build(deps): bump the github-actions group across 1 directory with 5 updates - #1747
Draft
dependabot[bot] wants to merge 1 commit into
Draft
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the github-actions group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.21.1` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.4` | `4.38.1` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.2.0` | `4.4.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.2.0` | `4.4.1` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` | Updates `step-security/harden-runner` from 2.20.0 to 2.21.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@bf7454d...e14015d) Updates `github/codeql-action/upload-sarif` from 4.37.4 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@f205ea1...1c5b675) Updates `docker/setup-qemu-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@96fe6ef...9901266) Updates `docker/setup-buildx-action` from 4.2.0 to 4.4.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@bb05f3f...f87e599) Updates `docker/build-push-action` from 7.3.0 to 7.4.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@53b7df9...c3c9e26) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.21.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: ContextualWisdomLab/naruon/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
marked this pull request as draft
September 21, 2026 10:54
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current authority — 2026-09-21 KST
develop@042b0c70531b229af3acbd0421a2f23098d848b328ceffc03875547d7746b17d7d3e75142ae3eab7f985a00030028c9989637b3fafffac07d95e2de2Fresh owner review
This dependency update touches seven repository-local workflows. Four of those files are currently owned as effective delta by canonical stacked-PR validation owner #1691:
.github/workflows/app-ci.yml.github/workflows/bandit.yml.github/workflows/dependency-review.yml.github/workflows/docker-publish.ymlThe other three touched workflows are
deploy.yml,mail-smoke.yml, andpr-governance.yml. The proposed SHA-pinned action updates may be useful, but this direct-developgeneration cannot be accepted independently while it would merge around #1691's still-unintegrated workflow semantics and tests.The current patch updates
step-security/harden-runner2.20.0→2.21.1,github/codeql-action/upload-sarif4.37.4→4.38.1, Docker QEMU 4.2.0→4.4.0, Buildx 4.2.0→4.4.1, and build-push 7.3.0→7.4.0. These are dependency-version intents, not authority to replace #1691, central.githubreusable workflow contracts, or repository-local tests/governance.Required repair path
Keep this PR open as the generated dependency-update lane. After #1691 reaches an accepted current generation/protected ancestry (or a verified complete successor is identified), ordinary/non-force restack this exact dependency intent onto that owner generation, preserve #1691's workflow semantics/tests, retain only the still-current SHA-pin updates, and reacquire all exact-head security/CI/review evidence. If upstream pins move again before that point, adopt the newer Dependabot generation rather than force-rewriting this branch.
Do not use
@dependabot rebasemerely to bypass the owner graph, do not copy central workflow source into Naruon, do not weaken pinned-SHA or security controls, and do not treat Dependabot metadata/release notes as executable acceptance evidence.No force push, destructive rebase, self-approval, blind rerun, source-neutral wake commit, predecessor receipt transfer, duplicate CI owner, or gate weakening.