Skip to content

build(deps): bump the actions-non-breaking group with 3 updates - #235

Merged
kennedy-mindermann merged 1 commit into
mainfrom
dependabot/github_actions/actions-non-breaking-39975d9e45
Oct 1, 2026
Merged

kennedy-mindermann merged 1 commit into
mainfrom
dependabot/github_actions/actions-non-breaking-39975d9e45

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions-non-breaking group with 3 updates: astral-sh/setup-uv, zizmorcore/zizmor-action and kjanat/actionlint.

Updates astral-sh/setup-uv from 10.0.1 to 10.1.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits

Updates zizmorcore/zizmor-action from 0.6.3 to 0.6.4

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.4

Sponsorship is appreciated!

zizmor 1.30.1 is now the default version.

Release notes: zizmorcore/zizmor-action#1301

Commits

Updates kjanat/actionlint from 1.15.1 to 1.17.0

Release notes

Sourced from kjanat/actionlint's releases.

v1.17.0

More of GitHub Actions understood. More mistakes caught before a workflow runs. actionlint 1.17.0 is a substantial release for this fork: explicit cache access controls, cache safety policies enabled by default, and a broad audit of workflow syntax, expressions, and local action manifests against GitHub's own schemas and runner code.

The schema work deserves equal billing. Valid expression-built matrices can now pass without spurious errors, newer workflow fields are understood, and malformed schedules and action metadata receive checks they previously escaped. Below are concrete examples of what changes when you upgrade, along with new installation options through the aqua registry and mise.

Upgrade note: the new policies can make previously clean workflows exit with status 1, including repositories without a configuration file. Existing opt-in policies retain their defaults.

Make cache access explicit

GitHub's cache-mode controls cache access independently of token permissions:

Mode Restore Save
read Yes No
write Yes Yes
write-only No Yes
none No No

Set it on the workflow or an individual job. Job settings override workflow settings; omission retains GitHub's trigger-dependent defaults. For example, give a reusable workflow a read-only ceiling:

on: pull_request_target
cache-mode: read
jobs:
report:
uses: $/.github/workflows/report.yml

actionlint follows nested local reusable calls and checks their explicit declarations against the caller's limit. Diagnostics preserve the original ./ or $/ reference. Missing or malformed callees are reported consistently regardless of file analysis order. (#163, #164)

Catch unsafe grants and ineffective cache steps

Three policies now run automatically:

  • cache-write-untrusted reports explicit write grants on low-trust triggers with access to default-branch caches, including pull_request_target, issue_comment, and workflow_run.
  • cache-call-unrestricted requires an explicit cache ceiling for reusable calls on those triggers.
  • cache-operation reports official actions/cache, actions/cache/save, and actions/cache/restore steps whose operations an explicit mode disables. Caller-imposed limits are followed through nested local workflows, including parallel child steps.

GitHub skips forbidden cache operations without failing the job. The operation check makes ineffective steps visible. The combined actions/cache action remains useful under read or write-only, where one operation is still available. Remote workflow bodies, wrappers, and package-manager caching options are not inspected. (#165)

For example, this job explicitly disables the operation its cache step requests:

jobs:
  build:
    runs-on: ubuntu-latest
    cache-mode: read
    steps:
      - uses: actions/cache/save@v6
</tr></table> 

... (truncated)

Changelog

Sourced from kjanat/actionlint's changelog.

Unreleased

  • Accept uses: $/kjanat/actionlint#199
  • Link CLI help to documentation at the release tag or development build's commit, including Go pseudo-versions and Makefile builds.
  • Add documented ACTIONLINT_* defaults for configuration selection, output, filters, logging and presentation. Split external-linter environment settings into literal BIN, argument FLAGS, and child ENV values for both ShellCheck and Pyflakes. Explicit flags override environment defaults, including empty and false values.
  • Pretty-print JSON metadata and JSON/SARIF diagnostics with installed jq when stdout is a terminal. Respect color controls and provide --json-pretty=false. Keep redirected output, JSONL, templates and stderr records unchanged; fall back to the original JSON if jq is unavailable or fails.
  • Make directory, configuration and executable paths in doctor clickable with OSC 8 file:// links. Follow the existing hyperlink controls and preserve JSON output. Encode special characters in link targets and support Windows drive and UNC paths.
  • Enable color automatically in GitHub Actions logs when GITHUB_ACTIONS=true. Respect NO_COLOR and explicit color controls, and keep automatic styling out of report files, structured output and custom templates.
  • Add OSC 8 links to the project name and URLs in CLI help. --hyperlinks=auto|always|never follows the [no-hyperlinks convention], including NO_HYPERLINKS and FORCE_HYPERLINKSkjanat/actionlint#65
  • Rebuild the CLI with a typed invocation model, a preserved Go flag parser for root calls, and Cobra commands for check, config inspection, rules, doctor, completion and version. Add JSON/JSONL/SARIF/GitHub output, template and output files, opt-in summaries, configuration origins and generated four-shell completion. Style terminal help while respecting color controls, add -V as a version alias, align doctor output, and keep concurrent verbose/debug log records intact. Preserve legacy options, templates, default diagnostics, version output, streams and exit codes. Test both grammars, command/file collisions and output side effects. Use the same input resolution, analysis results and renderers for commands and legacy Lint* methods. Preserve callbacks, working-directory handling and legacy write-error behavior. Protect all consumed local inputs from report replacement and retain configuration provenance through YAML merges. Move the frontend into internal/cli so library and Wasm builds do not import Cobra or pflag; Go callers migrating from the former root Command type can use the shared analysis APIs.
  • kjanat/actionlint#171

v1.17.0 - 2026-09-13

  • kjanat/actionlint#167

  • kjanat/actionlint#168

  • Upgrade note: the three new cache safety policies are enabled even without a configuration file and can make previously clean workflows exit with status 1. Disable individual checks with policy.cache-write-untrusted: false, policy.cache-call-unrestricted: false, or policy.cache-operation: falsekjanat/actionlint#165

  • Support current workflow schema fields and expression objects, including workflow descriptions, cancellation timeouts, image-version filters, stacked pull requests, empty choice options, disabled service images, and UTC timezone aliases.

  • Validate action manifests against generated runner schema constraints. Correct workflow expression contexts, matrix inference, function arity, expression depth, scalar decoding, required flags, schedule entries, and step ID checks.

  • Document the pinned workflow/action schema audit, complete definition coverage, regression evidence, and retained compatibility differences.

  • Enable cache safety policies by default: report explicit writes on low-trust triggers that can use default-branch caches, reusable calls without an explicit cache limit on those triggers, and official cache actions disabled by an explicit mode. Each policy can be disabled in configuration or suppressed on a specific line with a rule name and a reason.

  • Add policy.disallow-suppressions to prohibit inline cache exceptions for all or selected rules. Select report: suppression, violation, or allkjanat/actionlint#165

  • Support workflow- and job-level cache-mode values, including jobs that call reusable workflows. Check explicit cache access limits through nested local workflow calls, preserving job overrides and the distinction between omitted settings and nonekjanat/actionlint#163

  • kjanat/actionlint#164kjanat/actionlint#165)

[Changes][v1.17.0]

v1.16.1 - 2026-09-09

  • Report YAML alias type errors at each invalid alias use, with the anchor location included in the message. Preserve source locations inside anchored content and avoid missing-ref errors for malformed useskjanat/actionlint#149kjanat/actionlint#154)

  • kjanat/actionlint#150

  • kjanat/actionlint#151NixOS/nixpkgs#561437; thanks @​voidlily for the initial packaging proposal.)

... (truncated)

Commits
  • 08bb2c4 release: Prepare v1.17.0 distributions
  • 9098a85 Enforce cache safety policies by default with inline exceptions (#165)
  • 8991caa Support workflow and job cache access modes (#164)
  • 40ee367 funding: add sponsor badge
  • 231f09b Refresh the README demo for fork 1.16.1 and upstream 1.7.12 (#156)
  • 56c8ca1 Use nix profile add in installation docs
  • 662318d bump up version to v1.16.1
  • 10debd7 Complete the v1.16.1 changelog
  • 707c656 Report YAML alias errors at their use sites (#154)
  • a4dfe7e Share workflow setup and pin ShellCheck across runners (#152)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions-non-breaking group with 3 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv), [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) and [kjanat/actionlint](https://github.com/kjanat/actionlint).


Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@20cfd1b...bec219d)

Updates `zizmorcore/zizmor-action` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@70fb788...cc914d7)

Updates `kjanat/actionlint` from 1.15.1 to 1.17.0
- [Release notes](https://github.com/kjanat/actionlint/releases)
- [Changelog](https://github.com/kjanat/actionlint/blob/master/CHANGELOG.md)
- [Commits](kjanat/actionlint@b092abd...08bb2c4)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-non-breaking
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-non-breaking
- dependency-name: kjanat/actionlint
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-non-breaking
...

Signed-off-by: dependabot[bot] <support@github.com>
@kennedy-mindermann
kennedy-mindermann merged commit 94f9d5a into main Oct 1, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-non-breaking-39975d9e45 branch October 1, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant