Skip to content

build(deps): bump the cicd group with 10 updates - #3260

Merged
Erik Osterman (Cloud Posse) (osterman) merged 12 commits into
mainfrom
dependabot/github_actions/cicd-bea170933d
Oct 7, 2026
Merged

Erik Osterman (Cloud Posse) (osterman) merged 12 commits into
mainfrom
dependabot/github_actions/cicd-bea170933d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the cicd group with 10 updates:

Package From To
cloudposse/.github/.github/workflows/shared-release-branches.yml 0.171.0 0.173.0
github/codeql-action/upload-sarif 4.38.0 4.38.1
github/codeql-action/init 4.38.0 4.38.1
github/codeql-action/autobuild 4.38.0 4.38.1
github/codeql-action/analyze 4.38.0 4.38.1
cloudposse/.github/.github/workflows/shared-go-auto-release.yml 0.170.0 0.173.0
cloudposse/github-action-setup-atmos 3.5.0 3.6.0
codecov/codecov-action 7.0.0 7.1.1
trufflesecurity/trufflehog 3.97.4 3.97.5
aws-actions/configure-aws-credentials 6.2.4 6.3.0

Updates cloudposse/.github/.github/workflows/shared-release-branches.yml from 0.171.0 to 0.173.0

Release notes

Sourced from cloudposse/.github/.github/workflows/shared-release-branches.yml's releases.

v0.173.0

  • Add an optional deprecation_notice field that renders before Introduction in place of the Atmos tip.
  • Preserve the existing tip when no notice is supplied.

why

  • Put migration guidance near the top of deprecated action READMEs without changing notices for other projects.

references

v0.172.0

  • replace deprecated RunsOn disk presets with explicit gp3 volume settings
  • use 40 GB for default runners and 120 GB for large/xlarge runners
  • pin gp3 to the included 3,000 IOPS and 125 MiB/s baseline

The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.

Validation

  • parsed .github/runs-on.yml with YAML aliases enabled
  • confirmed no deprecated disk: runner keys remain

Expected savings: approximately $15-30/month, depending on runner volume lifetime.

Commits

Updates github/codeql-action/upload-sarif from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/upload-sarif's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/upload-sarif's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/autobuild from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/autobuild's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/autobuild's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates cloudposse/.github/.github/workflows/shared-go-auto-release.yml from 0.170.0 to 0.173.0

Release notes

Sourced from cloudposse/.github/.github/workflows/shared-go-auto-release.yml's releases.

v0.173.0

  • Add an optional deprecation_notice field that renders before Introduction in place of the Atmos tip.
  • Preserve the existing tip when no notice is supplied.

why

  • Put migration guidance near the top of deprecated action READMEs without changing notices for other projects.

references

v0.172.0

  • replace deprecated RunsOn disk presets with explicit gp3 volume settings
  • use 40 GB for default runners and 120 GB for large/xlarge runners
  • pin gp3 to the included 3,000 IOPS and 125 MiB/s baseline

The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.

Validation

  • parsed .github/runs-on.yml with YAML aliases enabled
  • confirmed no deprecated disk: runner keys remain

Expected savings: approximately $15-30/month, depending on runner volume lifetime.

v0.171.0

  • In shared-go-auto-release.yml's goreleaser job, mint a second, fresh GitHub App installation token immediately before the "Run GoReleaser" step (after all the setup/GPG-import/disk-cleanup steps), instead of reusing the single token minted at the very start of the job.
  • Use that fresh token for both the GoReleaser invocation itself and the immediately-following "Attest build provenance" step.

... (truncated)

Commits
  • 281621d feat(readme): render deprecation notices above the introduction (#283)
  • 1bce210 chore: right-size RunsOn volumes (#282)
  • 4e05ff6 fix: re-mint GitHub App token before goreleaser to avoid mid-run expiry (#281)
  • See full diff in compare view

Updates cloudposse/github-action-setup-atmos from 3.5.0 to 3.6.0

Release notes

Sourced from cloudposse/github-action-setup-atmos's releases.

v3.6.0

Move the public repository’s remaining RunsOn install job to ubuntu-latest. Standard GitHub-hosted runners are free for public repositories.

The hosted runner exposed pre-existing default-branch drift that the old RunsOn dependency cache had masked: package.json no longer matched yarn.lock, ESLint 10 was incompatible with the repository’s legacy ESLint configuration/plugins, and the checked-in dist/ bundle was stale. This PR reconciles both lockfiles, restores the compatible ESLint 8.57.1 line, and commits the reproducible Node 24 action bundle.

Validation

  • yarn --frozen-lockfile --prefer-offline
  • yarn lint:check
  • yarn format:check
  • yarn test:coverage: 63 tests pass; 96.61% line and 96.92% statement coverage
  • yarn clean && yarn build && yarn build:wrapper
  • generated dist/ verification passes
  • actionlint passes
  • no RunsOn routing labels remain in test-install.yaml

Expected savings: approximately $25–50/month.

Commits

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Updates trufflesecurity/trufflehog from 3.97.4 to 3.97.5

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.5

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.4...v3.97.5

Commits
  • f714bf4 [SCAN-177] Purge secret parts from verification cache (#5318)
  • 4ecb5c6 Add elasticsearch source documentation (#5284)
  • 8d77a9d Add filesystem source documentation (#5285)
  • b8a71ee Add documentation for CircleCI source (#5268)
  • b1d7dae perf(engine): lowercase prefilter chunks as ASCII in a pooled buffer (#5291)
  • 07e3ac7 Introduce a new optional detector interface that will allow us to verify cred...
  • 5a6944e ci: avoid Node 20 BuildPulse action (#5266)
  • ce7b2b8 fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)
  • 58bf481 Postgres: drop non-connection URI params before verifying (#5296)
  • 82fd19c Adding no-ignore flag to allow reporting of "ignored" secrets (#5297)
  • Additional commits viewable in compare view

Updates aws-actions/configure-aws-credentials from 6.2.4 to 6.3.0

Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.3.0

6.3.0 (2026-09-11)

Features

Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.3.0 (2026-09-11)

Features

6.2.4 (2026-08-31)

Bug Fixes

  • account-ids handling, mask proxy as secret in logs (#1943) (aa65264)
  • skip backoff sleep after the final retryAndBackoff attempt (#1937) (3852440)

6.2.3 (2026-07-22)

Bug Fixes

  • attach git credentials before Tag Major Version push (#1877) (9ae780b)
  • PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)

6.2.2 (2026-07-07)

Miscellaneous Chores

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)

6.2.0 (2026-06-01)

Features

  • add additional session tags by default (#1775) (e0ba768)
  • add more retry logic and better logging (#1764) (540d0c1)
  • add regex validation to role-session-name (#1765) (e354499)
  • Allow custom session tags to be passed when assuming a role (#1759) (61f50f6)
  • expose run id in STS client user-agent (#1774) (29d1be3)

... (truncated)

Commits
  • e125382 chore(main): release 6.3.0 (#1963)
  • 438100a chore: add link to GH security docs (#1962)
  • e92ebcc chore: Update dist
  • 57b8365 feat: add translate-env-variables option (#1961)
  • cc49fa7 chore(docs): README main branch guidance (#1960)
  • 866cb16 chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (#1958)
  • 6782cb1 chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (#1951)
  • c20509a chore: Update dist
  • 7a41fc6 chore(deps): bump @​aws-sdk/client-sts from 3.1121.0 to 3.1127.0 (#1954)
  • 726b713 chore(deps-dev): bump @​biomejs/biome from 2.5.11 to 2.5.12 (#1957)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cicd group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [cloudposse/.github/.github/workflows/shared-release-branches.yml](https://github.com/cloudposse/.github) | `0.171.0` | `0.173.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |
| [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` |
| [cloudposse/.github/.github/workflows/shared-go-auto-release.yml](https://github.com/cloudposse/.github) | `0.170.0` | `0.173.0` |
| [cloudposse/github-action-setup-atmos](https://github.com/cloudposse/github-action-setup-atmos) | `3.5.0` | `3.6.0` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.0.0` | `7.1.1` |
| [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.97.4` | `3.97.5` |
| [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.4` | `6.3.0` |


Updates `cloudposse/.github/.github/workflows/shared-release-branches.yml` from 0.171.0 to 0.173.0
- [Release notes](https://github.com/cloudposse/.github/releases)
- [Commits](cloudposse/.github@4e05ff6...281621d)

Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...1c5b675)

Updates `github/codeql-action/init` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...1c5b675)

Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...1c5b675)

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...1c5b675)

Updates `cloudposse/.github/.github/workflows/shared-go-auto-release.yml` from 0.170.0 to 0.173.0
- [Release notes](https://github.com/cloudposse/.github/releases)
- [Commits](cloudposse/.github@v0.170.0...281621d)

Updates `cloudposse/github-action-setup-atmos` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/cloudposse/github-action-setup-atmos/releases)
- [Commits](cloudposse/github-action-setup-atmos@60878d4...9e8d1e2)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@fb8b358...303a32d)

Updates `trufflesecurity/trufflehog` from 3.97.4 to 3.97.5
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@363923b...f714bf4)

Updates `aws-actions/configure-aws-credentials` from 6.2.4 to 6.3.0
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](aws-actions/configure-aws-credentials@cbe3b39...e125382)

---
updated-dependencies:
- dependency-name: cloudposse/.github/.github/workflows/shared-release-branches.yml
  dependency-version: 0.173.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
- dependency-name: cloudposse/.github/.github/workflows/shared-go-auto-release.yml
  dependency-version: 0.173.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: cloudposse/github-action-setup-atmos
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cicd
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cicd
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 00:18
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file minor New features that do not break anything no-release Do not create a new release (wait for additional code changes) labels Oct 4, 2026
@atmos-pro

atmos-pro Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions github-actions Bot removed the minor New features that do not break anything label Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/nightlybuilds.yml

PackageVersionLicenseIssue Type
cloudposse/.github/.github/workflows/shared-go-auto-release.yml281621d6f2e63a883ea884559ffdbb4895c1bd98NullUnknown License
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-2-Clause, BSD-2-Clause-Views, BSD-3-Clause, ISC, MPL-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, Python-2.0, OFL-1.1, LicenseRef-scancode-generic-cla, LicenseRef-scancode-unknown-license-reference, LicenseRef-scancode-unicode, LicenseRef-scancode-google-patent-license-golang
Excluded from license check: pkg:golang/github.com/antlr4-go/antlr/v4, pkg:golang/github.com/google/cel-go, pkg:golang/golang.org/x/image, pkg:golang/modernc.org/libc, pkg:golang/github.com/opencontainers/go-digest, pkg:npm/pako, pkg:npm/sax

Scanned Files

  • .github/workflows/nightlybuilds.yml
  • .github/workflows/setup-go-cache-warmup.yml
  • .github/workflows/website-preview-deploy.yml
  • .github/workflows/website-preview-destroy.yml

@github-actions github-actions Bot added the size/s Small size PR label Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Warning

SHA Pin Verification Passed — with documented exceptions

All 239 third-party action reference(s) are covered, but 2 rely on a documented allowlist entry in allowlist.json and could not be automatically drift-checked. This does not fail CI, but should be reviewed.

Action Location Status Details
aquasecurity/trivy-action@v0.36.0 build.yml:162 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.
aquasecurity/trivy-action@v0.36.0 test.yml:1294 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.

See the action run for full details.

@mergify mergify Bot added the auto-update This PR was automatically generated label Oct 4, 2026
@mergify

mergify Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@mergify mergify Bot added the needs-cloudposse Needs Cloud Posse assistance label Oct 4, 2026
@codecov

codecov Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.67%. Comparing base (bbe58a6) to head (35f011e).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #3260      +/-   ##
==========================================
- Coverage   84.68%   84.67%   -0.02%     
==========================================
  Files        2105     2105              
  Lines      206759   206759              
==========================================
- Hits       175092   175067      -25     
- Misses      23401    23416      +15     
- Partials     8266     8276      +10     
Flag Coverage Δ
unittests 84.67% <ø> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 12 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

CI timing summary

Latest completed GitHub Actions runs for 35f011e31f27.

  • PR wall-clock time: 1h 20m 32s
  • Aggregate runner time: 9h 21m 55s
  • Included: 17 workflows, 124 jobs (including matrix jobs)

Wall-clock time spans the earliest included workflow creation through the latest completion. Aggregate runner time adds each job's execution time, so concurrent jobs are counted separately.

Workflow Elapsed Runner time Jobs
✅ Tests 1h 20m 29s 8h 18m 27s 98
✅ Planfile Verify E2E 13m 18s 17m 33s 3
✅ Planfile Artifacts E2E 12m 41s 12m 36s 2
✅ CodeQL 8m 05s 16m 27s 6
✅ Version Tracker 4m 08s 4m 05s 1
✅ Dependency Review 4m 07s 3m 56s 1
✅ atmos.ci 3m 32s 3m 29s 1
✅ Pre-commit 2m 10s 2m 07s 1
✅ TruffleHog secret scan 44s 41s 1
✅ Validate Codeowners 30s 26s 1
✅ Verify SHA Pinning 28s 25s 1
✅ PR Size Labeler 27s 22s 1
✅ Release Documentation Check 27s 24s 1
✅ vhs 26s 23s 3
✅ Verify Repository Symlinks 24s 20s 1
✅ autofix.ci 18s 14s 1
⏭️ Feature release 1s 0s 1
Longest jobs (top 10)
Job Workflow Duration Conclusion
[race] non-acceptance test suite (shard 4/4) Tests 20m 35s ✅ success
Build (linux) Tests 19m 14s ✅ success
Acceptance Tests (windows, shard 1/10) Tests 15m 21s ✅ success
[floci] go e2e Tests 15m 00s ✅ success
Acceptance Tests (macos, shard 1/10) Tests 14m 37s ✅ success
Acceptance Tests (windows, shard 3/10) Tests 14m 24s ✅ success
[race] non-acceptance test suite (shard 3/4) Tests 14m 11s ✅ success
[race] non-acceptance test suite (shard 2/4) Tests 13m 14s ✅ success
Acceptance Tests (macos, shard 3/10) Tests 12m 43s ✅ success
Acceptance Tests (linux, shard 1/10) Tests 12m 23s ✅ success

Updated automatically when a PR workflow finishes.

@atmos-pro

atmos-pro Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

Merged via the queue into main with commit daffd3f Oct 7, 2026
135 checks passed
@osterman
Erik Osterman (Cloud Posse) (osterman) deleted the dependabot/github_actions/cicd-bea170933d branch October 7, 2026 12:34
@atmos-pro

atmos-pro Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@mergify mergify Bot removed the needs-cloudposse Needs Cloud Posse assistance label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-update This PR was automatically generated dependencies Pull requests that update a dependency file no-release Do not create a new release (wait for additional code changes) size/s Small size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant