From 43b2993b07e56655278a9f08a704002bfe290fbc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 23:57:35 +0000 Subject: [PATCH] build(deps): bump the dependencies group with 6 updates Bumps the dependencies group with 6 updates: | Package | From | To | | --- | --- | --- | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.1.0` | `10.2.0` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.1.0` | `7.1.1` | | [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `8.2.1` | `8.3.0` | Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](https://github.com/astral-sh/setup-uv/compare/bec219d24cd3e171d82865faccec33120bb574f4...c18668ad3cf93ea998bef934396af7bb5c839dc7) Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/init` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `codecov/codecov-action` from 7.1.0 to 7.1.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/codecov/codecov-action/compare/0b35c9ecc4f0529d0eb674914510c22f85b196b4...303a32d7a59b442fa8d48b6a1cc6825c09c847a5) Updates `SonarSource/sonarqube-scan-action` from 8.2.1 to 8.3.0 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](https://github.com/sonarsource/sonarqube-scan-action/compare/22918119ff8e1ca75a623e15c8296b6ea4fbe28f...d209202bc7d53ff1cc128f7f907dac145c9d6ae9) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: codecov/codecov-action dependency-version: 7.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] --- .github/workflows/release-please.yml | 4 ++-- .github/workflows/security-audit.yml | 8 ++++---- .github/workflows/test-and-build.yml | 8 ++++---- 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index acf784e..021f080 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -79,7 +79,7 @@ jobs: python-version: "3.13" - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true @@ -226,7 +226,7 @@ jobs: python-version: "3.13" - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index d1bafbf..bcd4cfc 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -59,7 +59,7 @@ jobs: retention-days: 30 - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: sarif_file: results.sarif @@ -86,7 +86,7 @@ jobs: run: npm ci --ignore-scripts - name: Setup uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: "3.13" enable-cache: true @@ -148,7 +148,7 @@ jobs: fetch-depth: 0 - name: "Initialize CodeQL" - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} packs: codeql/actions-queries @@ -160,4 +160,4 @@ jobs: npm run build --if-present - name: "Perform CodeQL Analysis" - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 diff --git a/.github/workflows/test-and-build.yml b/.github/workflows/test-and-build.yml index 30351e0..fddb223 100644 --- a/.github/workflows/test-and-build.yml +++ b/.github/workflows/test-and-build.yml @@ -56,7 +56,7 @@ jobs: # maintainer re-runs), so gate on the token itself - name: Upload Node coverage and test results to Codecov if: env.CODECOV_TOKEN != '' - uses: codecov/codecov-action@0b35c9ecc4f0529d0eb674914510c22f85b196b4 # v7.1.0 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: files: packages/node-commitlint/reports/lcov.info,packages/node-commitlint/reports/junit-vitest.xml flags: node @@ -141,7 +141,7 @@ jobs: python-version: ${{ matrix.python-version }} - name: Set up uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: enable-cache: true @@ -178,7 +178,7 @@ jobs: # maintainer re-runs), so gate on the token itself - name: Upload Python coverage and test results to Codecov if: env.CODECOV_TOKEN != '' - uses: codecov/codecov-action@0b35c9ecc4f0529d0eb674914510c22f85b196b4 # v7.1.0 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: files: packages/python-gitlint/reports/coverage.xml,packages/python-gitlint/reports/junit-py.xml flags: python @@ -274,6 +274,6 @@ jobs: merge-multiple: true - name: SonarCloud Scan - uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}