Skip to content

deps(gha): bump the github-actions group across 1 directory with 6 updates#83

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-1e4f131079
Closed

deps(gha): bump the github-actions group across 1 directory with 6 updates#83
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-1e4f131079

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 20, 2026

Bumps the github-actions group with 6 updates in the / directory:

Package From To
anthropics/claude-code-action 1.0.89 1.0.101
tj-actions/changed-files 47.0.5 47.0.6
iarekylew00t/verified-bot-commit 2.2.2 2.3.0
pnpm/action-setup 5 6
astral-sh/setup-uv 8.0.0 8.1.0
aws-actions/amazon-ecr-login 2.1.2 2.1.3

Updates anthropics/claude-code-action from 1.0.89 to 1.0.101

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.101

Full Changelog: anthropics/claude-code-action@v1...v1.0.101

v1.0.100

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.100

v1.0.99

Full Changelog: anthropics/claude-code-action@v1...v1.0.99

v1.0.98

Full Changelog: anthropics/claude-code-action@v1...v1.0.98

v1.0.97

Full Changelog: anthropics/claude-code-action@v1...v1.0.97

v1.0.96

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.96

v1.0.95

Full Changelog: anthropics/claude-code-action@v1...v1.0.95

v1.0.94

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.94

v1.0.93

Full Changelog: anthropics/claude-code-action@v1...v1.0.93

v1.0.92

Full Changelog: anthropics/claude-code-action@v1...v1.0.92

v1.0.91

What's Changed

... (truncated)

Commits
  • 38ec876 chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114
  • 0d2971c fix: pass install.sh binary path explicitly to Agent SDK (#1235)
  • c68f82c chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113
  • 78758ed chore: bump model version in workflows (#1227)
  • c3d45e8 chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112
  • 931e620 chore: bump Claude Code to 2.1.111 and Agent SDK to 0.2.111
  • 905d4eb chore: bump Claude Code to 2.1.110 and Agent SDK to 0.2.110
  • 5fb8995 chore: bump Claude Code to 2.1.109 and Agent SDK to 0.2.109
  • c3bf66d fix: handle fork PRs by fetching via refs/pull/N/head (#962) (#963)
  • 3943183 chore: bump Claude Code to 2.1.108 and Agent SDK to 0.2.108
  • Additional commits viewable in compare view

Updates tj-actions/changed-files from 47.0.5 to 47.0.6

Release notes

Sourced from tj-actions/changed-files's releases.

v47.0.6

What's Changed

Full Changelog: tj-actions/changed-files@v47.0.5...v47.0.6

Changelog

Sourced from tj-actions/changed-files's changelog.

Changelog

47.0.6 - (2026-04-18)

🔄 Update

  • Updated README.md (#2817)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> Co-authored-by: Tonye Jack jtonye@ymail.com (c23d52b) - (github-actions[bot])

⚙️ Miscellaneous Tasks

  • deps: Bump lodash from 4.17.23 to 4.18.1 (#2837) (9426d40) - (dependabot[bot])
  • deps: Bump peter-evans/create-pull-request from 8.1.0 to 8.1.1 (#2843) (32de080) - (dependabot[bot])
  • deps: Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#2844) (2487d12) - (dependabot[bot])
  • deps-dev: Bump @​types/node from 25.5.0 to 25.6.0 (#2846) (cef85a3) - (dependabot[bot])
  • deps-dev: Bump prettier from 3.8.1 to 3.8.3 (#2848) (7b082de) - (dependabot[bot])
  • deps: Bump github/codeql-action from 4.35.1 to 4.35.2 (#2849) (07224ca) - (dependabot[bot])
  • deps-dev: Bump jest from 30.2.0 to 30.3.0 (#2822) (2bb1357) - (dependabot[bot])
  • deps: Bump nrwl/nx-set-shas from 4.4.0 to 5.0.1 (#2829) (cc98117) - (dependabot[bot])
  • deps: Bump yaml from 2.8.2 to 2.8.3 (#2830) (786e421) - (dependabot[bot])
  • deps-dev: Bump eslint-plugin-jest from 29.15.0 to 29.15.1 (#2831) (726b41b) - (dependabot[bot])
  • deps: Bump github/codeql-action from 4.32.6 to 4.35.1 (#2834) (2c3585e) - (dependabot[bot])
  • deps: Bump actions/download-artifact from 8.0.0 to 8.0.1 (#2824) (3d37a7f) - (dependabot[bot])
  • deps-dev: Bump @​types/node from 25.3.5 to 25.5.0 (#2825) (445b0eb) - (dependabot[bot])
  • deps: Bump github/codeql-action from 4.32.5 to 4.32.6 (#2819) (4f892cd) - (dependabot[bot])
  • deps-dev: Bump @​types/node from 25.3.3 to 25.3.5 (#2820) (6118651) - (dependabot[bot])
  • deps: Bump actions/setup-node from 6.2.0 to 6.3.0 (#2818) (e517d7a) - (dependabot[bot])

⬆️ Upgrades

  • Upgraded to v47.0.5 (#2816)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> Co-authored-by: Tonye Jack jtonye@ymail.com (4750530) - (github-actions[bot])

47.0.5 - (2026-03-03)

🔄 Update

  • Updated README.md (#2805)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> (35dace0) - (github-actions[bot])

  • Updated README.md (#2803)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@​users.noreply.github.com> Co-authored-by: Tonye Jack jtonye@ymail.com (9ee99eb) - (github-actions[bot])

⚙️ Miscellaneous Tasks

... (truncated)

Commits
  • 9426d40 chore(deps): bump lodash from 4.17.23 to 4.18.1 (#2837)
  • 32de080 chore(deps): bump peter-evans/create-pull-request from 8.1.0 to 8.1.1 (#2843)
  • 2487d12 chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#2844)
  • cef85a3 chore(deps-dev): bump @​types/node from 25.5.0 to 25.6.0 (#2846)
  • 7b082de chore(deps-dev): bump prettier from 3.8.1 to 3.8.3 (#2848)
  • 07224ca chore(deps): bump github/codeql-action from 4.35.1 to 4.35.2 (#2849)
  • 2bb1357 chore(deps-dev): bump jest from 30.2.0 to 30.3.0 (#2822)
  • cc98117 chore(deps): bump nrwl/nx-set-shas from 4.4.0 to 5.0.1 (#2829)
  • 786e421 chore(deps): bump yaml from 2.8.2 to 2.8.3 (#2830)
  • 726b41b chore(deps-dev): bump eslint-plugin-jest from 29.15.0 to 29.15.1 (#2831)
  • Additional commits viewable in compare view

Updates iarekylew00t/verified-bot-commit from 2.2.2 to 2.3.0

Release notes

Sourced from iarekylew00t/verified-bot-commit's releases.

v2.3.0

What's Changed

✨ Other Changes

🏗️ Dependencies

New Contributors

Full Changelog: IAreKyleW00t/verified-bot-commit@v2.2.2...v2.3.0

Commits
  • 126a6a1 chore: Bumping version to v2.3.0
  • 7d48146 build(deps-dev): Bump the npm-development group across 1 directory with 6 upd...
  • baf6a0b Add support for file deletions / renames (#326)
  • See full diff in compare view

Updates pnpm/action-setup from 5 to 6

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.0

Added support for pnpm v11.

Commits
  • 71c9247 fix: pnpm self-update binary shadowed by bootstrap on PATH (#230)
  • 078e9d4 fix: update pnpm to 11.0.0-rc.2
  • 08c4be7 docs(README): update action-setup version
  • 5798914 chore: update .gitignore
  • ddffd66 fix: remove accidentally committed file
  • b43f991 fix: update pnpm to 11.0.0-rc.0
  • 3852509 README.md: bring versions up-to-date (#222)
  • 6e7bdbd chore: bump bootstrap pnpm to 11.0.0-beta.4-1 and add update script
  • 6b87c46 fix: Windows standalone mode — bypass broken npm shims (#217)
  • 994d756 feat: read pnpm version from devEngines.packageManager (#211)
  • Additional commits viewable in compare view

Updates astral-sh/setup-uv from 8.0.0 to 8.1.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v8.1.0 🌈 New input no-project

Changes

This add the a new boolean input no-project. It only makes sense to use in combination with activate-environment: true and will append --no project to the uv venv call. This is for example useful if you have a pyproject.toml file with parts unparseable by uv

🚀 Enhancements

  • Add input no-project in combination with activate-environment @​eifinger (#856)

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

  • chore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0 @dependabot[bot] (#855)
Commits
  • 0880764 fix: grant contents:write to validate-release job (#860)
  • 717d6ab Add a release-gate step to the release workflow (#859)
  • 5a911eb Draft commitish releases (#858)
  • 080c31e Add action-types.yml to instructions (#857)
  • b3e97d2 Add input no-project in combination with activate-environment (#856)
  • 7dd591d chore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0 (#855)
  • 1541b77 chore: update known checksums for 0.11.7 (#853)
  • cdfb2ee Refactor version resolving (#852)
  • cb84d12 chore: update known checksums for 0.11.6 (#850)
  • 1912cc6 chore: update known checksums for 0.11.5 (#845)
  • Additional commits viewable in compare view

Updates aws-actions/amazon-ecr-login from 2.1.2 to 2.1.3

Release notes

Sourced from aws-actions/amazon-ecr-login's releases.

v2.1.3

See the changelog for details about the changes included in this release.

Changelog

Sourced from aws-actions/amazon-ecr-login's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.1.3 (2026-04-15)

2.1.2 (2026-04-01)

2.1.1 (2026-03-24)

Bug Fixes

  • prefer explicit env var credentials over Pod Identity (#953) (ecbbdc7)

2.1.0 (2026-03-19)

Features

2.0.2 (2026-03-13)

Bug Fixes

2.0.1 (2023-10-02)

2.0.0 (2023-10-02)

⚠ BREAKING CHANGES

  • The default value of the 'mask-password' input has been updated from false to true.

  • Treat maskPassword as false only if explicitly set to false

  • Add new-v2-release to README

Features

1.7.0 (2023-08-09)

Features

... (truncated)

Commits
  • 376925c chore(release): 2.1.3
  • b6d79a7 chore: Update dist (#1012)
  • 18230a5 chore: Update dist (#1008)
  • b0bca04 chore(deps): bump actions/github-script from 8 to 9 (#1007)
  • 1432f2c chore(deps-dev): bump globals from 17.4.0 to 17.5.0 (#1004)
  • 9145f16 chore(deps): bump @​aws-sdk/credential-providers (#1002)
  • 51c7534 chore(deps): bump @​aws-sdk/client-ecr from 3.1026.0 to 3.1030.0 (#1001)
  • 9ba5e23 chore: Update dist (#995)
  • 6719be7 chore(deps): bump @​aws-sdk/client-ecr-public from 3.1021.0 to 3.1026.0 (#990)
  • 2e08de5 chore(deps): bump https-proxy-agent from 8.0.0 to 9.0.0 (#991)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.89` | `1.0.101` |
| [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.5` | `47.0.6` |
| [iarekylew00t/verified-bot-commit](https://github.com/iarekylew00t/verified-bot-commit) | `2.2.2` | `2.3.0` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | `5` | `6` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.0.0` | `8.1.0` |
| [aws-actions/amazon-ecr-login](https://github.com/aws-actions/amazon-ecr-login) | `2.1.2` | `2.1.3` |



Updates `anthropics/claude-code-action` from 1.0.89 to 1.0.101
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@6e2bd52...38ec876)

Updates `tj-actions/changed-files` from 47.0.5 to 47.0.6
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](tj-actions/changed-files@22103cc...9426d40)

Updates `iarekylew00t/verified-bot-commit` from 2.2.2 to 2.3.0
- [Release notes](https://github.com/iarekylew00t/verified-bot-commit/releases)
- [Commits](IAreKyleW00t/verified-bot-commit@4aeee09...126a6a1)

Updates `pnpm/action-setup` from 5 to 6
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@v5...v6)

Updates `astral-sh/setup-uv` from 8.0.0 to 8.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@cec2083...0880764)

Updates `aws-actions/amazon-ecr-login` from 2.1.2 to 2.1.3
- [Release notes](https://github.com/aws-actions/amazon-ecr-login/releases)
- [Changelog](https://github.com/aws-actions/amazon-ecr-login/blob/main/CHANGELOG.md)
- [Commits](aws-actions/amazon-ecr-login@f2e9fc6...376925c)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.101
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: tj-actions/changed-files
  dependency-version: 47.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: iarekylew00t/verified-bot-commit
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: pnpm/action-setup
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: aws-actions/amazon-ecr-login
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 20, 2026
@greptile-apps
Copy link
Copy Markdown

greptile-apps Bot commented Apr 20, 2026

PR author is in the excluded authors list.

Copy link
Copy Markdown

@codacy-production codacy-production Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates six GitHub Action dependencies, including a major version bump for pnpm/action-setup (v5 to v6). Codacy indicates the PR is not up to standards, likely due to the lack of evidence for verification of these third-party updates.

Major version upgrades and updates to critical CI components like amazon-ecr-login and claude-code-action require explicit validation to ensure pipeline stability. The absence of a code diff in the provided PR data also prevents confirmation that the version strings were correctly updated in the workflow files.

About this PR

  • The PR includes a major version bump for pnpm/action-setup (v5 to v6). This upgrade adds support for pnpm v11 and may contain breaking changes that could impact existing workflows. Verification is required to ensure compatibility.
  • The code changes (diff) were not provided in the PR data. It is currently impossible to verify that the workflow files have been updated to the intended versions.

Test suggestions

  • Verify GitHub workflows using anthropics/claude-code-action run successfully with version 1.0.101 and the model upgrade to opus-4-7
  • Verify tj-actions/changed-files v47.0.6 correctly identifies changed files in CI pipelines
  • Verify iarekylew00t/verified-bot-commit v2.3.0 correctly handles file deletions and renames as per the release notes
  • Verify pnpm/action-setup v6 successfully sets up pnpm and supports pnpm v11
  • Verify astral-sh/setup-uv v8.1.0 successfully sets up uv environment
  • Verify aws-actions/amazon-ecr-login v2.1.3 successfully authenticates to ECR using explicit env var credentials
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify GitHub workflows using anthropics/claude-code-action run successfully with version 1.0.101 and the model upgrade to opus-4-7
2. Verify tj-actions/changed-files v47.0.6 correctly identifies changed files in CI pipelines
3. Verify iarekylew00t/verified-bot-commit v2.3.0 correctly handles file deletions and renames as per the release notes
4. Verify pnpm/action-setup v6 successfully sets up pnpm and supports pnpm v11
5. Verify astral-sh/setup-uv v8.1.0 successfully sets up uv environment
6. Verify aws-actions/amazon-ecr-login v2.1.3 successfully authenticates to ECR using explicit env var credentials
Low confidence findings
  • There is no evidence of automated or manual testing attached to this PR. Given these updates affect the core CI/CD pipeline (authentication, file tracking, environment setup), these actions should be verified in a non-production workflow before merging.

🗒️ Improve review quality by adding custom instructions

@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes. Give us feedback

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 11, 2026

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this May 11, 2026
@dependabot dependabot Bot deleted the dependabot/github_actions/github-actions-1e4f131079 branch May 11, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants