chore(deps): bump the github-actions group across 1 directory with 6 updates - #6169
Merged
runningcode merged 1 commit intoSep 28, 2026
Merged
Conversation
…updates Bumps the github-actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | | [getsentry/craft](https://github.com/getsentry/craft) | `2.31.0` | `2.31.2` | | [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | | [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | Updates `github/codeql-action/init` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) Updates `getsentry/craft` from 2.31.0 to 2.31.2 - [Release notes](https://github.com/getsentry/craft/releases) - [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md) - [Commits](getsentry/craft@55694f8...25028d0) Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/danger dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/craft dependency-version: 2.31.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/updater dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/validate-pr dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
requested review from
0xadam-brown,
markushi,
romtsn and
runningcode
as code owners
September 28, 2026 04:37
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
runningcode
approved these changes
Sep 28, 2026
📲 Install BuildsAndroid
|
runningcode
deleted the
dependabot/github_actions/github-actions-fa382b61ac
branch
September 28, 2026 11:09
runningcode
added a commit
that referenced
this pull request
Sep 29, 2026
* docs: Warn about sendDefaultPii removal (#6156) Make the upcoming removal visible in the data collection changelog entry so customers know to migrate before the next major SDK version. Co-authored-by: Claude <noreply@anthropic.com> * release: 8.58.0 * docs(changelog): Remove warning indentation (#6157) Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com> Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io> * feat(core): Deprecate sendDefaultPii (#6158) * feat(core): Deprecate sendDefaultPii Mark the SentryOptions accessors as deprecated and scheduled for removal in 9.0. Direct users to dataCollection while retaining legacy fallback behavior throughout 8.x. Co-Authored-By: Claude <noreply@anthropic.com> * changelog --------- Co-authored-by: Claude <noreply@anthropic.com> * feat(android): Make tombstone merge time threshold configurable (#6154) * feat(android): Make tombstone merge time threshold configurable * changelog * ref(android): Drop duplicate no-match log and document the merge threshold default * docs(android): Expand tombstone merge threshold javadoc * chore(deps): bump the github-actions group across 1 directory with 6 updates (#6169) Bumps the github-actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | | [getsentry/craft](https://github.com/getsentry/craft) | `2.31.0` | `2.31.2` | | [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | | [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` | Updates `github/codeql-action/init` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) Updates `getsentry/craft` from 2.31.0 to 2.31.2 - [Release notes](https://github.com/getsentry/craft/releases) - [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md) - [Commits](getsentry/craft@55694f8...25028d0) Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md) - [Commits](getsentry/github-workflows@607fed7...959162c) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/danger dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/craft dependency-version: 2.31.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/updater dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows/validate-pr dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(detekt): Ignore FunctionNaming for Composable functions (#6176) Compose functions that emit UI are PascalCase by convention, which detekt's default FunctionNaming pattern flags. Follow detekt's Compose guide and skip the rule for @composable functions. Fixes JAVA-748 Fixes #6175 Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(android): Compile Android modules against Android SDK 37.2 (#6172) Updates our compile SDK version from 37.0 to 37.2 for all Sentry Android modules, which lays the groundwork for accommodating new MemoryLimiter flags introduced in 37.2. Introduces a mechanism that lets us support compilation against minor SDK versions for any future release. * ref(android): Match MemoryLimiter app exit reason introduced in Android 37.2 (JAVA-687) (#6174) Android 37.2 introduced a new ApplicationExitInfo.REASON_MEMORY_LIMITER flag. This commit updates our MemoryLimiterIntegration code to match against it (while preserving ouro previous matching logic). No new Android API guard is needed for the new flag because: - we already check MemoryLimiterIntegration registration against API 37; and - REASON_MEMORY_LIMITER is a static integer constant and will be inlined as an integer by the Java compiler (meaning we don't need extra protection for devices on 37.0 or 37.1). * build(detekt): Apply remaining Compose guide settings (#6179) Add the rest of detekt's Compose guide on top of the FunctionNaming change from #6176. Keep accepting SCREAMING_CASE top-level constants, because the guide's PascalCase-only pattern would flag every existing TRACE_ORIGIN-style constant. Refs JAVA-748 Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs: Link Data Collection changelog to guides (#6180) Replace duplicated configuration details in the 8.58.0 changelog with links to the Android, Java, and Spring Boot documentation while retaining the sendDefaultPii removal warning. Co-authored-by: Claude <noreply@anthropic.com> * fix(core): Clear the persisted replay id when resetting the scope cache (#6033) * fix(core): Clear the persisted replay id when resetting the scope cache resetCache() clears every other persisted scope value on init but leaves replay.json in place, so a replay id written by a previous process can still be attached to events from the current one. The reset already runs after the integrations that consume those values, so deleting it here is safe. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * changelog * Remove comment Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io> * build(detekt): Lint all Kotlin modules (#6178) * build(detekt): Apply Compose guide and lint all Kotlin modules Add the remaining settings from detekt's Compose guide. Keep accepting SCREAMING_CASE top-level constants, because the guide's PascalCase-only pattern would flag every existing TRACE_ORIGIN-style constant. sentry-compose had the detekt plugin applied but the task was always NO-SOURCE, because the default source set is src/main and a multiplatform module keeps its code in src/androidMain. Point it at the Android source sets. Also enable detekt in sentry-android-replay, where it was commented out, and in the Kotlin modules that never applied it. The newly linted modules have 298 existing findings. Record them in per-module baselines so check passes and only new issues fail. They can be fixed in follow-ups. Refs JAVA-748 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * build(detekt): Move Compose guide settings to a separate PR Regenerate the baselines against main's config so this PR doesn't depend on the config change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Alexander Dinauer <adinauer@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: adinauer <2542832+adinauer@users.noreply.github.com> Co-authored-by: sentry-release-bot[bot] <180476844+sentry-release-bot[bot]@users.noreply.github.com> Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com> Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io> Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adam Brown <adam.brown@sentry.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 6 updates in the / directory:
4.38.04.38.24.38.04.38.23.4.03.4.12.31.02.31.23.4.03.4.13.4.03.4.1Updates
github/codeql-action/initfrom 4.38.0 to 4.38.2Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
github/codeql-action/analyzefrom 4.38.0 to 4.38.2Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
getsentry/github-workflows/dangerfrom 3.4.0 to 3.4.1Release notes
Sourced from getsentry/github-workflows/danger's releases.
Changelog
Sourced from getsentry/github-workflows/danger's changelog.
... (truncated)
Commits
959162crelease: 3.4.1573d8affix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)6651df0fix(updater): prevent maintenance from racing ancestry cleanup (#177)45c8e3achore: cleanup changelog (#176)229617dfix(danger): preserve prepared workspaces with optional checkout (#175)14b30d6fix(updater): distinguish newer pins from divergent history (#174)4013fc6ci: bump danger tests to Node.js 24 (#170)c802283fix(danger): harden extra-install-packages against host-shell interpolation (...b6d9e26Merge branch 'release/3.4.0'Updates
getsentry/craftfrom 2.31.0 to 2.31.2Release notes
Sourced from getsentry/craft's releases.
Changelog
Sourced from getsentry/craft's changelog.
... (truncated)
Commits
25028d0release: 2.31.2bba2a96fix(deps): remediate open security alerts (#881)7137f20fix(github): Filter artifacts by name when fetching revision artifact (#880)960a1c7meta: Bump new development version7dab3b4Merge remote-tracking branch 'remotes/origin/release/2.31.1'b5451aarelease: 2.31.105953a0fix(npm): Show publish stderr at info level (#877)c17a278build(deps-dev): bump vitest from 4.1.8 to 4.1.11 (#875)a2e0589build(deps): bump sharp from 0.35.0 to 0.35.4 in /docs (#874)12f3b02build(deps-dev): bump js-yaml from 4.3.1 to 4.3.2 (#876)Updates
getsentry/github-workflows/updaterfrom 3.4.0 to 3.4.1Release notes
Sourced from getsentry/github-workflows/updater's releases.
Changelog
Sourced from getsentry/github-workflows/updater's changelog.
... (truncated)
Commits
959162crelease: 3.4.1573d8affix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)6651df0fix(updater): prevent maintenance from racing ancestry cleanup (#177)45c8e3achore: cleanup changelog (#176)229617dfix(danger): preserve prepared workspaces with optional checkout (#175)14b30d6fix(updater): distinguish newer pins from divergent history (#174)4013fc6ci: bump danger tests to Node.js 24 (#170)c802283fix(danger): harden extra-install-packages against host-shell interpolation (...b6d9e26Merge branch 'release/3.4.0'Updates
getsentry/github-workflows/validate-prfrom 3.4.0 to 3.4.1Release notes
Sourced from getsentry/github-workflows/validate-pr's releases.
Changelog
Sourced from getsentry/github-workflows/validate-pr's changelog.
... (truncated)
Commits
959162crelease: 3.4.1573d8affix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)6651df0fix(updater): prevent maintenance from racing ancestry cleanup (#177)45c8e3achore: cleanup changelog (#176)229617dfix(danger): preserve prepared workspaces with optional checkout (#175)14b30d6fix(updater): distinguish newer pins from divergent history (#174)4013fc6ci: bump danger tests to Node.js 24 (#170)c802283fix(danger): harden extra-install-packages against host-shell interpolation (...b6d9e26Merge branch 'release/3.4.0'Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions