Skip to content

build(deps): Bump the github-actions group across 1 directory with 11 updates - #175

Merged
rajbos merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-c30850a082
Aug 31, 2026
Merged

rajbos merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-c30850a082

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 11 updates in the / directory:

Package From To
devops-actions/.github/.github/workflows/actionlint.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
devops-actions/.github/.github/workflows/actions-dependencies.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
devops-actions/.github/.github/workflows/actions-example-checker.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
devops-actions/.github/.github/workflows/approve-dependabot-pr.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
step-security/harden-runner 2.20.1 2.21.0
github/codeql-action/init 4.37.6 4.37.8
github/codeql-action/autobuild 4.37.6 4.37.8
github/codeql-action/analyze 4.37.6 4.37.8
devops-actions/.github/.github/workflows/dependency-review.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
devops-actions/.github/.github/workflows/issue-pr-tag.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51
devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml 72f72c4ce25d0ab32530f581be0de7e914365c29 e537f6767594e8d4cfff18edf24e5b4e899b0e51

Updates devops-actions/.github/.github/workflows/actionlint.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/actions-dependencies.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/actions-example-checker.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/approve-dependabot-pr.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates step-security/harden-runner from 2.20.1 to 2.21.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.21.0

What's Changed

  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0

Commits
  • 05e3151 Merge pull request #684 from step-security/rc-42
  • 0f37afa fix: ignore denied-endpoints on non-enterprise tier
  • 93b58ee fix: resolve cache host read-first and never downgrade egress policy
  • e7399dd fix: align deny-list mode detection with agent and log when both endpoint inp...
  • c16689f test: add denied_endpoints to Configuration fixtures and cover deny-list merge
  • 40b99cf Merge pull request #682 from rohan-stepsecurity/rp/feat/codebuild-self-v2
  • fedec02 Merge branch 'rc-42' into rp/feat/codebuild-self-v2
  • 5361fb1 feat: add build artifacts
  • 286474f feat: Support Bravo agent install on CodeBuild runners
  • 051ec05 Merge pull request #683 from h0x0er/jatin/deny-list
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.37.6 to 4.37.8

Release notes

Sourced from github/codeql-action/init's releases.

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

... (truncated)

Commits
  • db488dd Merge pull request #4102 from github/update-v4.37.8-9ee088e13
  • 1845f5b Update changelog for v4.37.8
  • 9ee088e Merge pull request #4080 from github/henrymercer/studious-giggle
  • 1aef003 Address review feedback on overlay disk flags
  • 508b83b Merge main into overlay minimum disk feature branch
  • d97b342 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
  • 47fa622 Make EACCES a ConfigurationError
  • 45693cc Refactor ENOSPC check into isDiskConfigurationError function
  • c2fd8f5 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
  • c56f48e Log unexpected conditions during caching CLI output
  • Additional commits viewable in compare view

Updates github/codeql-action/autobuild from 4.37.6 to 4.37.8

Release notes

Sourced from github/codeql-action/autobuild's releases.

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085
Changelog

Sourced from github/codeql-action/autobuild's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

... (truncated)

Commits
  • db488dd Merge pull request #4102 from github/update-v4.37.8-9ee088e13
  • 1845f5b Update changelog for v4.37.8
  • 9ee088e Merge pull request #4080 from github/henrymercer/studious-giggle
  • 1aef003 Address review feedback on overlay disk flags
  • 508b83b Merge main into overlay minimum disk feature branch
  • d97b342 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
  • 47fa622 Make EACCES a ConfigurationError
  • 45693cc Refactor ENOSPC check into isDiskConfigurationError function
  • c2fd8f5 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
  • c56f48e Log unexpected conditions during caching CLI output
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.37.6 to 4.37.8

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

... (truncated)

Commits
  • db488dd Merge pull request #4102 from github/update-v4.37.8-9ee088e13
  • 1845f5b Update changelog for v4.37.8
  • 9ee088e Merge pull request #4080 from github/henrymercer/studious-giggle
  • 1aef003 Address review feedback on overlay disk flags
  • 508b83b Merge main into overlay minimum disk feature branch
  • d97b342 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
  • 47fa622 Make EACCES a ConfigurationError
  • 45693cc Refactor ENOSPC check into isDiskConfigurationError function
  • c2fd8f5 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
  • c56f48e Log unexpected conditions during caching CLI output
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/dependency-review.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/issue-pr-tag.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

Updates devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51

Commits
  • e537f67 Merge pull request #348 from devops-actions/dependabot/github_actions/devops-...
  • 2cb1a5d Merge pull request #347 from devops-actions/dependabot/github_actions/devops-...
  • 277cb07 Merge pull request #346 from devops-actions/dependabot/github_actions/github/...
  • 83a3a8f deps: bump devops-actions/secure-action-inputs from 1.0.1 to 1.0.2
  • 920a345 deps: bump devops-actions/actionlint from 0.1.12 to 0.1.13
  • d501b5d deps: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8
  • 1eb193a Merge pull request #345 from devops-actions/dependabot/github_actions/jesseho...
  • 2707fa4 deps: bump jessehouwing/actions-dependency-submission
  • a2dcba2 deps: bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.7
  • afab007 deps: bump actions/setup-node from 6.4.0 to 7.0.0
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from rajbos as a code owner August 17, 2026 15:19
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 17, 2026
@github-actions

github-actions Bot commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA cd130ad.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

.github/workflows/ossf-analysis.yml

PackageVersionLicenseIssue Type
devops-actions/.github/.github/workflows/rw-ossf-scorecard.ymle537f6767594e8d4cfff18edf24e5b4e899b0e51NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/github/codeql-action/analyze db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 UnknownUnknown
actions/github/codeql-action/autobuild db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 UnknownUnknown
actions/github/codeql-action/init db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 UnknownUnknown
actions/step-security/harden-runner 05e31511f85b41b11d1cf0ef85d0992719546e2c 🟢 7.8
Details
CheckScoreReason
Binary-Artifacts🟢 10no binaries found in the repo
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
CI-Tests🟢 105 out of 5 merged PRs checked by a CI test -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Code-Review🟢 10all changesets reviewed
Contributors🟢 6project has 2 contributing companies or organizations -- score normalized to 6
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Dependency-Update-Tool🟢 10update tool detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
SAST🟢 9SAST tool detected but not run on all commits
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Vulnerabilities⚠️ 022 existing vulnerabilities detected
actions/devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml e537f6767594e8d4cfff18edf24e5b4e899b0e51 UnknownUnknown

Scanned Files

  • .github/workflows/codeql.yml
  • .github/workflows/ossf-analysis.yml

@github-actions

Copy link
Copy Markdown
Contributor

Tagging @rajbos for notifications

… updates

Bumps the github-actions group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [devops-actions/.github/.github/workflows/actionlint.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [devops-actions/.github/.github/workflows/actions-dependencies.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [devops-actions/.github/.github/workflows/actions-example-checker.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [devops-actions/.github/.github/workflows/approve-dependabot-pr.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.1` | `2.21.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.6` | `4.37.8` |
| [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.37.6` | `4.37.8` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.6` | `4.37.8` |
| [devops-actions/.github/.github/workflows/dependency-review.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [devops-actions/.github/.github/workflows/issue-pr-tag.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |
| [devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml](https://github.com/devops-actions/.github) | `72f72c4ce25d0ab32530f581be0de7e914365c29` | `e537f6767594e8d4cfff18edf24e5b4e899b0e51` |



Updates `devops-actions/.github/.github/workflows/actionlint.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `devops-actions/.github/.github/workflows/actions-dependencies.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `devops-actions/.github/.github/workflows/actions-example-checker.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `devops-actions/.github/.github/workflows/approve-dependabot-pr.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `step-security/harden-runner` from 2.20.1 to 2.21.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@b09bb98...05e3151)

Updates `github/codeql-action/init` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

Updates `github/codeql-action/autobuild` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

Updates `devops-actions/.github/.github/workflows/dependency-review.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `devops-actions/.github/.github/workflows/issue-pr-tag.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

Updates `devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml` from 72f72c4ce25d0ab32530f581be0de7e914365c29 to e537f6767594e8d4cfff18edf24e5b4e899b0e51
- [Release notes](https://github.com/devops-actions/.github/releases)
- [Commits](devops-actions/.github@72f72c4...e537f67)

---
updated-dependencies:
- dependency-name: devops-actions/.github/.github/workflows/actionlint.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/actions-dependencies.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/actions-example-checker.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/approve-dependabot-pr.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/dependency-review.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/issue-pr-tag.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: devops-actions/.github/.github/workflows/rw-ossf-scorecard.yml
  dependency-version: a2dcba26c2b4e873ec3b9c6291ac680e2ea452a2
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: step-security/harden-runner
  dependency-version: 2.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): Bump the github-actions group with 11 updates build(deps): Bump the github-actions group across 1 directory with 11 updates Aug 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-c30850a082 branch from 8cd5d52 to cd130ad Compare August 24, 2026 15:20
@rajbos
rajbos merged commit 878c117 into main Aug 31, 2026
12 checks passed
@rajbos
rajbos deleted the dependabot/github_actions/github-actions-c30850a082 branch August 31, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant