container whitespace rejection. Keep registrations scoped to their actual action paths.

  • Declare both git-submodule and reusable-workflow consumption in the GDS

... (truncated)

Commits
  • a624689 Merge pull request #100 from NDDev-OpenNetwork/fix/security-evidence-log-fall...
  • 8419bdf fix: retain security evidence when artifact delivery fails
  • 3e70397 Merge pull request #99 from NDDev-OpenNetwork/fix/pin-the-fuzzing-base-image
  • 4958996 fix(fuzz): pin the ClusterFuzzLite base image by digest
  • 9231ee7 Merge pull request #98 from fix/private-security-check-identity-20260907
  • b507bbf fix(security): preserve required check names in private-free migration
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 2 updates: [NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml](https://github.com/nddev-opennetwork/github-actions) and [NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml](https://github.com/nddev-opennetwork/ci-workflows).


Updates `NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml` from c078ddcbcfb771f56a334184b7b6399cfd9c39c4 to c113d4c9b0265bcefeb756489da9a06c8c1b9e5f
- [Release notes](https://github.com/nddev-opennetwork/github-actions/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/github-actions/blob/main/CHANGELOG.md)
- [Commits](NDDev-OpenNetwork/github-actions@c078ddc...c113d4c)

Updates `NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml` from bc9c7919de1c39d947a8709a92856925051bae05 to a624689c897c5f4733cf475159e77bba3a2b98c7
- [Release notes](https://github.com/nddev-opennetwork/ci-workflows/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/ci-workflows/blob/main/CHANGELOG.md)
- [Commits](NDDev-OpenNetwork/ci-workflows@bc9c791...a624689)

---
updated-dependencies:
- dependency-name: NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml
  dependency-version: c113d4c9b0265bcefeb756489da9a06c8c1b9e5f
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml
  dependency-version: a624689c897c5f4733cf475159e77bba3a2b98c7
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants