Skip to content

chore(deps): bump the actions group across 1 directory with 7 updates - #808

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-39deae0f4f
Closed

chore(deps): bump the actions group across 1 directory with 7 updates#808
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-39deae0f4f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 7 updates in the / directory:

Package From To
actions/checkout 6.0.2 7.0.0
gitleaks/gitleaks-action 2.3.9 3.0.0
petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml 1 2
petry-projects/.github/.github/workflows/dependency-audit-reusable.yml 1 2
petry-projects/.github/.github/workflows/feature-ideation-reusable.yml 897e4dede3518cdd7273b9dc63e607d0d05cbdda cc05a74683f8e3564592878e417bb20f8013f16f
anthropics/claude-code-action 1.0.148 1.0.153
actions/setup-java 5.2.0 5.3.0

Updates actions/checkout from 6.0.2 to 7.0.0

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates gitleaks/gitleaks-action from 2.3.9 to 3.0.0

Release notes

Sourced from gitleaks/gitleaks-action's releases.

v3.0.0

What's changed

gitleaks-action v3 migrates the runtime from Node 20 to Node 24. No changes to inputs, outputs, or behavior. Update your workflow from gitleaks/gitleaks-action@v2 to gitleaks/gitleaks-action@v3.

Migration

# Before
- uses: gitleaks/gitleaks-action@v2
After

uses: gitleaks/gitleaks-action@v3

Why

GitHub is deprecating the Node 20 runtime for Actions:

  • June 2, 2026: GitHub flips the runner default to Node 24. Workflows using gitleaks-action@v2 (Node 20) will still run, but only if ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true is set as an environment variable.
  • September 16, 2026: Node 20 is removed from GitHub-hosted runners entirely. gitleaks-action@v2 stops working regardless of any opt-out flag.

Changes

  • action.yml: runtime node20node24
  • @actions/core: 1.10.0 → 1.11.1
  • dist/ rebuilt
  • Example workflows updated to actions/checkout@v6 and gitleaks-action@v3
  • README updated with v3 migration guide

Self-hosted runners

If you use self-hosted runners, ensure your runner version is >= v2.327.1 (required for Node 24 support).

Commits

Updates petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml from 1 to 2

Commits
  • 376a4fc feat: auto-trigger PR review when all readiness criteria are met (#323)
  • 6306793 feat(concurrency): add per-repo serialized concurrency to dev-lead stubs (#322)
  • 0765a60 fix(compliance): track per-workflow version tags in stub checker (#302)
  • 66c4866 chore: remove claude-code-reusable.yml and update auto-rebase references
  • f666f32 Merge pull request #320 from petry-projects/feat/harden-scorecard-workflow
  • 9c9cdd3 feat: harden scorecard workflow to report malformed YAML as findings
  • f88d254 Merge pull request #319 from petry-projects/fix/scorecard-summary-score
  • 57c1c5e fix: update aggregate score extraction key for scorecard v5.5.0
  • 6fd676b Merge pull request #312 from petry-projects/fix/scorecard-workflow-v2
  • b1b947e fix: resolve jq parse error by iterating with index
  • Additional commits viewable in compare view

Updates petry-projects/.github/.github/workflows/dependency-audit-reusable.yml from 1 to 2

Commits
  • 376a4fc feat: auto-trigger PR review when all readiness criteria are met (#323)
  • 6306793 feat(concurrency): add per-repo serialized concurrency to dev-lead stubs (#322)
  • 0765a60 fix(compliance): track per-workflow version tags in stub checker (#302)
  • 66c4866 chore: remove claude-code-reusable.yml and update auto-rebase references
  • f666f32 Merge pull request #320 from petry-projects/feat/harden-scorecard-workflow
  • 9c9cdd3 feat: harden scorecard workflow to report malformed YAML as findings
  • f88d254 Merge pull request #319 from petry-projects/fix/scorecard-summary-score
  • 57c1c5e fix: update aggregate score extraction key for scorecard v5.5.0
  • 6fd676b Merge pull request #312 from petry-projects/fix/scorecard-workflow-v2
  • b1b947e fix: resolve jq parse error by iterating with index
  • Additional commits viewable in compare view

Updates petry-projects/.github/.github/workflows/feature-ideation-reusable.yml from 897e4dede3518cdd7273b9dc63e607d0d05cbdda to cc05a74683f8e3564592878e417bb20f8013f16f

Commits
  • cc05a74 feat(standards): per-repo initiative-driver caller stub (#884) (#523)
  • 08b6be9 feat: implement issue #518 — add-to-project backlog reconcile (workflow_dispa...
  • 419c90f docs(ci-standards): correct stale 'ring model is the next phase' note (#517)
  • 91d8a73 feat: implement issue #506 — [Phase 1] ADR: pull-request-limits mechanism + p...
  • 5fb37e1 chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0 (#512)
  • 754a6db chore(deps): Bump pnpm/action-setup from 6.0.8 to 6.0.9 (#511)
  • 455a460 feat: implement issue #500 — pr-review: dispatcher fails on review_requested ...
  • 0e3f498 feat: implement issue #498 — SonarCloud S7637 conflicts with org first-party ...
  • b93f8b8 chore(deps): Bump petry-projects/.github/.github/workflows/feature-ideation-r...
  • 0011a11 ci(dev-lead): pin .github to @​dev-lead/ring0 + accept ring channels in audit ...
  • Additional commits viewable in compare view

Updates anthropics/claude-code-action from 1.0.148 to 1.0.153

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.153

Full Changelog: anthropics/claude-code-action@v1...v1.0.153

v1.0.152

Full Changelog: anthropics/claude-code-action@v1...v1.0.152

v1.0.151

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.151

v1.0.150

Full Changelog: anthropics/claude-code-action@v1...v1.0.150

v1.0.149

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.149

Commits
  • 2fee155 chore: bump Claude Code to 2.1.185 and Agent SDK to 0.3.185
  • 51705da chore: bump Claude Code to 2.1.183 and Agent SDK to 0.3.183
  • 806af32 chore: bump Claude Code to 2.1.181 and Agent SDK to 0.3.181
  • 0a08a86 fix: skip workflow validation token exchange failures (#1417)
  • 9dd8b95 chore: bump Claude Code to 2.1.179 and Agent SDK to 0.3.179
  • 4d7e1f0 chore: bump Claude Code to 2.1.178 and Agent SDK to 0.3.178
  • 3d9f0dc fix(mcp): align allowed-tools parser with SDK option parser (#1373)
  • a5e5d3b fix(parse-sdk-options): prevent shell-quote from collapsing unquoted Bash(X:*...
  • See full diff in compare view

Updates actions/setup-java from 5.2.0 to 5.3.0

Release notes

Sourced from actions/setup-java's releases.

v5.3.0

What's Changed

New Contributors

Full Changelog: actions/setup-java@v5...v5.3.0

Commits
  • ad2b381 Bump @​vercel/ncc from 0.38.1 to 0.44.0 (#1018)
  • b24df5b Make the Adoptopenjdk package type look at the Temurin repo first for latest ...
  • 43120bc Implement pagination with link headers for Adoptium based apis (#1014)
  • ad9d6a6 Bump @​types/node from 24.1.0 to 25.9.3 (#950)
  • 039af37 Bump picomatch, @​types/jest, jest, jest-circus and ts-jest (#1016)
  • 1756ab6 Bump eslint-config-prettier from 8.10.0 to 10.1.8 (#881)
  • 662bb59 Bump @​typescript-eslint/eslint-plugin from 8.35.1 to 8.46.2 (#952)
  • 1071fc1 fix: resolve npm audit vulnerabilities in fast-xml-builder and fast-xml-parse...
  • 576b821 Merge pull request #674 from gdams/alpine
  • 307d3a2 update readme for ubuntu sudo java_home behavior (#1013)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Dependency update PRs security Security-related PRs and issues labels Jun 19, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 19, 2026 17:07
@dependabot dependabot Bot added security Security-related PRs and issues dependencies Dependency update PRs labels Jun 19, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 9fb91df to 44fa82f Compare June 19, 2026 22:47
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 44fa82f to 67af541 Compare June 20, 2026 05:21
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 67af541 to 7b854e0 Compare June 20, 2026 06:52
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 7b854e0 to 1087b8f Compare June 20, 2026 06:57
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 1087b8f to c9bb34e Compare June 20, 2026 07:06
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 1d0cbca to 9987c19 Compare June 20, 2026 22:21
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 3efd3ef to 8a7d188 Compare June 21, 2026 10:58
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 8a7d188 to 0e3759d Compare June 21, 2026 15:07
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 0e3759d to 0bd6812 Compare June 21, 2026 16:24
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 0bd6812 to 834278f Compare June 21, 2026 16:31
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 834278f to 4aca033 Compare June 21, 2026 16:38
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 4aca033 to 6d574dc Compare June 21, 2026 16:44
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 6d574dc to cf0f300 Compare June 21, 2026 16:50
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from cf0f300 to 2068705 Compare June 21, 2026 23:38
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 2068705 to 2053254 Compare June 22, 2026 03:23
Bumps the actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.0` |
| [gitleaks/gitleaks-action](https://github.com/gitleaks/gitleaks-action) | `2.3.9` | `3.0.0` |
| [petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml](https://github.com/petry-projects/.github) | `1` | `2` |
| [petry-projects/.github/.github/workflows/dependency-audit-reusable.yml](https://github.com/petry-projects/.github) | `1` | `2` |
| [petry-projects/.github/.github/workflows/feature-ideation-reusable.yml](https://github.com/petry-projects/.github) | `897e4dede3518cdd7273b9dc63e607d0d05cbdda` | `cc05a74683f8e3564592878e417bb20f8013f16f` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.148` | `1.0.153` |
| [actions/setup-java](https://github.com/actions/setup-java) | `5.2.0` | `5.3.0` |



Updates `actions/checkout` from 6.0.2 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6.0.2...9c091bb)

Updates `gitleaks/gitleaks-action` from 2.3.9 to 3.0.0
- [Release notes](https://github.com/gitleaks/gitleaks-action/releases)
- [Commits](gitleaks/gitleaks-action@ff98106...e0c47f4)

Updates `petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml` from 1 to 2
- [Commits](petry-projects/.github@v1...v2)

Updates `petry-projects/.github/.github/workflows/dependency-audit-reusable.yml` from 1 to 2
- [Commits](petry-projects/.github@v1...v2)

Updates `petry-projects/.github/.github/workflows/feature-ideation-reusable.yml` from 897e4dede3518cdd7273b9dc63e607d0d05cbdda to cc05a74683f8e3564592878e417bb20f8013f16f
- [Commits](petry-projects/.github@897e4de...cc05a74)

Updates `anthropics/claude-code-action` from 1.0.148 to 1.0.153
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@d5726de...2fee155)

Updates `actions/setup-java` from 5.2.0 to 5.3.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@be666c2...ad2b381)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-java
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.152
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: gitleaks/gitleaks-action
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/dependency-audit-reusable.yml
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/feature-ideation-reusable.yml
  dependency-version: '068af9d51dcdfa66d7cbb5da16774520519e5bb0'
  dependency-type: direct:production
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-39deae0f4f branch from 2053254 to b547460 Compare June 22, 2026 05:42
@dependabot @github

dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 23, 2026
auto-merge was automatically disabled June 23, 2026 16:52

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-39deae0f4f branch June 23, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency update PRs security Security-related PRs and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants