Skip to content

chore(deps): bump the github-actions group across 1 directory with 7 updates - #15

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-d0e97c0d1d
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-d0e97c0d1d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown

Bumps the github-actions group with 7 updates in the / directory:

Package From To
actions/checkout 4.2.2 7.0.1
dorny/paths-filter 4.0.1 4.0.3
pnpm/action-setup 6.0.9 6.0.10
actions/setup-node 4.4.0 7.0.0
actions/setup-python 5.6.0 7.0.0
actions/deploy-pages 5.0.0 5.0.1
fallow-rs/fallow 2.101.0 3.22.0

Updates actions/checkout from 4.2.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dorny/paths-filter from 4.0.1 to 4.0.3

Release notes

Sourced from dorny/paths-filter's releases.

v4.0.3

What's Changed

Security

New Contributors

Full Changelog: dorny/paths-filter@v4...v4.0.3

v4.0.2

What's Changed

New Contributors

Full Changelog: dorny/paths-filter@v4.0.1...v4.0.2

Changelog

Sourced from dorny/paths-filter's changelog.

Changelog

v4.0.3

v4.0.2

v4.0.1

v4.0.0

v3.0.4

v3.0.3

v3.0.2

v3.0.1

v3.0.0

v2.11.1

v2.11.0

v2.10.2

... (truncated)

Commits
  • ceb8a2b Update CHANGELOG.md for v4.0.3 and v3.0.4 (#327)
  • ef09b88 Document safe handling of file list outputs in workflows (#326)
  • 44adc5b Merge commit from fork
  • 4711b7a feat: add 'some-with-excludes' predicate quantifier (#322)
  • 93c889f fix: escape multi-line filenames in list-files shell and csv output
  • b41dfa9 docs: add contents permission to PR example (#248)
  • 9af6e5a fix: scope base-ignored warning to API path (#319)
  • cae9006 docs: update outputs in readme to account for the 'every' predicate-quantifie...
  • 7b450ff docs: update changelog for v4.0.2 (#318)
  • 9280377 fix: work around git dubious ownership errors in container jobs (#317)
  • Additional commits viewable in compare view

Updates pnpm/action-setup from 6.0.9 to 6.0.10

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.10

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6...v6.0.10

Commits

Updates actions/setup-node from 4.4.0 to 7.0.0

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Updates actions/setup-python from 5.6.0 to 7.0.0

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates actions/deploy-pages from 5.0.0 to 5.0.1

Release notes

Sourced from actions/deploy-pages's releases.

v5.0.1

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

Commits
  • 368f825 Merge pull request #444 from actions/yoannchaudet-deployment-polling-backoff
  • 7e97763 Validate deployment polling intervals
  • 0143e11 Add backoff and jitter to deployment polling
  • 5e98f10 Merge pull request #440 from actions/user/adwitiya
  • 8b0625a Improve deployment request test coverage
  • See full diff in compare view

Updates fallow-rs/fallow from 2.101.0 to 3.22.0

Release notes

Sourced from fallow-rs/fallow's releases.

v3.22.0: honest answers from surfaces that were guessing

Fifty commits since v3.21.0. The theme this cycle is honesty about what the tool knows: several surfaces were reporting a confident answer they had not earned.

A type-aware pass that cannot finish no longer takes the run with it

The semantic pass has a fixed two-minute ceiling, and a project large enough to reach it lost its entire report: every CLI surface exited 2 regardless of typeAware.require, whose default is best-effort. The LSP already degraded correctly for the identical failure, so the same condition produced a warning through one surface and a hard error through the other.

check, watch, health and the combined run now warn and finish with the syntactic findings, recording the reason in _meta.type_aware.warnings for CI to assert on. Syntactic analysis reports a superset and the semantic pass only removes candidates it confirms are used, so continuing is the conservative outcome.

fallow fix is the deliberate exception and still stops. It removes code, and the extra entries in the unrefined set are precisely the ones a working semantic pass would have proven live, so widening a deletion is the opposite of conservative. Its error now names both ways forward.

The ceiling is settable with FALLOW_TYPE_AWARE_TIMEOUT_SECS, and VS Code exposes it as a setting. This stops the hard failure; it does not make the semantic pass fast enough to finish on a very large project on Windows.

Thanks @​VariableVince for the report.

Branching outside every function is no longer invisible

No frame was pushed at module scope, so decision points outside every function contributed nothing to any complexity number. Module-scope ??, || and ?. scored zero too, not just if ladders, which made "this change removed branching" unprovable: a fall was equally consistent with a branch having been hoisted out of a function.

A synthetic per-file unit now carries that branching into the aggregates and the review brief's conservation check. It is deliberately aggregate-only and never produces a finding, because "extract helper functions" is meaningless advice for module scope.

Measured across five real projects, the effect is smaller than expected: two showed zero movement in any vital sign and no health score moved by more than 0.2. Well-factored TypeScript keeps its boolean operators inside functions, where they were already counted.

Hoisted dependencies in a monorepo

A private sibling workspace is not installed from a registry, so a consumer that depends on it inlines its source and the package manager resolves that sibling's packages from the consumer's manifest. Nothing in the consumer imports them, so each was reported unused, with advice to move the dependency to the workspace that imports it. Following that advice breaks the build.

Fallow now walks the private-sibling closure and credits what those siblings import. A published sibling brings its own dependency tree and is deliberately not followed. Previously private was not consulted at all: the old behaviour was not conservative, it was uninformed.

Thanks @​simmo for the report.

React Native Storybook

.rnstorybook is now recognized end to end: the config, the swapped application entry, the generated requires module, and deviceAddons for on-device addons. Web Storybook projects are unchanged, verified byte for byte against nine real ones.

Thanks @​PrinceD96, who reported the gap and implemented it, and who also fixed the Lefthook binary resolution this cycle.

Migration tables

fallow migrate reads a config from another tool and maps it onto fallow's. A systematic diff against the upstream sources found 143 gaps across the two tables. The serious category is not the missing entries: sixteen keys were claimed as auto-detected when no fallow plugin covers them, so migration was telling users their tooling was handled when it was not. Those now report honestly. Unknown keys no longer vanish silently either, and the covered table is pinned to the plugin registry rather than to a hand-kept list.

Fallow still has no Marko plugin, so only the table side is fixed there.

Thanks @​VariableVince for the report, and for the hunch that more than one entry was missing.

Analysis lenses in the codebase map

fallow viz covered four analyses; everything else rendered as nothing, and an analysis that was switched off looked identical to one that ran and found no problems. Six primary lenses plus an adaptive More menu now carry an explicit availability state with a reason, so a missing analysis reads as missing data rather than as zero findings.

Also in this release

... (truncated)

Commits
  • 79a0e8d chore: release v3.22.0
  • a212b0f fix(viz): gate every path-redaction site on rooted rather than absolute (#2538)
  • bc71019 fix(viz): redact a rooted path that carries no drive letter (#2537)
  • edb3954 docs(changelog): credit React Native Storybook, the lefthook fix, and the ver...
  • d4b0e6a docs(config): stop the rule-name guard claiming a check it does not make (#2536)
  • 1630ac7 fix(engine): read the built-in plugin roster from core instead of copying it ...
  • 62de59f chore(deps-dev): bump oxfmt in /apps/review-electron (#2531)
  • 1e8a949 chore(deps-dev): bump oxfmt from 0.64.0 to 0.65.0 (#2524)
  • 0beb9fb fix(cli): complete the knip and jscpd migration tables (#2523)
  • 31e493e chore(deps): bump open from 5.4.1 to 5.4.2 (#2525)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.1` |
| [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.3` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | `6.0.9` | `6.0.10` |
| [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `7.0.0` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `7.0.0` |
| [actions/deploy-pages](https://github.com/actions/deploy-pages) | `5.0.0` | `5.0.1` |
| [fallow-rs/fallow](https://github.com/fallow-rs/fallow) | `2.101.0` | `3.22.0` |



Updates `actions/checkout` from 4.2.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4.2.2...3d3c42e)

Updates `dorny/paths-filter` from 4.0.1 to 4.0.3
- [Release notes](https://github.com/dorny/paths-filter/releases)
- [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md)
- [Commits](dorny/paths-filter@fbd0ab8...ceb8a2b)

Updates `pnpm/action-setup` from 6.0.9 to 6.0.10
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0ebf471...0977fd9)

Updates `actions/setup-node` from 4.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4.4.0...8207627)

Updates `actions/setup-python` from 5.6.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a26af69...5fda3b9)

Updates `actions/deploy-pages` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@cd2ce8f...368f825)

Updates `fallow-rs/fallow` from 2.101.0 to 3.22.0
- [Release notes](https://github.com/fallow-rs/fallow/releases)
- [Changelog](https://github.com/fallow-rs/fallow/blob/main/release.toml)
- [Commits](fallow-rs/fallow@5da5e73...79a0e8d)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: dorny/paths-filter
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: fallow-rs/fallow
  dependency-version: 3.22.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 21, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-d0e97c0d1d branch September 21, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants