Merged
Conversation
Bumps [actions/stale](https://github.com/actions/stale) from 9.1.0 to 10.1.0. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@v9.1.0...v10.1.0) --- updated-dependencies: - dependency-name: actions/stale dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
brrygrdn
approved these changes
Nov 27, 2025
mergify bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Feb 22, 2026
Bumps the github-actions group with 3 updates: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action), [github/codeql-action](https://github.com/github/codeql-action) and [actions/dependency-review-action](https://github.com/actions/dependency-review-action). Updates `anthropics/claude-code-action` from 1.0.51 to 1.0.55 Release notes *Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).* > v1.0.55 > ------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.55> > > v1.0.54 > ------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.54> > > v1.0.53 > ------- > > What's Changed > -------------- > > * fix: grant write permissions and use [`@main`](https://github.com/main) in claude workflow by [`@ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#950](https://redirect.github.com/anthropics/claude-code-action/pull/950) > * feat: add display\_report option to disable step summary by [`@ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#952](https://redirect.github.com/anthropics/claude-code-action/pull/952) > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.53> > > v1.0.52 > ------- > > What's Changed > -------------- > > * Fix stale claudeCodeVersion and update bump script to keep run.ts in sync by [`@ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#943](https://redirect.github.com/anthropics/claude-code-action/pull/943) > * fix: revert to colon-based wildcard syntax for git permissions by [`@ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#949](https://redirect.github.com/anthropics/claude-code-action/pull/949) > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.52> Commits * [`edd85d6`](anthropics/claude-code-action@edd85d6) chore: bump Claude Code to 2.1.49 and Agent SDK to 0.2.49 * [`0cf5eee`](anthropics/claude-code-action@0cf5eee) chore: bump Claude Code to 2.1.47 and Agent SDK to 0.2.47 * [`e6cb7a7`](anthropics/claude-code-action@e6cb7a7) chore: bump Claude Code to 2.1.45 and Agent SDK to 0.2.45 * [`2f8ba26`](anthropics/claude-code-action@2f8ba26) chore: bump Claude Code to 2.1.44 and Agent SDK to 0.2.44 * [`cc5ef44`](anthropics/claude-code-action@cc5ef44) feat: add display\_report option to disable step summary ([#952](https://redirect.github.com/anthropics/claude-code-action/issues/952)) * [`f6a1c4c`](anthropics/claude-code-action@f6a1c4c) fix: grant write permissions and use [`@main`](https://github.com/main) in claude workflow ([#950](https://redirect.github.com/anthropics/claude-code-action/issues/950)) * [`68cfeea`](anthropics/claude-code-action@68cfeea) Revert "fix: replace deprecated :\* with modern \* wildcard in git permissions ... * [`f508883`](anthropics/claude-code-action@f508883) Fix stale claudeCodeVersion in run.ts and update bump automation ([#943](https://redirect.github.com/anthropics/claude-code-action/issues/943)) * See full diff in [compare view](anthropics/claude-code-action@ea36d6a...edd85d6) Updates `github/codeql-action` from 4.32.3 to 4.32.4 Release notes *Sourced from [github/codeql-action's releases](https://github.com/github/codeql-action/releases).* > v4.32.4 > ------- > > * Update default CodeQL bundle version to [2.24.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.2). [#3493](https://redirect.github.com/github/codeql-action/pull/3493) > * Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. [#3473](https://redirect.github.com/github/codeql-action/pull/3473) > * When the CodeQL Action is run [with debugging enabled in Default Setup](https://docs.github.com/en/code-security/how-tos/scan-code-for-vulnerabilities/troubleshooting/troubleshooting-analysis-errors/logs-not-detailed-enough#creating-codeql-debugging-artifacts-for-codeql-default-setup) and [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries), the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. [#3486](https://redirect.github.com/github/codeql-action/pull/3486) > * Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. [#3485](https://redirect.github.com/github/codeql-action/pull/3485) > * Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a [nightly CodeQL CLI release](https://github.com/dsp-testing/codeql-cli-nightlies) instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. [#3484](https://redirect.github.com/github/codeql-action/pull/3484) Changelog *Sourced from [github/codeql-action's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).* > CodeQL Action Changelog > ======================= > > See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. > > [UNRELEASED] > ------------ > > No user facing changes. > > 4.32.4 - 20 Feb 2026 > -------------------- > > * Update default CodeQL bundle version to [2.24.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.2). [#3493](https://redirect.github.com/github/codeql-action/pull/3493) > * Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. [#3473](https://redirect.github.com/github/codeql-action/pull/3473) > * When the CodeQL Action is run [with debugging enabled in Default Setup](https://docs.github.com/en/code-security/how-tos/scan-code-for-vulnerabilities/troubleshooting/troubleshooting-analysis-errors/logs-not-detailed-enough#creating-codeql-debugging-artifacts-for-codeql-default-setup) and [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries), the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. [#3486](https://redirect.github.com/github/codeql-action/pull/3486) > * Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. [#3485](https://redirect.github.com/github/codeql-action/pull/3485) > * Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a [nightly CodeQL CLI release](https://github.com/dsp-testing/codeql-cli-nightlies) instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. [#3484](https://redirect.github.com/github/codeql-action/pull/3484) > > 4.32.3 - 13 Feb 2026 > -------------------- > > * Added experimental support for testing connections to [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. [#3466](https://redirect.github.com/github/codeql-action/pull/3466) > > 4.32.2 - 05 Feb 2026 > -------------------- > > * Update default CodeQL bundle version to [2.24.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.1). [#3460](https://redirect.github.com/github/codeql-action/pull/3460) > > 4.32.1 - 02 Feb 2026 > -------------------- > > * A warning is now shown in Default Setup workflow logs if a [private package registry is configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) using a GitHub Personal Access Token (PAT), but no username is configured. [#3422](https://redirect.github.com/github/codeql-action/pull/3422) > * Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. [#3421](https://redirect.github.com/github/codeql-action/pull/3421) > > 4.32.0 - 26 Jan 2026 > -------------------- > > * Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://redirect.github.com/github/codeql-action/pull/3425) > > 4.31.11 - 23 Jan 2026 > --------------------- > > * When running a Default Setup workflow with [Actions debugging enabled](https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging), the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. [#3409](https://redirect.github.com/github/codeql-action/pull/3409) > * Improved error handling throughout the CodeQL Action. [#3415](https://redirect.github.com/github/codeql-action/pull/3415) > * Added experimental support for automatically excluding [generated files](https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github) from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. [#3318](https://redirect.github.com/github/codeql-action/pull/3318) > * The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. [#3403](https://redirect.github.com/github/codeql-action/pull/3403) > > 4.31.10 - 12 Jan 2026 > --------------------- > > * Update default CodeQL bundle version to 2.23.9. [#3393](https://redirect.github.com/github/codeql-action/pull/3393) > > 4.31.9 - 16 Dec 2025 > -------------------- > > No user facing changes. > > 4.31.8 - 11 Dec 2025 > -------------------- ... (truncated) Commits * [`89a39a4`](github/codeql-action@89a39a4) Merge pull request [#3494](https://redirect.github.com/github/codeql-action/issues/3494) from github/update-v4.32.4-39ba80c47 * [`e5d84c8`](github/codeql-action@e5d84c8) Apply remaining review suggestions * [`0c20209`](github/codeql-action@0c20209) Apply suggestions from code review * [`314172e`](github/codeql-action@314172e) Fix typo * [`cdda72d`](github/codeql-action@cdda72d) Add changelog entries * [`cfda84c`](github/codeql-action@cfda84c) Update changelog for v4.32.4 * [`39ba80c`](github/codeql-action@39ba80c) Merge pull request [#3493](https://redirect.github.com/github/codeql-action/issues/3493) from github/update-bundle/codeql-bundle-v2.24.2 * [`00150da`](github/codeql-action@00150da) Add changelog note * [`d97dce6`](github/codeql-action@d97dce6) Update default bundle to codeql-bundle-v2.24.2 * [`50fdbb9`](github/codeql-action@50fdbb9) Merge pull request [#3492](https://redirect.github.com/github/codeql-action/issues/3492) from github/henrymercer/new-repository-properties-ff * Additional commits viewable in [compare view](github/codeql-action@9e907b5...89a39a4) Updates `actions/dependency-review-action` from 4.8.2 to 4.8.3 Release notes *Sourced from [actions/dependency-review-action's releases](https://github.com/actions/dependency-review-action/releases).* > 4.8.3 > ----- > > Dependency Review Action v4.8.3 > ------------------------------- > > This is a bugfix release that updates a number of upstream dependencies and includes a fix for the earlier feature that detected oversized summaries and upload them as artifacts, which could occasionally crash the action. > > We have also updated the release process to use a long-lived `v4` **branch** for the action, instead of a force-pushed tag, which aligns better with git branching strategies; the change should be transparent to end users. > > What's Changed > -------------- > > * GitHub Actions can't push to our protected main by [`@dangoor`](https://github.com/dangoor) in [actions/dependency-review-action#1017](https://redirect.github.com/actions/dependency-review-action/pull/1017) > * Bump actions/stale from 9.1.0 to 10.1.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#995](https://redirect.github.com/actions/dependency-review-action/pull/995) > * Bump github/codeql-action from 3 to 4 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#1003](https://redirect.github.com/actions/dependency-review-action/pull/1003) > * Bump actions/setup-node from 4 to 6 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#1005](https://redirect.github.com/actions/dependency-review-action/pull/1005) > * Upgrade glob to address a vulnerability by [`@brrygrdn`](https://github.com/brrygrdn) in [actions/dependency-review-action#1024](https://redirect.github.com/actions/dependency-review-action/pull/1024) > * Bump js-yaml by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#1020](https://redirect.github.com/actions/dependency-review-action/pull/1020) > * Addressing vulnerabilities by [`@Ahmed3lmallah`](https://github.com/Ahmed3lmallah) in [actions/dependency-review-action#1036](https://redirect.github.com/actions/dependency-review-action/pull/1036) > * Bump fast-xml-parser from 5.3.3 to 5.3.5 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#1050](https://redirect.github.com/actions/dependency-review-action/pull/1050) > * Bump fast-xml-parser from 5.3.5 to 5.3.6 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#1053](https://redirect.github.com/actions/dependency-review-action/pull/1053) > * Properly truncate long summaries and catch errors by [`@juxtin`](https://github.com/juxtin) in [actions/dependency-review-action#1052](https://redirect.github.com/actions/dependency-review-action/pull/1052) > * Bump spdx-expression-parse from 3.0.1 to 4.0.0 in the spdx-licenses group across 1 directory by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/dependency-review-action#931](https://redirect.github.com/actions/dependency-review-action/pull/931) > * Changes for Release 4.8.3 by [`@ahpook`](https://github.com/ahpook) in [actions/dependency-review-action#1054](https://redirect.github.com/actions/dependency-review-action/pull/1054) > > **Full Changelog**: <https://github.com/actions/dependency-review-action/compare/v4.8.2..v4.8.3> Commits * [`05fe457`](actions/dependency-review-action@05fe457) Merge pull request [#1054](https://redirect.github.com/actions/dependency-review-action/issues/1054) from actions/ahpook/release-4.8.3 * [`3a8496c`](actions/dependency-review-action@3a8496c) Update generated package files for v4.8.3 * [`0f22a01`](actions/dependency-review-action@0f22a01) Update CONTRIBUTING for new release process * [`58be343`](actions/dependency-review-action@58be343) Updating package versions for 4.8.3 * [`9284e0c`](actions/dependency-review-action@9284e0c) Merge pull request [#931](https://redirect.github.com/actions/dependency-review-action/issues/931) from actions/dependabot/npm\_and\_yarn/spdx-licenses-20... * [`8b76656`](actions/dependency-review-action@8b76656) Bump spdx-expression-parse in the spdx-licenses group across 1 directory * [`43f5f02`](actions/dependency-review-action@43f5f02) Merge pull request [#1052](https://redirect.github.com/actions/dependency-review-action/issues/1052) from actions/juxtin/fix-long-summaries * [`f0033fc`](actions/dependency-review-action@f0033fc) Merge pull request [#1053](https://redirect.github.com/actions/dependency-review-action/issues/1053) from actions/dependabot/npm\_and\_yarn/fast-xml-parser... * [`b379e2e`](actions/dependency-review-action@b379e2e) Bump fast-xml-parser from 5.3.5 to 5.3.6 * [`2e1cf54`](actions/dependency-review-action@2e1cf54) Properly truncate long summaries and catch errors * Additional commits viewable in [compare view](actions/dependency-review-action@3c4e3dc...05fe457) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/stale from 9.1.0 to 10.1.0.
Release notes
Sourced from actions/stale's releases.
Changelog
Sourced from actions/stale's changelog.
Commits
5f858e3Addonly-issue-typesoption to filter issues by type (#1255)3a9db7eUpgrade to node 24 (#1279)8f717f0Bumps form-data (#1277)a92fd57build(deps): bump undici from 5.28.5 to 5.29.0 (#1251)128b2c8Introducing sort-by option (#1254)f78de97Update README.md (#1248)816d9dbUpgrade@action/cachefrom 4.0.2 to 4.0.3 (#1233)ba23c1cupgrade actions/cache from 4.0.0 to 4.0.2 (#1226)a65e88abuild(deps): bump undici from 5.28.4 to 5.28.5 (#1201)d4df79cUpdates to CHANGELOG.MD for recent releases (#1224)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)