Skip to content

chore(deps): roll up Dependabot updates - #1004

Merged
eifinger merged 1 commit into
mainfrom
dependabot-rollup-20260811-142729
Aug 11, 2026
Merged

chore(deps): roll up Dependabot updates#1004
eifinger merged 1 commit into
mainfrom
dependabot-rollup-20260811-142729

Conversation

@eifinger

Copy link
Copy Markdown
Collaborator

Summary

Roll up the remaining dependency changes from Dependabot PRs #997, #998, #999, #1000, #1001, #1002, and #1003:

  • update github/codeql-action to 4.37.6
  • update zizmorcore/zizmor-action to 0.6.2
  • update undici to 8.10.0
  • update smol-toml to 1.7.1
  • update @biomejs/biome and its schema to 2.5.6
  • regenerate the published bundles

PRs #905 and #907 were excluded because their requested Jest and pep440 versions are already present on main.

Validation

  • npm run all
  • actionlint .github/workflows/codeql-analysis.yml .github/workflows/test.yml
  • uvx zizmor .github/workflows/codeql-analysis.yml .github/workflows/test.yml
  • git diff --check

Refs: pi-session 019ff0c9-8e00-72d3-99ad-d4383a4c57d4

Refs: pi-session 019ff0c9-8e00-72d3-99ad-d4383a4c57d4
@eifinger eifinger added the dependencies Pull requests that update a dependency file label Aug 11, 2026
@eifinger
eifinger merged commit 8d6402c into main Aug 11, 2026
93 checks passed
@eifinger
eifinger deleted the dependabot-rollup-20260811-142729 branch August 11, 2026 13:08
ajgon pushed a commit to deedee-ops/schemas that referenced this pull request Aug 12, 2026
…0) (#17)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.0` |

---

### Release Notes

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

### [`v10.0.0`](https://github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features

[Compare Source](astral-sh/setup-uv@v9.0.0...v10.0.0)

#### Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

##### Extra security by default

If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events:

- `pull_request_target`
- `workflow_run`
- `release`

You can read the full reasoning in [#&#8203;984](astral-sh/setup-uv#984)

##### `version: latest-known`

```yaml
- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"
```

This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

##### Read python version from `.tool-versions`

```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
```

Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)

#### 🚨 Breaking changes

- Disable automatic caching for sensitive events [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;992](astral-sh/setup-uv#992))

#### 🐛 Bug fixes

- Reject paths in .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1007](astral-sh/setup-uv#1007))

#### 🚀 Enhancements

- Read Python version from .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;996](astral-sh/setup-uv#996))
- Add latest-known version selector [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;993](astral-sh/setup-uv#993))

#### 🧰 Maintenance

- Require pull requests for Dependabot rollups [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1005](astral-sh/setup-uv#1005))
- ci: pin Alpine container image [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;995](astral-sh/setup-uv#995))
- chore: update known checksums for 0.12.3 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;991](astral-sh/setup-uv#991))
- chore: update known checksums for 0.12.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;985](astral-sh/setup-uv#985))
- chore: update known checksums for 0.12.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;982](astral-sh/setup-uv#982))
- chore: update known checksums for 0.12.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;981](astral-sh/setup-uv#981))
- chore: update known checksums for 0.11.31/0.11.32 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;972](astral-sh/setup-uv#972))

#### 📚 Documentation

- docs: update version references to v9.0.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;971](astral-sh/setup-uv#971))

#### ⬆️ Dependency updates

- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1013](astral-sh/setup-uv#1013))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1004](astral-sh/setup-uv#1004))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;994](astral-sh/setup-uv#994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;976](astral-sh/setup-uv#976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;980](astral-sh/setup-uv#980))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Warsaw)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC44LjEiLCJ1cGRhdGVkSW5WZXIiOiI0NC44LjEiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: https://git.ajgon.casa/deedee/schemas/pulls/17
Doridian pushed a commit to FoxDenHome/core that referenced this pull request Aug 12, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [https://github.com/astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.0` |

---

### Release Notes

<details>
<summary>astral-sh/setup-uv (https://github.com/astral-sh/setup-uv)</summary>

### [`v10.0.0`](https://github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features

[Compare Source](astral-sh/setup-uv@v9.0.0...v10.0.0)

#### Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

##### Extra security by default

If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events:

- `pull_request_target`
- `workflow_run`
- `release`

You can read the full reasoning in [#&#8203;984](astral-sh/setup-uv#984)

##### `version: latest-known`

```yaml
- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"
```

This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

##### Read python version from `.tool-versions`

```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
```

Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)

#### 🚨 Breaking changes

- Disable automatic caching for sensitive events [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;992](astral-sh/setup-uv#992))

#### 🐛 Bug fixes

- Reject paths in .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1007](astral-sh/setup-uv#1007))

#### 🚀 Enhancements

- Read Python version from .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;996](astral-sh/setup-uv#996))
- Add latest-known version selector [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;993](astral-sh/setup-uv#993))

#### 🧰 Maintenance

- Require pull requests for Dependabot rollups [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1005](astral-sh/setup-uv#1005))
- ci: pin Alpine container image [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;995](astral-sh/setup-uv#995))
- chore: update known checksums for 0.12.3 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;991](astral-sh/setup-uv#991))
- chore: update known checksums for 0.12.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;985](astral-sh/setup-uv#985))
- chore: update known checksums for 0.12.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;982](astral-sh/setup-uv#982))
- chore: update known checksums for 0.12.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;981](astral-sh/setup-uv#981))
- chore: update known checksums for 0.11.31/0.11.32 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;972](astral-sh/setup-uv#972))

#### 📚 Documentation

- docs: update version references to v9.0.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;971](astral-sh/setup-uv#971))

#### ⬆️ Dependency updates

- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1013](astral-sh/setup-uv#1013))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1004](astral-sh/setup-uv#1004))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;994](astral-sh/setup-uv#994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;976](astral-sh/setup-uv#976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;980](astral-sh/setup-uv#980))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: https://git.foxden.network/FoxDen/core/pulls/145
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant