Skip to content

chore(deps): update all non-major dependencies - #258

Merged
chgl merged 1 commit into
masterfrom
renovate/all-minor-patch
Jul 28, 2026
Merged

chore(deps): update all non-major dependencies#258
chgl merged 1 commit into
masterfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/setup-java action minor v5.5.0v5.6.0 age confidence
docker/login-action action minor v4.4.0v4.5.2 age confidence
github/codeql-action action patch v4.37.0v4.37.3 age confidence
zizmor (source) minor 1.26.11.28.0 age confidence

Release Notes

actions/setup-java (actions/setup-java)

v5.6.0

Compare Source

What's Changed

Full Changelog: actions/setup-java@v5...v5.6.0

docker/login-action (docker/login-action)

v4.5.2

Compare Source

v4.5.1

Compare Source

v4.5.0

Compare Source

github/codeql-action (github/codeql-action)

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019
zizmorcore/zizmor (zizmor)

v1.28.0

Compare Source

Security 🔒🔗

  • v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See GHSA-f42p-wjw5-97qh for full information.

    Many thanks to @​shaanmajid for finding and reporting this vulnerability.

Enhancements 🌱🔗

  • The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes (#​2186)

  • The dependabot-cooldown audit is now aware of GitHub's new three-day default cooldown (#​2193)

  • sbt is now recognized as a package-ecosystem in dependabot.yml (#​2211)

Bug Fixes 🐛🔗

  • Fixed a bug where the template-injection audit would incorrectly flag steps.*.outcome and steps.*.conclusion as injection risks in the default persona (#​2199)

  • Fixed a bug where the github-env audit would incorrectly flag some printf calls as exploitable (#​2201)

  • Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input (#​2205)

v1.27.0

Compare Source

New Features 🌈🔗

  • zizmor now has experimental support for workflows that specify parallel steps. See Usage - Parallel steps for more information (#​2153)
    Enhancements 🌱🔗

  • zizmor's handling of paths is now more consistent, particularly when run on Windows (#​2163)

  • zizmor now emits a helpful warning when being run in implicit offline mode (#​2180)

Bug Fixes 🐛🔗

  • Fixed a bug where the secrets-outside-env audit would not honor ignore comments within the same job scope (#​2157)

  • Fixed a bug where the ref-version-mismatch audit would not honor ignore comments within the same steps scope (#​2177)

  • Fixed a bug where --collect=[MODE] was not correctly handled when auditing remote inputs (#​2185)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.31s
✅ ACTION zizmor 4 0 0 2.83s
✅ COPYPASTE jscpd yes no no 0.53s
✅ DOCKERFILE hadolint 1 0 0 0.34s
✅ JSON jsonlint 3 0 0 0.17s
✅ JSON prettier 3 0 0 0.67s
✅ JSON v8r 3 0 0 2.53s
✅ MARKDOWN markdownlint 1 0 0 1.05s
✅ MARKDOWN markdown-table-formatter 1 0 0 0.48s
✅ PYTHON bandit 1 0 0 2.93s
✅ PYTHON black 1 0 0 2.07s
✅ PYTHON flake8 1 0 0 1.64s
✅ PYTHON isort 1 0 0 0.38s
✅ PYTHON mypy 1 0 0 4.47s
✅ PYTHON pylint 1 0 0 3.75s
✅ PYTHON pyright 1 0 0 1.86s
✅ PYTHON ruff 1 0 0 0.3s
✅ REPOSITORY betterleaks yes no no 2.06s
✅ REPOSITORY checkov yes no no 37.63s
✅ REPOSITORY dustilock yes no no 0.06s
✅ REPOSITORY gitleaks yes no no 0.91s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 75.04s
✅ REPOSITORY kingfisher yes no no 14.49s
✅ REPOSITORY osv-scanner yes no no 0.25s
✅ REPOSITORY secretlint yes no no 1.72s
✅ REPOSITORY syft yes no no 3.84s
✅ REPOSITORY trivy yes no no 14.26s
✅ REPOSITORY trivy-sbom yes no no 0.2s
✅ REPOSITORY trufflehog yes no no 5.53s
✅ YAML prettier 7 0 0 0.85s
✅ YAML v8r 7 0 0 8.28s
✅ YAML yamllint 7 0 0 1.15s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters PYTHON_PYLINT,PYTHON_BLACK,PYTHON_FLAKE8,PYTHON_ISORT,PYTHON_BANDIT,PYTHON_MYPY,PYTHON_PYRIGHT,PYTHON_RUFF,ACTION_ACTIONLINT,ACTION_ZIZMOR,COPYPASTE_JSCPD,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_DUSTILOCK,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,REPOSITORY_KINGFISHER,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 7288537 to 6158f3b Compare July 28, 2026 08:03
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 6158f3b to 7ce7b19 Compare July 28, 2026 08:04
@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-without-test-image:pr-258 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

No Vulnerabilities found

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow:pr-258 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

No Vulnerabilities found

No Misconfigurations found

@github-actions

Copy link
Copy Markdown
Contributor

Trivy image scan report

ghcr.io/chgl/github-reusable-workflow-with-fixed-image-tags:v1.2.3-beta.123 (debian 13.6)

No Vulnerabilities found

No Misconfigurations found

Python

No Vulnerabilities found

No Misconfigurations found

@chgl
chgl merged commit 64326bb into master Jul 28, 2026
39 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch July 28, 2026 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.11.45 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant