Skip to content

chore(deps): bump the github-actions group with 2 updates#86

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/github-actions-4739d124e3
Open

chore(deps): bump the github-actions group with 2 updates#86
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/github-actions-4739d124e3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates: AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml and softprops/action-gh-release.

Updates AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml from 1.1.0 to 1.2.0

Release notes

Sourced from AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml's releases.

v1.2.0

New Features 🎉

  • Feature: #82 Update AquaSec workflow behavior - remove sec:adept-to-close label by @​HuvarVer, @​tmikula-dev in #84
    • GitHub issues now close automatically, after they disappear from AquaSec platform.
    • New standard labels recommended sec:suppression and sec:false-positive for full security ticket lifecycle.

Infrastructure ⚙️

Security Alerts 🛡️

  • #62 Security Alert – AVD-PIPELINE-0003
  • #63, #64, #65, #66 [SEC:LOW] Echo of variables

Full Changelog

v1.1.0...v1.2.0

Commits
  • 3b6a6b0 feat: Removing adept to close label logic (#84)
  • 7fce4b9 chore(deps): bump the github-actions group across 1 directory with 2 updates ...
  • bf6d958 chore(deps): bump the python-dependencies group with 2 updates (#83)
  • 572d3e3 chore(deps): bump the github-actions group with 2 updates (#78)
  • 2654cb2 chore(deps): update pytest requirement in the python-dependencies group (#79)
  • a679b38 Update aquasec-night-scan-example.yml
  • 704f266 Update AquaSec night scan workflow configuration
  • See full diff in compare view

Updates softprops/action-gh-release from 3.0.1 to 3.0.2

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. v2.6.2 was the final Node 20-compatible release and is no longer maintained or supported.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; freeze v2 at the final v2.6.2 release

... (truncated)

Commits
  • 3d0d988 release 3.0.2 (#818)
  • 7e13ed4 fix: clarify release creation 404 errors (#817)
  • e6c70a5 fix: replace existing release assets on Gitea (#816)
  • f345337 fix: publish existing draft releases as prereleases (#801)
  • d8a89a2 fix: upload small checksum assets reliably (#815)
  • 45ece40 chore(deps): remove unused TypeScript tooling (#814)
  • f6b913c feat: improve release error reporting and test coverage (#813)
  • 15f193d chore(deps): upgrade TypeScript to 7 (#812)
  • cc8268d chore(deps): bump actions/checkout in the github-actions group (#810)
  • fd0ed1e chore(deps): bump the npm group with 3 updates (#811)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 2 updates: [AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml](https://github.com/absaoss/organizational-workflows) and [softprops/action-gh-release](https://github.com/softprops/action-gh-release).


Updates `AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml` from 1.1.0 to 1.2.0
- [Release notes](https://github.com/absaoss/organizational-workflows/releases)
- [Commits](d3e4ff7...3b6a6b0)

Updates `softprops/action-gh-release` from 3.0.1 to 3.0.2
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@718ea10...3d0d988)

---
updated-dependencies:
- dependency-name: AbsaOSS/organizational-workflows/.github/workflows/aquasec-scan.yml
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added infrastructure Project setup and deployment no RN No release notes required labels Jul 19, 2026
@dependabot
dependabot Bot requested a review from miroslavpojer as a code owner July 19, 2026 22:42
@dependabot dependabot Bot added the infrastructure Project setup and deployment label Jul 19, 2026
@dependabot
dependabot Bot requested a review from tmikula-dev as a code owner July 19, 2026 22:42
@dependabot dependabot Bot added the no RN No release notes required label Jul 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infrastructure Project setup and deployment no RN No release notes required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants