Update github-actions - #4032
Conversation
Signed-off-by: ide-developer <rhoai-ide-konflux@redhat.com>
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited), Repository UI (inherited) Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughPinned commit SHAs/version tags for third-party GitHub Actions are bumped across 21 workflow/action files: docker/login-action (v4.1.0→v4.4.0), docker/setup-buildx-action (v4.1.0→v4.2.0), docker/build-push-action (v7.2.0→v7.3.0), astral-sh/setup-uv (v8.1.0→v8.3.2), actions/setup-go (v6.4.0→v6.5.0), golangci-lint-action (v9.2.0→v9.3.0), actions/cache (v6.0.0→v6.1.0), github/codeql-action (v4.35.4→v4.37.0), actions/setup-python (v6.2.0→v6.3.0), trivy-action (v0.70.0→v0.72.0), actions/stale (v10.2.0→v10.3.0), snok/container-retention-policy (v3.0.1→v3.1.0), jdx/mise-action (v4.0.1→v4.2.0), and pnpm/action-setup (v6.0.8→v6.0.9). No workflow logic, inputs, or job structure changed. Estimated code review effort: 2 (Simple) | ~10 minutes Supply-chain note: every entry is a SHA-pinned bump — verify each new commit SHA resolves to the claimed tag/release upstream before merge (CWE-829: Inclusion of Functionality from Untrusted Control Sphere). Confirm no unpinned 🚥 Pre-merge checks | ✅ 9 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (9 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #4032 +/- ##
=======================================
Coverage 39.70% 39.70%
=======================================
Files 43 43
Lines 5374 5374
Branches 913 913
=======================================
Hits 2134 2134
Misses 3038 3038
Partials 202 202
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
@coderabbitai any exciting new features or worrisome changes in the updated actions? |
🧩 Analysis chain🤖 web_search executed:
Length of output: 7462 🤖 web_search executed:
Length of output: 8475 🤖 web_search executed:
Length of output: 9163 🤖 web_search executed:
Length of output: 7408 🤖 web_search executed:
Length of output: 9574
CVE-2026-33634 (Trivy supply-chain compromise) — relevant to this PR since github/codeql-action v4.37.0 — bumps default CodeQL bundle to 2.26.0. Also ships (not yet enabled) support for a new docker/login-action v4.4.0 — cosmetic/dependency fix only (skips masking an empty actions/stale v10.3.0 — bug fix to ignore stale-labeling events as activity triggers, plus dependency bumps ( snok/container-retention-policy v3.1.0 — fixes a panic on negative durations (DoS-adjacent, not exploitable remotely) and fixes GHCR token parsing broken by GitHub's token-format migration — this is a correctness fix, not hardening. Also adds multi-arch manifest protection so children of multi-arch images you intend to keep aren't pruned. No CVE. Net assessment: nothing in this bump set introduces a new CVE into the pinned SHAs. The one item requiring your attention going forward is the CodeQL ✅ Action performedReview finished.
|
|
@coderabbitai I read through the PR description (Renovate changelog + CodeRabbit review) and cross-checked the actual diff. Here's what stands out. What's in the PR14 packages bumped across 21 workflow/action files — all Things to be mindful of1. 2. 3. 4. 5. 6. CodeRabbit's own PR checks (informational, not from our fix):
7. Approval gate: openshift-ci shows "NOT APPROVED" — needs an OWNERS approval (you're the fallback approver per the bot message) plus review from Nothing here contradicts or threatens the RHAIENG-6163 fix — the grouped PR is exactly what we expected to unblock. Only trivy and codeql-action bundle-version are worth a post-merge glance; everything else is routine. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo "=== Checking SHA-pinning discipline for bumped actions ==="
rg -n 'uses:\s*(github/codeql-action|docker/login-action|docker/setup-buildx-action|docker/build-push-action|actions/stale|actions/cache|actions/setup-go|actions/setup-python|jdx/mise-action|golangci/golangci-lint-action|snok/container-retention-policy|pnpm/action-setup|astral-sh/setup-uv|aquasecurity/trivy)' .github/workflows/*.yaml .github/workflows/*.yml .github/actions/setup-uv/action.yml 2>/dev/null | grep -v '@[0-9a-f]\{40\}' || echo "ALL PINNED: no non-SHA uses lines found"
echo
echo "=== golangci-lint version value in code-quality.yaml ==="
rg -n -B2 -A2 'golangci-lint-action|version:' .github/workflows/code-quality.yaml
echo
echo "=== mise.lock presence check ==="
fd -H 'mise.lock' . || echo "no mise.lock found"
echo
echo "=== setup-uv action.yml version-file input ==="
cat .github/actions/setup-uv/action.ymlLength of output: 2444 Verified. SHA-pinning: confirmed 100% — every golangci-lint-action: confirmed — mise.lock: confirmed absent from the repo, so your point 3 ( setup-uv: confirmed — One correction on your codeql-action note: v4.36.0's bundle-version bump to 2.19.4 is enforced by the action at runtime, not by anything in this repo's config — there's no pinned bundle version to check against, so it's a pure runtime risk, not a config-verifiable one. If any of No other findings beyond what's already listed. Nothing here weakens the sha-pinning control or reopens RHAIENG-6163. (=^ェ^=) |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
rg -n 'golangci-lint-action|version:' .github/workflows/code-quality.yaml -A2 -B2Length of output: 512 🤖 web_search executed:
Length of output: 3925
RHAIENG-6163 mitigation holds — no digest-pin regression on that input.
No new CVE/CWE surface beyond what's already been called out (CVE-2026-33634 Trivy tag-hijack — irrelevant here due to SHA-pinning; CWE-829 CodeQL |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
echo "--- code-quality.yaml golangci section ---"
rg -n "golangci|version:" .github/workflows/code-quality.yaml -A2 -B2
echo "--- semgrep.yaml exists ---"
fd -t f semgrep.yaml .github/workflows
echo "--- mise.lock search ---"
fd -H "mise.lock" .
echo "--- gitleaks.yaml mise config ---"
cat .github/workflows/gitleaks.yaml | rg -n "mise" -A3 -B3Length of output: 1533 🤖 web_search executed:
Length of output: 2783 🤖 web_search executed:
Length of output: 12525
Confirmed correct:
One correction to your writeup: the mise-action bump is v4.0.1 → v4.2.0, not "v4.0.1 → v4.1.0" alone — v4.1.0 introduced the Remaining unverified item: your claim that Renovate's own SHA resolution covers the "verify each SHA resolves to its claimed tag" due diligence. That's true for the resolution step, but it does not protect against a tag being force-pushed after Renovate opened the PR and before merge — a live TOCTOU gap for SHA-pin renovation (relevant given the CVE-2026-33634 tag-hijack precedent I cited earlier). Worth a final No open objections to your assessment. Approval gate (item 7) is outside my visibility — that's on OWNERS review. [resolve] ✏️ Learnings added
|
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jiridanek The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Caution Review failedAn error occurred during the review process. Please try again later. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This PR contains the following updates:
v6.0.0→v6.1.0v6.4.0→v6.5.0v6.2.0→v6.3.0v10.2.0→v10.3.0v0.70.0→v0.72.0v8.1.0→v8.3.2v7.2.0→v7.3.0v4.1.0→v4.4.0v4.1.0→v4.2.0v4.35.4→v4.37.0v9.2.0→v9.3.0v4.0.1→v4.2.0v6.0.8→v6.0.9v3.0.1→v3.1.0Release Notes
actions/cache (actions/cache)
v6.1.0Compare Source
What's Changed
Full Changelog: actions/cache@v6...v6.1.0
actions/setup-go (actions/setup-go)
v6.5.0Compare Source
What's Changed
Dependency update
New Contributors
Full Changelog: actions/setup-go@v6...v6.5.0
actions/setup-python (actions/setup-python)
v6.3.0Compare Source
What's Changed
Enhancement
Dependency update
Documentation
New Contributors
Full Changelog: actions/setup-python@v6.2.0...v6.3.0
actions/stale (actions/stale)
v10.3.0Compare Source
What's Changed
Bug Fix
Dependency Updates
New Contributors
Full Changelog: actions/stale@v10...v10.3.0
aquasecurity/trivy (aquasecurity/trivy)
v0.72.0Compare Source
⚡ Highlights ⚡
👉 https://github.com/aquasecurity/trivy/discussions/10907
Changelog
https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0720-2026-06-30
v0.71.2Compare Source
Changelog
055a5c8release: v0.71.2 [release/v0.71] (#10871)875328afix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)998f7b3chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)v0.71.1Compare Source
Changelog
164b383release: v0.71.1 [release/v0.71] (#10818)a72d9a4fix(oci): validate artifact filename3dd9847fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#10825)a62cbe4fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#10821)43d1d26fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#10812)ac7696cci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#10815)v0.71.0Compare Source
⚡ Highlights ⚡
👉 https://github.com/aquasecurity/trivy/discussions/10767
Changelog
https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0710-2026-06-01
astral-sh/setup-uv (astral-sh/setup-uv)
v8.3.2: 🌈 update known checksums for 0.11.28Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.3.1: 🌈 update known checksums for 0.11.27Compare Source
Changes
Just a maintenance release
🧰 Maintenance
📚 Documentation
v8.3.0: 🌈 Support uv.lock as a version-file sourceCompare Source
Changes
Thanks to @somaz94 you can now use the pinned version of uv itself in
uv.lock. It gets picked up automatically.If you have pinned another version of uv in your
uv.lockyou can use the inputsversionorversion-sourceto override this.🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.2.0: 🌈 New inputsquietanddownload-from-astral-mirrorCompare Source
Changes
This release brings two new inputs and a few bug fixes.
New inputs
Lets talk about the new inputs first.
quiet
Pretty simple. It turns of all
infologgings. Useful if you use this in a composite action and are not interested in all the details.In the upcoming releases we will add log groups to fully implement support for "less noise"
download-from-astral-mirror
In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting
download-from-astral-mirror: falseallows you to do that.Bugfixes
When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.
We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.
🐛 Bug fixes
🚀 Enhancements
download-from-astral-mirrorinput @eifinger (#897)🧰 Maintenance
⬆️ Dependency updates
docker/build-push-action (docker/build-push-action)
v7.3.0Compare Source
Full Changelog: docker/build-push-action@v7.2.0...v7.3.0
docker/login-action (docker/login-action)
v4.4.0Compare Source
registry-authsecret mask by @crazy-max in #1035Full Changelog: docker/login-action@v4.3.0...v4.4.0
v4.3.0Compare Source
Full Changelog: docker/login-action@v4.2.0...v4.3.0
v4.2.0Compare Source
Full Changelog: docker/login-action@v4.1.0...v4.2.0
docker/setup-buildx-action (docker/setup-buildx-action)
v4.2.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0
github/codeql-action (github/codeql-action)
v4.37.0Compare Source
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@​ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3Compare Source
No user facing changes.
v4.36.2Compare Source
v4.36.1Compare Source
No user facing changes.
v4.36.0Compare Source
v4.35.5Compare Source
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892golangci/golangci-lint-action (golangci/golangci-lint-action)
v9.3.0Compare Source
What's Changed
Changes
Dependencies
Full Changelog: golangci/golangci-lint-action@v9.2.1...v9.3.0
v9.2.1Compare Source
What's Changed
IMPORTANT: this is the first immutable release.
Changes
Dependencies
Full Changelog: golangci/golangci-lint-action@v9.2.0...v9.2.1
jdx/mise-action (jdx/mise-action)
v4.2.0: : Bootstrap mode & wget fallbackCompare Source
This release adds an opt-in bootstrap mode for projects that use
mise bootstrap, and makes the action work on runner images that shipwgetbut notcurl.Added
Bootstrap mode (#522) by @jdx
Three new inputs let the action drive
mise bootstrapinstead ofmise install:bootstrap: true, the action runsmise bootstrapunder the existinginstallgate and setsMISE_EXPERIMENTAL=1automatically.mise --locked bootstrap, matching the auto-lock behavior introduced formise installin v4.1.0.install_argscannot be combined withbootstrap: true— the action fails fast and tells you to usebootstrap_skip/bootstrap_argsinstead, because full bootstrap doesn't support partial tool install args.{{bootstrap_hash}}template variable is included in the default cache key (and available in customcache_keytemplates) so bootstrap and non-bootstrap configurations don't share caches.bootstrap_skiprelies onmise bootstrap --skipfrom jdx/mise#10497, so make sure you're on a recent mise version if you use it.Fixed
wgetwhencurlis unavailable (#521) by @risu729 — The action used to hard-codecurlfor fetching the mise binary, tar/zip archives, and the latestVERSIONlookup, which broke on minimal runner images that only shipwget. It now preferscurland transparently falls back towget, preserving the streamingdownload | tarfast path for.tar.gzand.tar.zstinstalls on Linux/macOS. Proxy support is unchanged — both tools honorHTTP_PROXY/HTTPS_PROXY. Addresses jdx/mise#10488.Documentation
Full Changelog: jdx/mise-action@v4.1.0...v4.2.0
v4.1.0: : automatic --locked installsCompare Source
This release adds automatic locked installs when a
mise.lockis present, and fixes a long-standing cache-key collision that could poison tool installs when workflows migrate between runner providers.Added
Automatic
--lockedinstall whenmise.lockexists (#495) by @zeitlingerWhen a repo contains
mise.lock, the action now automatically passes--lockedtomise install(on mise versions that support it). This removes the need to manually setinstall_args: --lockedand preventsmise installfrom silently mutating the lockfile in CI. Explicitinstall_argsand older mise versions are still respected.Note: workflows with a stale lockfile may now fail earlier and more explicitly instead of silently updating
mise.lockmid-run — this surfaces lockfile drift rather than hiding it.Fixed
macos15,ubuntu24for GitHub-hosted runners;self-hostedotherwise). Previously, repos migrating between providers like github-hosted, namespace.so, BuildJet, and self-hosted runners with the same OS/arch could restore a peer provider's~/.local/share/mise/installs/*, causing failures likedoes not have an executable named '…'or SIGILL crashes from binaries built against a different glibc/CPU featureset. Expect a one-time cache miss after upgrading; thereafter the cache stays scoped per image.mise-shim.exemissing on Windows (#476) by @risu729 — the action now installsmise-shim.exealongsidemise.exeand repairs restored caches that lack the shim. Fixes #475.Changed
Full Changelog: jdx/mise-action@v4.0.1...v4.1.0
pnpm/action-setup (pnpm/action-setup)
v6.0.9Compare Source
What's Changed
Full Changelog: pnpm/action-setup@v6...v6.0.9
snok/container-retention-policy (snok/container-retention-policy)
v3.1.0Compare Source
Features
Fixes
Misc
Full Changelog: snok/container-retention-policy@v3.0.1...v3.1.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
Summary by CodeRabbit