Skip to content

Upgrade trunk#338

Open
github-actions[bot] wants to merge 1 commit intomainfrom
trunk-io/update-trunk
Open

Upgrade trunk#338
github-actions[bot] wants to merge 1 commit intomainfrom
trunk-io/update-trunk

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Apr 6, 2026

Trunk

7 linters were upgraded:

  • checkov 3.2.513 → 3.2.527
  • oxipng 10.1.0 → 10.1.1
  • renovate 43.104.1 → 43.150.0
  • ruff 0.15.9 → 0.15.12
  • trivy 0.69.3 → 0.70.0
  • trufflehog 3.94.2 → 3.95.2
  • ty 0.0.28 → 0.0.34

1 plugin was upgraded:

  • trunk-io/plugins v1.7.6 → v1.8.0

This PR was generated by the Trunk Action. For more info, see our docs or reach out on Slack.

@github-actions github-actions Bot added the trunk label Apr 6, 2026
@sourcery-ai
Copy link
Copy Markdown
Contributor

sourcery-ai Bot commented Apr 6, 2026

Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This PR updates Trunk linter configuration to bump the versions of the ty and renovate linters, without changing any other tooling or project code.

File-Level Changes

Change Details Files
Bump ty linter version in Trunk configuration
  • Update the enabled ty linter from version 0.0.28 to 0.0.29 in the Trunk lint configuration
  • Keep the rest of the lint tool list and configuration unchanged
.trunk/trunk.yaml
Bump renovate linter version in Trunk configuration
  • Update the enabled renovate linter from version 43.104.1 to 43.104.6 in the Trunk lint configuration
  • Retain all other linter versions and configuration entries as-is
.trunk/trunk.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link
Copy Markdown
Contributor

@sourcery-ai sourcery-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@kilo-code-bot
Copy link
Copy Markdown

kilo-code-bot Bot commented Apr 6, 2026

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (3 files)
  • .github/workflows/agentics-maintenance.yml - No issues
  • .github/workflows/code-simplifier.lock.yml - No issues
  • .trunk/trunk.yaml - No issues

Final review: All changes in this PR are routine version bumps to Trunk linters and GitHub Actions. No security, logic, or runtime issues found throughout the review process.

Latest update: ty 0.0.33 → 0.0.34.

Complete version history:

  • ty: 0.0.28 → 0.0.34
  • renovate: 43.104.1 → 43.150.0
  • trivy: 0.69.3 → 0.70.0
  • actionlint: 1.7.12 (unchanged)
  • bandit: 1.9.4 (unchanged)
  • checkov: 3.2.513 → 3.2.526
  • git-diff-check: (unchanged)
  • hadolint: 2.14.0 (unchanged)
  • markdownlint: 0.48.0 (unchanged)
  • oxipng: 10.1.0 → 10.1.1
  • ruff: 0.15.9 → 0.15.12
  • trufflehog: 3.94.2 → 3.95.2
  • yamllint: 1.38.0 (unchanged)
  • trunk plugin: v1.7.6 → v1.8.0
  • GitHub Actions: gh-aw/actions setup updates

All updates are standard dependency maintenance with no breaking changes. PR is ready for merge.

Review completed at 2026-05-04T10:18:00Z


Reviewed by laguna-m.1:free · 0 tokens

@deepsource-io
Copy link
Copy Markdown

deepsource-io Bot commented Apr 6, 2026

DeepSource Code Review

We reviewed changes in a4ccdc8...2c603fd on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Python May 4, 2026 10:18a.m. Review ↗
Secrets May 4, 2026 10:18a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@github-actions github-actions Bot force-pushed the trunk-io/update-trunk branch 5 times, most recently from b2a7032 to 7abb812 Compare April 13, 2026 09:59
@github-actions github-actions Bot force-pushed the trunk-io/update-trunk branch 5 times, most recently from a8eecc1 to 053a1f1 Compare April 20, 2026 10:02
@github-actions github-actions Bot force-pushed the trunk-io/update-trunk branch 5 times, most recently from 4c20cc5 to 56b623d Compare April 27, 2026 10:21
@github-actions github-actions Bot force-pushed the trunk-io/update-trunk branch 5 times, most recently from 0624763 to 2c603fd Compare May 4, 2026 10:17
@github-actions github-actions Bot force-pushed the trunk-io/update-trunk branch from 2c603fd to e92e1c5 Compare May 8, 2026 09:43
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented May 8, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants