Skip to content

chore(deps): bump the github-actions group across 1 directory with 8 updates - #17

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-bd97f9f86b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-bd97f9f86b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown

Bumps the github-actions group with 8 updates in the / directory:

Package From To
actions/checkout 4.2.2 7.0.1
dorny/paths-filter 4.0.1 4.0.3
pnpm/action-setup 6.0.9 6.1.0
actions/setup-node 4.4.0 7.0.0
codecov/codecov-action 7.0.0 7.1.1
actions/setup-python 5.6.0 7.0.0
actions/deploy-pages 5.0.0 5.0.1
fallow-rs/fallow 2.101.0 3.27.0

Updates actions/checkout from 4.2.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dorny/paths-filter from 4.0.1 to 4.0.3

Release notes

Sourced from dorny/paths-filter's releases.

v4.0.3

What's Changed

Security

New Contributors

Full Changelog: dorny/paths-filter@v4...v4.0.3

v4.0.2

What's Changed

New Contributors

Full Changelog: dorny/paths-filter@v4.0.1...v4.0.2

Changelog

Sourced from dorny/paths-filter's changelog.

Changelog

v4.0.3

v4.0.2

v4.0.1

v4.0.0

v3.0.4

v3.0.3

v3.0.2

v3.0.1

v3.0.0

v2.11.1

v2.11.0

v2.10.2

... (truncated)

Commits
  • ceb8a2b Update CHANGELOG.md for v4.0.3 and v3.0.4 (#327)
  • ef09b88 Document safe handling of file list outputs in workflows (#326)
  • 44adc5b Merge commit from fork
  • 4711b7a feat: add 'some-with-excludes' predicate quantifier (#322)
  • 93c889f fix: escape multi-line filenames in list-files shell and csv output
  • b41dfa9 docs: add contents permission to PR example (#248)
  • 9af6e5a fix: scope base-ignored warning to API path (#319)
  • cae9006 docs: update outputs in readme to account for the 'every' predicate-quantifie...
  • 7b450ff docs: update changelog for v4.0.2 (#318)
  • 9280377 fix: work around git dubious ownership errors in container jobs (#317)
  • Additional commits viewable in compare view

Updates pnpm/action-setup from 6.0.9 to 6.1.0

Release notes

Sourced from pnpm/action-setup's releases.

v6.1.0

What's Changed

Full Changelog: pnpm/action-setup@v6.0.10...v6.1.0

v6.0.10

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6...v6.0.10

Commits

Updates actions/setup-node from 4.4.0 to 7.0.0

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Updates actions/setup-python from 5.6.0 to 7.0.0

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates actions/deploy-pages from 5.0.0 to 5.0.1

Release notes

Sourced from actions/deploy-pages's releases.

v5.0.1

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

Commits
  • 368f825 Merge pull request #444 from actions/yoannchaudet-deployment-polling-backoff
  • 7e97763 Validate deployment polling intervals
  • 0143e11 Add backoff and jitter to deployment polling
  • 5e98f10 Merge pull request #440 from actions/user/adwitiya
  • 8b0625a Improve deployment request test coverage
  • See full diff in compare view

Updates fallow-rs/fallow from 2.101.0 to 3.27.0

Release notes

Sourced from fallow-rs/fallow's releases.

v3.27.0: every CI gate reaches the job, baseline staleness in CI, MCP verdicts

Every gate fallow documents now reaches CI. This release closes a defect class rather than a single bug: verdicts the CLI expressed only on stderr or through its exit code were invisible to the GitHub Action, the GitLab template and the MCP server, because all three run with --quiet --format json and drop the exit code whenever stdout parses as JSON.

CI gates that actually fail the job

  • fail-on-regression, threshold, min-severity and the security gate were documented as gates and were silently inert in both integrations. A run that arms a gate now publishes gate_outcomes in its JSON envelope, and the action and the template read the verdict from there. A gate fails the build when its status is fail and enforced is true, and only when the input that owns it asked for it; a flag passed through args: warns and never overrides fail-on-issues: false.
  • Every failing gate reports before the step exits: all reasons are printed, outputs and artifacts are written, and the step exits once. The security gate keeps its documented exit 8.
  • min-score is a first-class action input and GitLab variable. It runs health with --complexity so annotations, SARIF and the pull-request comment stay populated, and the count gate stands down for that run because the CLI's own findings rule does.
  • The duplication threshold reaches the bare command on GitHub, and in combined mode the envelope says the threshold is not enforced instead of pretending it is.
  • A run that analyzed no source file says so. It warns and passes by default; fail-on-empty-analysis: true (FALLOW_FAIL_ON_EMPTY_ANALYSIS on GitLab) turns it into a failure. Diagnostics that mean the run measured less than the project land as one aggregated warning.
  • Gate outcomes are exposed as step outputs on GitHub and as a dotenv report on GitLab.

Baseline staleness reaches CI

3.26.0 shipped the advisory that a dead-code baseline has gone stale and --fail-on-stale-baseline to turn that into a failing build, but both lived on stderr only, so the documented CI path never saw them. dead-code, the combined run, dupes and health now publish one baseline_staleness object with the counts, the advisory verdict and gate_trips. The action and the template surface it as a warning and in the job summary; on a pull request, where the primary run is scoped to changed files, the integration re-reads the baseline once over the whole project so the advisory reaches pull-request-only repositories too. The new fail-on-stale-baseline input and FALLOW_FAIL_ON_STALE_BASELINE variable decide whether that verdict fails the job. Thanks @​cloud-walker for the report in #2673, which documented exactly where the 3.26.0 fix stopped short.

MCP tool results state the verdict

MCP tool results now carry the baseline advisory, every failing or warning gate with its numbers, and the degraded-analysis summary as plain sentences in the envelope's warnings array, on the subprocess, Code Mode and typed routes. Result bodies stay JSON, no member moves, and a clean run is byte-identical to CLI stdout.

Envelope additions, no schema version moved

  • gate_outcomes: an optional object keyed by gate name with status, enforced, and observed, threshold and threshold_label where a comparison happened. Absent when no gate was armed; the key set is open on the wire.
  • baseline_staleness on dead-code, combined, dupes and health envelopes, grouped output included.
  • workspace_diagnostics[].degrades_analysis and a no-source-files-analyzed diagnostic.
  • fallow report --from renders a neutral "Gate outcomes" line on the GitHub summary, annotations, pull-request comment, review targets and the GitLab merge-request note; the check-run conclusion and the exit code are unchanged.
  • TypeScript consumers of npm/fallow/types: HealthBaselineStaleness is now the shared BaselineStaleness; the old name ships as a deprecated alias so existing imports keep compiling.

Behaviour changes to check before upgrading

  • A repository with a security gate configured and fail-on-issues: false now fails on a tripped gate. Not configuring the gate is the opt-out.
  • The action's inline Check threshold step is gone; its logic lives in the analyze step, and the gates-failed output carries which gates decided the verdict.
  • --fail-on-stale-baseline now moves exactly one wire member, gate_outcomes["stale-baseline"].enforced; the baseline_staleness object itself stays flag-independent.
  • On a fallow older than 3.27.0 both integrations fall back to the fields those releases already published and fail open with one warning for the gates that had none.

Full Changelog: fallow-rs/fallow@v3.26.0...v3.27.0

v3.26.0: stale-baseline gate, built-in exclusion diagnostics, rule overrides everywhere

Features

  • --fail-on-stale-baseline turns a rotting baseline into a failing build. The new global flag exits 1 when a loaded --baseline has any entry that matched nothing this run, on dead-code / check, the bare run, dupes and health, in every output format. A run that cannot judge the baseline (a narrowed scope, health --report-only, audit, decision-surface) stands down and says so on stderr. JSON output is unchanged. (#2637)
  • dead-code --baseline warns when the saved baseline has gone stale, in the same wording health --baseline has used since 3.12.0: when a quarter or more of the entries match no current issue, the run says so and points at the re-save command. Exit codes are untouched. Thanks @​cloud-walker for the report. (#2627)
  • A run can say which built-in ignore pattern removed source files. The walk attributes every excluded candidate to the pattern that removed it and records one excluded-by-default-ignore entry per pattern in workspace_diagnostics[] with the glob, an exact file count, the matched-directory count and a project-relative anchor. --explain-skipped prints the breakdown on check, dead-code, audit and the default run; without the flag, only a run that discovered no source files at all prints a two-fact warning pointing at the flag. (#2638)
  • Oxfmt is a built-in plugin. oxfmt.config.ts and its siblings are marked always-used and static imports from those configs are credited. Thanks @​uzosrc for the request. (#2614)
  • Expo Router's SuspenseFallback, getNavOptions and generateMetadata route exports are recognized. Thanks @​tilgovi for the SuspenseFallback patch (#2618).

Changed

  • The built-in build exclusion now matches at any depth (**/build/**), consistent with the dist and coverage defaults, so nested build output in monorepos no longer produces unused-file, unused-export, duplication and health findings. Five consequences are stated plainly in the changelog together with the remedy for each, including that hand-written source in a nested build/ directory is now skipped. Thanks @​michalius for the report. (#2622)
  • Unused- and unlisted-dependency checks are faster on large workspace monorepos: each file's owning workspace is resolved once per analysis. On a repository with about 18,000 files and 800 workspaces the check went from roughly 30 seconds to 6 seconds. Thanks @​Freakazo for the patch (#2624).

... (truncated)

Commits
  • adff2c9 chore: release v3.27.0
  • b846e62 feat(mcp): state the run's gate and baseline verdicts in the tool result (#2694)
  • 1645a5e fix(action): read every gate verdict from the envelope and fail the job the i...
  • 5cebdde feat(output): publish gate_outcomes on every analysis envelope (#2692)
  • de90d31 fix(action): surface baseline staleness and propagate the stale-baseline gate...
  • 1080fe0 chore(deps-dev): bump rolldown to 1.2.7 in viz-frontend (#2671)
  • d1b4b72 chore(deps): bump ast-v8-to-istanbul to 1.0.6 in the producer corpus (#2672)
  • 9c6910d chore(deps): bump @​tanstack/intent to 0.4.0 (#2670)
  • 4528f4c chore(deps-dev): bump vitest from 4.1.11 to 5.0.0 in /editors/vscode (#2646)
  • be23bf3 chore(deps-dev): bump vitest from 4.1.11 to 5.0.0 in /viz-frontend (#2655)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.1` |
| [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.3` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | `6.0.9` | `6.1.0` |
| [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `7.0.0` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.0.0` | `7.1.1` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `7.0.0` |
| [actions/deploy-pages](https://github.com/actions/deploy-pages) | `5.0.0` | `5.0.1` |
| [fallow-rs/fallow](https://github.com/fallow-rs/fallow) | `2.101.0` | `3.27.0` |



Updates `actions/checkout` from 4.2.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4.2.2...3d3c42e)

Updates `dorny/paths-filter` from 4.0.1 to 4.0.3
- [Release notes](https://github.com/dorny/paths-filter/releases)
- [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md)
- [Commits](dorny/paths-filter@fbd0ab8...ceb8a2b)

Updates `pnpm/action-setup` from 6.0.9 to 6.1.0
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0ebf471...ea17c68)

Updates `actions/setup-node` from 4.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4.4.0...8207627)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@fb8b358...303a32d)

Updates `actions/setup-python` from 5.6.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a26af69...5fda3b9)

Updates `actions/deploy-pages` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@cd2ce8f...368f825)

Updates `fallow-rs/fallow` from 2.101.0 to 3.27.0
- [Release notes](https://github.com/fallow-rs/fallow/releases)
- [Changelog](https://github.com/fallow-rs/fallow/blob/main/release.toml)
- [Commits](fallow-rs/fallow@5da5e73...adff2c9)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: dorny/paths-filter
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: pnpm/action-setup
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: fallow-rs/fallow
  dependency-version: 3.27.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 56a31351-cf2c-4939-8dcc-d1679775de18

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants