chore(deps): bump the github-actions group across 1 directory with 9 updates - #455
Conversation
…updates Bumps the github-actions group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` | | [docker/login-action](https://github.com/docker/login-action) | `4.4.0` | `4.5.2` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.3.0` | `7.0.0` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.3.2` | `9.0.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` | Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@9c091bb...3d3c42e) Updates `docker/login-action` from 4.4.0 to 4.5.2 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@af1e73f...371161b) Updates `github/codeql-action/init` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) Updates `github/codeql-action/autobuild` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) Updates `actions/setup-python` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@ece7cb0...5fda3b9) Updates `astral-sh/setup-uv` from 8.3.2 to 9.0.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@11f9893...c771a70) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@4eaacf0...2d11466) Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/autobuild dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: astral-sh/setup-uv dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
📝 WalkthroughWalkthrough여러 GitHub Actions 워크플로우에서 Changes워크플로우 액션 핀 업데이트
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
.github/workflows/gh-pages.yml (1)
45-46: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick winsetup-uv 캐시 정리 동작을 모든 캐시 사용 워크플로에서 명시하세요.
setup-uv v9의
prune-cache기본값 변경으로 캐시 정리 정책이 달라질 수 있습니다.
.github/workflows/gh-pages.yml#L45-L46:prune-cache: true를 추가하세요..github/workflows/quality-gate.yml#L26-L27:prune-cache: true를 추가하세요..github/workflows/tests.yml#L26-L27:prune-cache: true를 추가하세요.
.github/workflows/release.yml은 캐시를 비활성화하므로 이 변경의 영향을 받지 않습니다.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/gh-pages.yml around lines 45 - 46, Explicitly set prune-cache: true on the setup-uv steps in .github/workflows/gh-pages.yml lines 45-46, .github/workflows/quality-gate.yml lines 26-27, and .github/workflows/tests.yml lines 26-27. No change is needed in .github/workflows/release.yml because its cache is disabled.Source: MCP tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/clusterfuzzlite.yml:
- Line 17: Disable checkout credential persistence in the checkout steps at
.github/workflows/clusterfuzzlite.yml:17-17 and
.github/workflows/dependency-review.yml:18-18 by adding the with configuration
with persist-credentials set to false.
---
Nitpick comments:
In @.github/workflows/gh-pages.yml:
- Around line 45-46: Explicitly set prune-cache: true on the setup-uv steps in
.github/workflows/gh-pages.yml lines 45-46, .github/workflows/quality-gate.yml
lines 26-27, and .github/workflows/tests.yml lines 26-27. No change is needed in
.github/workflows/release.yml because its cache is disabled.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 2bca0e3e-a9f4-49d8-884f-0acfe88ccd34
📒 Files selected for processing (10)
.github/workflows/build-ci-image.yml.github/workflows/clusterfuzzlite.yml.github/workflows/codeql.yml.github/workflows/container-image.yml.github/workflows/dependency-review.yml.github/workflows/gh-pages.yml.github/workflows/quality-gate.yml.github/workflows/release.yml.github/workflows/scorecards.yml.github/workflows/tests.yml
|
@coderabbitai review |
✅ Action performedReview finished.
|
seonghobae
left a comment
There was a problem hiding this comment.
Reviewed the immutable action-SHA updates and the follow-up hardening. Checkout credential persistence is disabled in the read-only workflows identified by review, setup-uv v9 retains the prior cache-pruning behavior where caching is enabled, and release remains intentionally uncached. Current-head checks are the remaining merge gate.
|
@jules Please add a narrowly scoped governance regression test on this PR branch that prevents these reviewed workflow semantics from regressing: read-only checkout steps in |
|
Temporarily parking this workflow dependency update so the base-branch CVE remediation is the sole consumer of the constrained required-workflow queue. The hardened branch is preserved and will be reopened, rebased, and fully revalidated after the security base merge. |
Pull request was closed
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Summary
Updates nine GitHub Actions dependencies to their current pinned commits, including checkout, Docker login, CodeQL, setup-python, setup-uv, OSSF Scorecard, and SARIF upload. Follow-up hardening preserves the repository's existing security and cache semantics by disabling checkout credential persistence in read-only workflows and explicitly retaining setup-uv cache pruning after the v9 default change.
Git Flow target
dependabot/github_actions/develop/*→develop.Verification
762e11330e320d68175d832b0840222bcf01b518.prune-cachewere implemented in all affected workflows.Notes
release.ymlintentionally keeps cache disabled and therefore does not needprune-cache.Dependency updates
actions/checkout7.0.07.0.1docker/login-action4.4.04.5.2github/codeql-action/*4.37.04.37.3actions/setup-python6.3.07.0.0astral-sh/setup-uv8.3.29.0.0ossf/scorecard-action2.4.32.4.4