Skip to content

Bump the github-actions group with 3 updates - #584

Merged
auto-submit[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-989309fbd9
Oct 1, 2026
Merged

auto-submit[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-989309fbd9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 3 updates: dart-lang/setup-dart, dart-lang/ecosystem/.github/workflows/post_summaries.yaml and dart-lang/ecosystem/.github/workflows/publish.yaml.

Updates dart-lang/setup-dart from 1.8.0 to 1.8.1

Release notes

Sourced from dart-lang/setup-dart's releases.

v1.8.1

  • Update workflows to pin actions/checkout to a commit SHA.
  • Harden workflow permissions to contents: read.
  • Update publish.yml reusable workflow to reference setup-dart@v1.8.0 and latest setup-flutter.
  • Bump undici to 6.28.0 and @vercel/ncc to 0.44.1.
Changelog

Sourced from dart-lang/setup-dart's changelog.

v1.8.1

  • Update workflows to pin actions/checkout to a commit SHA.
  • Harden workflow permissions to contents: read.
  • Update publish.yml reusable workflow to reference setup-dart@v1.8.0 and latest setup-flutter.
  • Bump undici to 6.28.0 and @vercel/ncc to 0.44.1.

v1.8.0

  • Add a problem matcher for dart analyze to automatically create inline annotations on GitHub pull requests.
  • Update publish.yml reusable workflow to reference setup-dart@v1.7.2 (running on Node 24) (#188[]).
  • Update GitHub Action dependencies (actions/checkout v7).
  • Bump undici to 6.27.0 and update npm dependencies.

#188: dart-lang/setup-dart#188

v1.7.2

  • Update Node.js requirement to Node 24.
  • Fix open Dependabot alerts by bumping undici to >=6.24.0.
  • Update GitHub Action dependencies (@actions/core, @actions/exec, @actions/tool-cache, @actions/http-client).
  • Update workflow actions to their latest versions (actions/checkout v6, setup-flutter).

v1.7.1

  • Roll undici dependency to address CVE-2025-22150.
  • Update to the latest npm dependencies.
  • Recompile the action using the new Dart / JavaScript interop.

v1.7.0

v1.6.5

  • Fix zip path handling on Windows 11 (#118[])

#118: dart-lang/setup-dart#118

v1.6.4

  • Rebuild JS code.

v1.6.3

... (truncated)

Commits
  • 6afc89d Pin actions/checkout to a commit SHA and harden workflow permissions (#196)
  • b653b3c Prepare v1.8.1 release (#195)
  • 45165d2 Bump the github-actions group across 1 directory with 2 updates (#194)
  • 9af6bba Pin actions/checkout to a commit SHA in publish.yml (#193)
  • ddca5d2 Bump @​vercel/ncc in the npm-dependencies group across 1 directory (#185)
  • 5c116a3 Bump undici from 6.27.0 to 6.28.0 (#190)
  • See full diff in compare view

Updates dart-lang/ecosystem/.github/workflows/post_summaries.yaml from fc3dd9a17a8e18b3b4aa5abac8a0f4a679fe2d57 to 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115

Commits
  • 16dca7a fix(firehose): keep dart_apitool crash details in logs and sanitize breaking ...
  • 1bdafd8 Tighten workflow for posting PR comments (#451)
  • See full diff in compare view

Updates dart-lang/ecosystem/.github/workflows/publish.yaml from fc3dd9a17a8e18b3b4aa5abac8a0f4a679fe2d57 to 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115

Commits
  • 16dca7a fix(firehose): keep dart_apitool crash details in logs and sanitize breaking ...
  • 1bdafd8 Tighten workflow for posting PR comments (#451)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 3 updates: [dart-lang/setup-dart](https://github.com/dart-lang/setup-dart), [dart-lang/ecosystem/.github/workflows/post_summaries.yaml](https://github.com/dart-lang/ecosystem) and [dart-lang/ecosystem/.github/workflows/publish.yaml](https://github.com/dart-lang/ecosystem).


Updates `dart-lang/setup-dart` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/dart-lang/setup-dart/releases)
- [Changelog](https://github.com/dart-lang/setup-dart/blob/main/CHANGELOG.md)
- [Commits](dart-lang/setup-dart@7654d45...6afc89d)

Updates `dart-lang/ecosystem/.github/workflows/post_summaries.yaml` from fc3dd9a17a8e18b3b4aa5abac8a0f4a679fe2d57 to 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115
- [Release notes](https://github.com/dart-lang/ecosystem/releases)
- [Commits](dart-lang/ecosystem@fc3dd9a...16dca7a)

Updates `dart-lang/ecosystem/.github/workflows/publish.yaml` from fc3dd9a17a8e18b3b4aa5abac8a0f4a679fe2d57 to 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115
- [Release notes](https://github.com/dart-lang/ecosystem/releases)
- [Commits](dart-lang/ecosystem@fc3dd9a...16dca7a)

---
updated-dependencies:
- dependency-name: dart-lang/setup-dart
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: dart-lang/ecosystem/.github/workflows/post_summaries.yaml
  dependency-version: 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: dart-lang/ecosystem/.github/workflows/publish.yaml
  dependency-version: 16dca7ae5d3ff896a4db47e1ed6cd50f7ebbf115
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the autosubmit label Oct 1, 2026
@auto-submit
auto-submit Bot merged commit b2d1d6b into main Oct 1, 2026
34 checks passed
@auto-submit
auto-submit Bot deleted the dependabot/github_actions/github-actions-989309fbd9 branch October 1, 2026 06:57
copybara-service Bot pushed a commit to dart-lang/sdk that referenced this pull request Oct 7, 2026
Revisions updated by `dart tools/rev_sdk_deps.dart`.

core (https://github.com/dart-lang/core/compare/08e4022..4d80610):
  4d80610a  Thu Oct 1 22:03:38 2026 +0000  dependabot[bot]  Bump the github-actions group with 5 updates (dart-lang/core#1005)

dartdoc (https://github.com/dart-lang/dartdoc/compare/2a040a8..5eb0f2c):
  5eb0f2c7  Thu Oct 1 19:03:48 2026 +0000  dependabot[bot]  Bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.2 in the github-actions group (dart-lang/dartdoc#4291)

http (https://github.com/dart-lang/http/compare/d8e8e9c..585d433):
  585d433  Mon Oct 5 16:12:54 2026 -0700  Brian Quinlan  fix(cupertino_http): fix a websocket memory leak (dart-lang/http#1991)
  337adf3  Mon Oct 5 16:03:25 2026 -0700  Brian Quinlan  fix(cupertino_http): add `autoReleasePool` use to `CupertinoClient` (dart-lang/http#1990)
  47c57df  Tue Sep 29 14:07:01 2026 -0700  Brian Quinlan  fix(ok_http): fix `NetworkOnMainThreadException` (dart-lang/http#1995)
  d8cde5d  Tue Sep 29 14:06:44 2026 -0700  Brian Quinlan  fix test (dart-lang/http#1996)
  31056fe  Tue Sep 29 13:57:20 2026 -0700  Brian Quinlan  chore(cronet_http): prepare to release 1.10.0 (dart-lang/http#1993)
  9bc3a91  Tue Sep 29 13:53:25 2026 -0700  Brian Quinlan  fix(cronet_http): one global reference per `onReadCompleted` (dart-lang/http#1992)
  49ecd36  Mon Sep 28 14:20:26 2026 -0700  Brian Quinlan  fix(conformance): `supportsAbort` not considered in response (dart-lang/http#1994)

native (https://github.com/dart-lang/native/compare/27f7678..a2a6179):
  a2a617910  Tue Oct 6 13:53:17 2026 +0200  Daco Harkes  [jni_flutter] Bump version for publishing (dart-lang/native#3730)
  d3a99d66b  Tue Oct 6 19:46:34 2026 +1100  Liam Appelbe  [infra] Fix ffigen and jni_flutter (dart-lang/native#3724)
  b66d0815a  Tue Oct 6 04:28:35 2026 +0300  Manar Elhabbal  [ffigen] add Support passing C++ classes by value  (dart-lang/native#3677)
  f7ffe9667  Fri Oct 2 11:33:49 2026 +0200  Moritz  [native_toolchain_c] Don't pass /INCLUDE per symbol with a generated .def on Windows (dart-lang/native#3718)
  77a5e4169  Thu Oct 1 10:56:45 2026 +0300  Hassnaa Mohamed  [ffigen] Fix cpp method filtering (dart-lang/native#3696)
  cca065ca6  Thu Oct 1 10:17:12 2026 +1000  Liam Appelbe  [infra] Prepare to publish everything (dart-lang/native#3716)
  f13623ee3  Thu Oct 1 10:16:39 2026 +1000  Liam Appelbe  [jnigen] API docs (dart-lang/native#3715)
  be618790c  Thu Oct 1 10:05:26 2026 +1000  Liam Appelbe  [objective_c] API docs (dart-lang/native#3708)
  a18dd1148  Thu Oct 1 10:04:38 2026 +1000  Liam Appelbe  [ffigen] API docs (dart-lang/native#3707)
  6fd87c3b2  Tue Sep 29 19:01:11 2026 -0700  Brian Quinlan  [jni] Clarify `JBuffer.asUint8List` behavior (dart-lang/native#3704)
  6d5bbcfad  Wed Sep 30 09:35:47 2026 +1000  Liam Appelbe  [jni] API documentation (dart-lang/native#3706)
  fbcbc894b  Wed Sep 30 09:35:34 2026 +1000  Liam Appelbe  [ffigen] Document autorelease issues (dart-lang/native#3705)
  f99449ec9  Tue Sep 29 09:39:27 2026 +1000  Liam Appelbe  [infra] Add swift2objc to the workspace (dart-lang/native#3700)
  31494fa08  Tue Sep 29 09:38:59 2026 +1000  Liam Appelbe  [infra] Add jni_util to the workspace (dart-lang/native#3698)

shelf (https://github.com/dart-lang/shelf/compare/e5c8dc6..b2cb503):
  b2cb503  Wed Sep 30 22:53:07 2026 -0700  Kevin Moore  Resolve shelf.io.connection_info lazily (dart-lang/shelf#542)
  b70fafa  Tue Sep 29 13:37:08 2026 -0700  Kevin Moore  Match parameterless shelf_router routes without running a regex (dart-lang/shelf#544)

test (https://github.com/dart-lang/test/compare/4f92d53..d749b10):
  d749b104  Mon Oct 5 15:42:46 2026 -0700  Nate Bosch  Fail isolate suites when the test isolate exits (dart-lang/test#2775)
  da2157e9  Mon Oct 5 11:12:43 2026 -0700  Nate Bosch  Wait longer for the Chrome test tab to appear (dart-lang/test#2771)
  00bd0c99  Mon Oct 5 18:50:03 2026 +0300  Yusuf İhsan Görgel  Fix broken links in architecture.md (dart-lang/test#2774)
  3be2f547  Thu Oct 1 03:46:29 2026 +0000  dependabot[bot]  Bump the github-actions group with 4 updates (dart-lang/test#2773)
  40a5ad90  Tue Sep 29 12:07:31 2026 -0700  Nate Bosch  Delete compilation artifacts once they are no longer needed (dart-lang/test#2764)
  171ad0e5  Mon Sep 28 17:29:48 2026 -0700  Jacob MacDonald  export additional types from package:test_api/backend.dart (dart-lang/test#2745)
  52b45064  Mon Sep 28 15:04:08 2026 -0700  Nate Bosch  Tag browser and node tests, relax flaky timeouts (dart-lang/test#2770)

tools (https://github.com/dart-lang/tools/compare/d87eaf7..a66d517):
  a66d517d  Tue Oct 6 09:41:32 2026 -0700  Phil Quitslund  [analytics] `DASH__SUPPRESS_ANALYTICS` env handling (dart-lang/tools#2641)
  00c6e4ad  Fri Oct 2 17:17:49 2026 +0530  shivytyahoo  Fix VersionConstraint.intersection throwing on disjoint ranges (dart-lang/tools#2622)
  d523e1f8  Thu Oct 1 11:09:16 2026 +0200  Morgan :)  [unified_analytics] Append to the log file instead of rewriting it (dart-lang/tools#2613)
  6993cbad  Wed Sep 30 14:09:32 2026 +0300  Yusuf İhsan Görgel  [yaml] Improve error messages when mixing list and key-value syntax (dart-lang/tools#2610)
  068119b4  Tue Sep 29 23:21:03 2026 +0200  Lukas Klingsbo  [pubspec_parse] Support tag_pattern for git dependencies (dart-lang/tools#2565)
  7d859ed5  Mon Sep 28 20:28:23 2026 -0700  Kevin Moore  [api_summary] Add expectApiSummaryClean and --write/--check CLI flags (dart-lang/tools#2603)

web (https://github.com/dart-lang/web/compare/ec71a4c..63e6662):
  63e6662  Sat Oct 3 00:23:21 2026 +0000  Natalie Weizenbaum  Add a JSPair type (dart-lang/web#586)
  2d68d90  Fri Oct 2 20:26:48 2026 +0000  Natalie Weizenbaum  Use `js_interop` APIs in `js_interop_gen` (dart-lang/web#585)
  037823c  Thu Oct 1 21:59:21 2026 +0000  Natalie Weizenbaum  Add JSMap, JSSet, and JSSetLike types (dart-lang/web#571)
  b2d1d6b  Thu Oct 1 06:57:03 2026 +0000  dependabot[bot]  Bump the github-actions group with 3 updates (dart-lang/web#584)
  8dc8f75  Wed Sep 30 08:12:18 2026 -0700  Kevin Moore  [js_interop_gen] Split union/intersection AST types and extract TypeTransformer (dart-lang/web#580)
  751ccdf  Wed Sep 30 08:12:18 2026 -0700  Kevin Moore  [js_interop_gen] Decompose `Transformer._transformType` and deduplicate type caching (dart-lang/web#579)
  6f3dd4e  Wed Sep 30 08:12:17 2026 -0700  Kevin Moore  [js_interop_gen] Deduplicate `UnionType` and `IntersectionType` via `UnionOrIntersectionType` (dart-lang/web#578)
  d9f095e  Tue Sep 29 12:17:29 2026 -0700  Kevin Moore  [js_interop_gen] Remove unused JS interop extension types and bindings (dart-lang/web#577)
  07111ee  Tue Sep 29 09:51:36 2026 -0700  Kevin Moore  fix(js_interop_gen): update js_type_supertypes for Dart 3.12 (dart-lang/web#582)

Change-Id: I4532049c45561fe8f8c57713ac8ec2153096fd9a
Reviewed-on: https://dart-review.googlesource.com/c/sdk/+/560660
Commit-Queue: Nate Bosch <nbosch@google.com>
Reviewed-by: Brian Quinlan <bquinlan@google.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant