Skip to content

chore(deps): bump the github-actions group across 1 directory with 6 updates - #6169

Merged
runningcode merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-fa382b61ac
Sep 28, 2026
Merged

runningcode merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-fa382b61ac

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 6 updates in the / directory:

Package From To
github/codeql-action/init 4.38.0 4.38.2
github/codeql-action/analyze 4.38.0 4.38.2
getsentry/github-workflows/danger 3.4.0 3.4.1
getsentry/craft 2.31.0 2.31.2
getsentry/github-workflows/updater 3.4.0 3.4.1
getsentry/github-workflows/validate-pr 3.4.0 3.4.1

Updates github/codeql-action/init from 4.38.0 to 4.38.2

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.0 to 4.38.2

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates getsentry/github-workflows/danger from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/danger's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/danger's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Updates getsentry/craft from 2.31.0 to 2.31.2

Release notes

Sourced from getsentry/craft's releases.

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880

2.31.1

Bug Fixes 🐛

Internal Changes 🔧

Deps

Deps Dev

Changelog

Sourced from getsentry/craft's changelog.

Changelog

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880

2.31.1

Bug Fixes 🐛

Internal Changes 🔧

Deps

Deps Dev

2.31.0

New Features ✨

  • (config) Top-level workspaces schema + --workspace selector by @​BYK in #848
  • Propagate release workspaces by @​BYK in #872

Bug Fixes 🐛

2.30.1

Bug Fixes 🐛

  • (vercel) Pass prebuilt output directory by @​BYK in #868

2.30.0

New Features ✨

  • (vercel) Allow project ID in target config by @​BYK in #867

... (truncated)

Commits
  • 25028d0 release: 2.31.2
  • bba2a96 fix(deps): remediate open security alerts (#881)
  • 7137f20 fix(github): Filter artifacts by name when fetching revision artifact (#880)
  • 960a1c7 meta: Bump new development version
  • 7dab3b4 Merge remote-tracking branch 'remotes/origin/release/2.31.1'
  • b5451aa release: 2.31.1
  • 05953a0 fix(npm): Show publish stderr at info level (#877)
  • c17a278 build(deps-dev): bump vitest from 4.1.8 to 4.1.11 (#875)
  • a2e0589 build(deps): bump sharp from 0.35.0 to 0.35.4 in /docs (#874)
  • 12f3b02 build(deps-dev): bump js-yaml from 4.3.1 to 4.3.2 (#876)
  • Additional commits viewable in compare view

Updates getsentry/github-workflows/updater from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/updater's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/updater's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Updates getsentry/github-workflows/validate-pr from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/validate-pr's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/validate-pr's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/craft](https://github.com/getsentry/craft) | `2.31.0` | `2.31.2` |
| [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |



Updates `github/codeql-action/init` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/craft` from 2.31.0 to 2.31.2
- [Release notes](https://github.com/getsentry/craft/releases)
- [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md)
- [Commits](getsentry/craft@55694f8...25028d0)

Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/danger
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/craft
  dependency-version: 2.31.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/updater
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/validate-pr
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from adinauer as a code owner September 28, 2026 04:37
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@runningcode runningcode reopened this Sep 28, 2026
@sentry

sentry Bot commented Sep 28, 2026

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.58.0 (1) release

⚙️ sentry-android Build Distribution Settings

@runningcode
runningcode merged commit cf43fac into main Sep 28, 2026
131 of 135 checks passed
@runningcode
runningcode deleted the dependabot/github_actions/github-actions-fa382b61ac branch September 28, 2026 11:09
runningcode added a commit that referenced this pull request Sep 29, 2026
* docs: Warn about sendDefaultPii removal (#6156)

Make the upcoming removal visible in the data collection changelog entry
so customers know to migrate before the next major SDK version.

Co-authored-by: Claude <noreply@anthropic.com>

* release: 8.58.0

* docs(changelog): Remove warning indentation (#6157)

Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com>
Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io>

* feat(core): Deprecate sendDefaultPii (#6158)

* feat(core): Deprecate sendDefaultPii

Mark the SentryOptions accessors as deprecated and scheduled for removal in 9.0. Direct users to dataCollection while retaining legacy fallback behavior throughout 8.x.

Co-Authored-By: Claude <noreply@anthropic.com>

* changelog

---------

Co-authored-by: Claude <noreply@anthropic.com>

* feat(android): Make tombstone merge time threshold configurable (#6154)

* feat(android): Make tombstone merge time threshold configurable

* changelog

* ref(android): Drop duplicate no-match log and document the merge threshold default

* docs(android): Expand tombstone merge threshold javadoc

* chore(deps): bump the github-actions group across 1 directory with 6 updates (#6169)

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/craft](https://github.com/getsentry/craft) | `2.31.0` | `2.31.2` |
| [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |



Updates `github/codeql-action/init` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/craft` from 2.31.0 to 2.31.2
- [Release notes](https://github.com/getsentry/craft/releases)
- [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md)
- [Commits](getsentry/craft@55694f8...25028d0)

Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/danger
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/craft
  dependency-version: 2.31.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/updater
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/validate-pr
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(detekt): Ignore FunctionNaming for Composable functions (#6176)

Compose functions that emit UI are PascalCase by convention, which
detekt's default FunctionNaming pattern flags. Follow detekt's Compose
guide and skip the rule for @composable functions.

Fixes JAVA-748
Fixes #6175

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(android): Compile Android modules against Android SDK 37.2 (#6172)

Updates our compile SDK version from 37.0 to 37.2 for all Sentry Android modules, which lays the groundwork for accommodating new MemoryLimiter flags introduced in 37.2.

Introduces a mechanism that lets us support compilation against minor SDK versions for any future release.

* ref(android): Match MemoryLimiter app exit reason introduced in Android 37.2 (JAVA-687) (#6174)

Android 37.2 introduced a new ApplicationExitInfo.REASON_MEMORY_LIMITER flag. This commit updates our MemoryLimiterIntegration code to match against it (while preserving ouro previous matching logic).

No new Android API guard is needed for the new flag because:

 - we already check MemoryLimiterIntegration registration against API 37; and
 - REASON_MEMORY_LIMITER is a static integer constant and will be inlined as an integer by the Java compiler (meaning we don't need extra protection for devices on 37.0 or 37.1).

* build(detekt): Apply remaining Compose guide settings (#6179)

Add the rest of detekt's Compose guide on top of the FunctionNaming
change from #6176. Keep accepting SCREAMING_CASE top-level constants,
because the guide's PascalCase-only pattern would flag every existing
TRACE_ORIGIN-style constant.

Refs JAVA-748

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: Link Data Collection changelog to guides (#6180)

Replace duplicated configuration details in the 8.58.0 changelog with links to the Android, Java, and Spring Boot documentation while retaining the sendDefaultPii removal warning.

Co-authored-by: Claude <noreply@anthropic.com>

* fix(core): Clear the persisted replay id when resetting the scope cache (#6033)

* fix(core): Clear the persisted replay id when resetting the scope cache

resetCache() clears every other persisted scope value on init but leaves
replay.json in place, so a replay id written by a previous process can
still be attached to events from the current one. The reset already runs
after the integrations that consume those values, so deleting it here is
safe.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* changelog

* Remove comment

Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>

* build(detekt): Lint all Kotlin modules (#6178)

* build(detekt): Apply Compose guide and lint all Kotlin modules

Add the remaining settings from detekt's Compose guide. Keep accepting
SCREAMING_CASE top-level constants, because the guide's PascalCase-only
pattern would flag every existing TRACE_ORIGIN-style constant.

sentry-compose had the detekt plugin applied but the task was always
NO-SOURCE, because the default source set is src/main and a
multiplatform module keeps its code in src/androidMain. Point it at the
Android source sets. Also enable detekt in sentry-android-replay, where
it was commented out, and in the Kotlin modules that never applied it.

The newly linted modules have 298 existing findings. Record them in
per-module baselines so check passes and only new issues fail. They can
be fixed in follow-ups.

Refs JAVA-748

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* build(detekt): Move Compose guide settings to a separate PR

Regenerate the baselines against main's config so this PR doesn't depend
on the config change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Alexander Dinauer <adinauer@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: adinauer <2542832+adinauer@users.noreply.github.com>
Co-authored-by: sentry-release-bot[bot] <180476844+sentry-release-bot[bot]@users.noreply.github.com>
Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com>
Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io>
Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Brown <adam.brown@sentry.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant