Skip to content

chore(deps): Bump actions/stale from 9 to 10 - #2

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/stale-10
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/stale-10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 20, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/stale from 9 to 10.

Release notes

Sourced from actions/stale's releases.

v10.0.0

What's Changed

Breaking Changes

Enhancement

Dependency Upgrades

Documentation changes

New Contributors

Full Changelog: actions/stale@v9...v10.0.0

v9.1.0

What's Changed

New Contributors

Full Changelog: actions/stale@v9...v9.1.0

Changelog

Sourced from actions/stale's changelog.

Changelog

[10.1.0]

What's Changed

[10.0.0]

What's Changed

Breaking Changes

Enhancement

Dependency Upgrades

Documentation changes

[9.1.0]

What's Changed

[9.0.0]

Breaking Changes

  1. Action is now stateful: If the action ends because of operations-per-run then the next run will start from the first unprocessed issue skipping the issues processed during the previous run(s). The state is reset when all the issues are processed. This should be considered for scheduling workflow runs.
  2. Version 9 of this action updated the runtime to Node.js 20. All scripts are now run with Node.js 20 instead of Node.js 16 and are affected by any breaking changes between Node.js 16 and 20.

... (truncated)

Commits
  • b5d41d4 build(deps-dev): bump lodash from 4.17.21 to 4.17.23 (#1313)
  • dcd2b94 Fix punycode and url.parse Deprecation Warnings (#1312)
  • d6f8a33 build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (#1304)
  • a21a081 Fix checking state cache (fix #1136), also switch to octokit methods (#1152)
  • 9971854 build(deps): bump actions/checkout from 4 to 6 (#1306)
  • 5611b9d build(deps): bump actions/publish-action from 0.3.0 to 0.4.0 (#1291)
  • fad0de8 Improves error handling when rate limiting is disabled on GHES. (#1300)
  • 39bea7d Add Missing Input Reading for only-issue-types (#1298)
  • e46bbab build(deps-dev): bump @​types/node from 20.10.3 to 24.2.0 and document breakin...
  • 65d1d48 build(deps-dev): bump eslint-config-prettier from 8.10.0 to 10.1.8 (#1276)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/stale](https://github.com/actions/stale) from 9 to 10.
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](actions/stale@v9...v10)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-version: '10'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 20, 2026
@dependabot
dependabot Bot requested a review from 4444J99 as a code owner March 20, 2026 19:09
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 20, 2026

@llamapreview llamapreview Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Code Review by LlamaPReview

🎯 TL;DR & Recommendation

Recommendation: Request Changes

This PR updates the actions/stale workflow to v10, which introduces a critical breaking change that could break workflows if runner compatibility is not verified, alongside other behavioral changes requiring testing.

🌟 Strengths

  • Security improvement by patching a critical vulnerability in the dependency.
Priority File Category Impact Summary (≤12 words) Anchors
P1 .github/workflows/stale.yml Architecture Breaking change risks workflow failure due to runner incompatibility.
P2 .github/workflows/stale.yml Testing Stateful behavior changes may affect scheduling and need validation.
P2 .github/workflows/stale.yml Security Patches critical vulnerability, enhancing security of the action.

🔍 Notable Themes

  • Dependency upgrade with mixed breaking changes and improvements that require careful verification and testing.

💡 Have feedback? We'd love to hear it in our GitHub Discussions.
✨ This review was generated by LlamaPReview Advanced, which is free for all open-source projects. Learn more.

Comment on lines 12 to 15
steps:
- uses: actions/stale@v9
- uses: actions/stale@v10
with:
stale-issue-message: 'Marked stale due to inactivity. Will close in 14 days.'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 | Confidence: High

  • The PR updates actions/stale from v9 to v10. According to the release notes, v10.0.0 contains a breaking change: "Upgrade to node 24 by @salmanmkc in Upgrade to node 24 actions/stale#1279. Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release." This is a public API/behavior change that could break existing workflows. The workflow currently uses runs-on: ubuntu-latest, which should automatically provide compatible runner versions over time, but there could be a transition period where the action fails due to runner version mismatch. This requires explicit verification that the GitHub Actions runner environment meets the minimum version requirement.

  • Speculative: The actions/stale v10 release includes several behavioral changes worth noting: 1) The action is stateful (continues from previous runs when hitting operation limits), which was introduced in v9 but is relevant for scheduling considerations. 2) Version 9 also introduced breaking changes from Node.js 16 to Node.js 20. Since we're moving directly from v9 to v10, we're subject to both sets of breaking changes. The workflow should be tested to ensure the stateful behavior doesn't cause unexpected results with the current schedule (cron: '0 9 * * 1') and operation limits. While the configuration appears standard, the cumulative effect of these breaking changes warrants validation.

  • The update addresses a security vulnerability. The release notes mention: "Upgrade form-data to bring in fix for critical vulnerability by @gowridurgad in Bump form-data to bring in fix for critical vulnerability actions/stale#1277." While this doesn't directly introduce a security issue in our codebase, it mitigates a potential vulnerability in a dependency used by the GitHub Action. This is a positive security improvement that should be highlighted as a benefit of the upgrade.

@4444J99

4444J99 commented Mar 24, 2026

Copy link
Copy Markdown
Owner

Closing — disabling Dependabot version updates system-wide. Security alerts remain active.

@4444J99 4444J99 closed this Mar 24, 2026
@4444J99
4444J99 deleted the dependabot/github_actions/actions/stale-10 branch March 24, 2026 01:10
@dependabot @github

dependabot Bot commented on behalf of github Mar 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant