Skip to content

build(deps): bump the github-actions group across 1 directory with 5 updates - #1747

Draft
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/github-actions-ec22632096
Draft

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/github-actions-ec22632096

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-21 KST

  • protected base: develop@042b0c70531b229af3acbd0421a2f23098d848b3
  • generated Dependabot head: 28ceffc03875547d7746b17d7d3e75142ae3eab7
  • canonical overlapping Naruon-local CI owner: fix(ci): make stacked PR validation a develop prerequisite #1691 f985a00030028c9989637b3fafffac07d95e2de2
  • lifecycle: Draft / useful dependency-update intent retained / wrong-base owner overlap unresolved / do not merge or rebase destructively

Fresh owner review

This dependency update touches seven repository-local workflows. Four of those files are currently owned as effective delta by canonical stacked-PR validation owner #1691:

  • .github/workflows/app-ci.yml
  • .github/workflows/bandit.yml
  • .github/workflows/dependency-review.yml
  • .github/workflows/docker-publish.yml

The other three touched workflows are deploy.yml, mail-smoke.yml, and pr-governance.yml. The proposed SHA-pinned action updates may be useful, but this direct-develop generation cannot be accepted independently while it would merge around #1691's still-unintegrated workflow semantics and tests.

The current patch updates step-security/harden-runner 2.20.0→2.21.1, github/codeql-action/upload-sarif 4.37.4→4.38.1, Docker QEMU 4.2.0→4.4.0, Buildx 4.2.0→4.4.1, and build-push 7.3.0→7.4.0. These are dependency-version intents, not authority to replace #1691, central .github reusable workflow contracts, or repository-local tests/governance.

Required repair path

Keep this PR open as the generated dependency-update lane. After #1691 reaches an accepted current generation/protected ancestry (or a verified complete successor is identified), ordinary/non-force restack this exact dependency intent onto that owner generation, preserve #1691's workflow semantics/tests, retain only the still-current SHA-pin updates, and reacquire all exact-head security/CI/review evidence. If upstream pins move again before that point, adopt the newer Dependabot generation rather than force-rewriting this branch.

Do not use @dependabot rebase merely to bypass the owner graph, do not copy central workflow source into Naruon, do not weaken pinned-SHA or security controls, and do not treat Dependabot metadata/release notes as executable acceptance evidence.

No force push, destructive rebase, self-approval, blind rerun, source-neutral wake commit, predecessor receipt transfer, duplicate CI owner, or gate weakening.

…updates

Bumps the github-actions group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.21.1` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.4` | `4.38.1` |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.2.0` | `4.4.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.2.0` | `4.4.1` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |



Updates `step-security/harden-runner` from 2.20.0 to 2.21.1
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@bf7454d...e14015d)

Updates `github/codeql-action/upload-sarif` from 4.37.4 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@f205ea1...1c5b675)

Updates `docker/setup-qemu-action` from 4.2.0 to 4.4.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@96fe6ef...9901266)

Updates `docker/setup-buildx-action` from 4.2.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@bb05f3f...f87e599)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.21.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 21, 2026 10:52
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: ContextualWisdomLab/naruon/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: b5188841-17a7-487e-8dcb-a3bf763906a8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants