From 45810c10527081297acfb307bfbc3b5304e0fdbc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 00:44:29 +0000 Subject: [PATCH] build(deps): bump the actions-updates group across 1 directory with 8 updates Bumps the actions-updates group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.1` | `2.21.1` | | [actions/checkout](https://github.com/actions/checkout) | `4.4.0` | `7.0.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.2.0` | `4.4.1` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.1.0` | `10.2.0` | | [edera-dev/actions/report-disk-space](https://github.com/edera-dev/actions) | `0.0.17` | `0.0.19` | | [edera-dev/actions/reclaim-disk-space](https://github.com/edera-dev/actions) | `0.0.17` | `0.0.19` | | [edera-dev/actions/configure-azure-sccache](https://github.com/edera-dev/actions) | `0.0.17` | `0.0.19` | | [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.208` | `1.0.241` | Updates `step-security/harden-runner` from 2.20.1 to 2.21.1 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/v2.20.1...e14015d583714f6e62063499dc959a02595150a1) Updates `actions/checkout` from 4.4.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4.4.0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `docker/setup-buildx-action` from 4.2.0 to 4.4.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c...f87e5991a6d7451dcb8d9637bfbc97413f497069) Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](https://github.com/astral-sh/setup-uv/compare/bec219d24cd3e171d82865faccec33120bb574f4...c18668ad3cf93ea998bef934396af7bb5c839dc7) Updates `edera-dev/actions/report-disk-space` from 0.0.17 to 0.0.19 - [Release notes](https://github.com/edera-dev/actions/releases) - [Commits](https://github.com/edera-dev/actions/compare/6e6996f6fff5d6016bcdc097e9065da6fb33ac7f...faf60530c573a16a539da282eb6d17198a6d1416) Updates `edera-dev/actions/reclaim-disk-space` from 0.0.17 to 0.0.19 - [Release notes](https://github.com/edera-dev/actions/releases) - [Commits](https://github.com/edera-dev/actions/compare/6e6996f6fff5d6016bcdc097e9065da6fb33ac7f...faf60530c573a16a539da282eb6d17198a6d1416) Updates `edera-dev/actions/configure-azure-sccache` from 0.0.17 to 0.0.19 - [Release notes](https://github.com/edera-dev/actions/releases) - [Commits](https://github.com/edera-dev/actions/compare/6e6996f6fff5d6016bcdc097e9065da6fb33ac7f...faf60530c573a16a539da282eb6d17198a6d1416) Updates `anthropics/claude-code-action` from 1.0.208 to 1.0.241 - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](https://github.com/anthropics/claude-code-action/compare/e8c2d7c16c018cf1e694711c1c07a5f5db2b5eb1...cab360f6565aa35a51d6ce9e43f1f4287c0a32ea) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-updates - dependency-name: anthropics/claude-code-action dependency-version: 1.0.231 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-updates - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-updates - dependency-name: docker/setup-buildx-action dependency-version: 4.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-updates - dependency-name: edera-dev/actions/configure-azure-sccache dependency-version: 0.0.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-updates - dependency-name: edera-dev/actions/reclaim-disk-space dependency-version: 0.0.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-updates - dependency-name: edera-dev/actions/report-disk-space dependency-version: 0.0.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-updates - dependency-name: step-security/harden-runner dependency-version: 2.21.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/buildenv-diff.yml | 2 +- .github/workflows/buildenv.yml | 8 +++---- .github/workflows/digestabot.yml | 2 +- .github/workflows/lint.yml | 2 +- .github/workflows/matrix.yml | 24 ++++++++++----------- .github/workflows/pr-review-selftest.yml | 4 ++-- .github/workflows/pr-review-suggestions.yml | 6 +++--- .github/workflows/pr-test-coverage.yml | 6 +++--- .github/workflows/refresh-nvidia.yml | 2 +- 9 files changed, 28 insertions(+), 28 deletions(-) diff --git a/.github/workflows/buildenv-diff.yml b/.github/workflows/buildenv-diff.yml index 9e417b8..312d42b 100644 --- a/.github/workflows/buildenv-diff.yml +++ b/.github/workflows/buildenv-diff.yml @@ -18,7 +18,7 @@ jobs: labels: edera-16 steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: checkout repository diff --git a/.github/workflows/buildenv.yml b/.github/workflows/buildenv.yml index 52378e0..5a249b6 100644 --- a/.github/workflows/buildenv.yml +++ b/.github/workflows/buildenv.yml @@ -38,13 +38,13 @@ jobs: runs-on: "${{ matrix.runner }}" steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - name: docker setup buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: docker login ghcr.io uses: Wandalen/wretry.action@e68c23e6309f2871ca8ae4763e7629b9c258e1ea # v3.8.0 with: @@ -89,13 +89,13 @@ jobs: labels: edera-16 steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: install cosign uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - name: docker setup buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: docker login ghcr.io uses: Wandalen/wretry.action@e68c23e6309f2871ca8ae4763e7629b9c258e1ea # v3.8.0 with: diff --git a/.github/workflows/digestabot.yml b/.github/workflows/digestabot.yml index 005631e..533681f 100644 --- a/.github/workflows/digestabot.yml +++ b/.github/workflows/digestabot.yml @@ -28,7 +28,7 @@ jobs: steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 9aa3d02..4376dca 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -31,7 +31,7 @@ jobs: curl -sSfL "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/koalaman/shellcheck/releases/download/v${SHELLCHECK_VERSION}/shellcheck-v${SHELLCHECK_VERSION}.linux.x86_64.tar.xz" | tar -xJ -C /tmp install -m755 "/tmp/shellcheck-v${SHELLCHECK_VERSION}/shellcheck" "${HOME}/.local/bin/shellcheck" - name: Install the latest version of uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: "3.14" - name: Show versions diff --git a/.github/workflows/matrix.yml b/.github/workflows/matrix.yml index 577c573..50e6855 100644 --- a/.github/workflows/matrix.yml +++ b/.github/workflows/matrix.yml @@ -24,11 +24,11 @@ jobs: labels: edera-16 steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: Install the latest version of uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: "3.14" - name: Setup Crane @@ -83,17 +83,17 @@ jobs: KERNEL_ARCH: "${{ matrix.builds.arch }}" steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: report disk space (before) - uses: edera-dev/actions/report-disk-space@6e6996f6fff5d6016bcdc097e9065da6fb33ac7f # v0.0.17 + uses: edera-dev/actions/report-disk-space@faf60530c573a16a539da282eb6d17198a6d1416 # v0.0.19 - name: reclaim runner disk space # Kernel builds never touch Rust or the hosted toolcache, so both # opt-in removals are on. Must stay before cosign-installer, which # installs into the toolcache this deletes. - uses: edera-dev/actions/reclaim-disk-space@6e6996f6fff5d6016bcdc097e9065da6fb33ac7f # v0.0.17 + uses: edera-dev/actions/reclaim-disk-space@faf60530c573a16a539da282eb6d17198a6d1416 # v0.0.19 with: remove-toolcache: 'true' remove-rust: 'true' @@ -132,7 +132,7 @@ jobs: # - name: docker setup linux-kernel-oci # run: sudo uv run ./hack/build/docker-setup.py - name: docker setup buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: docker login ghcr.io uses: Wandalen/wretry.action@e68c23e6309f2871ca8ae4763e7629b9c258e1ea # v3.8.0 with: @@ -148,13 +148,13 @@ jobs: # list in hack/build/generate-docker-script.py (docker_compile); a # name missing there silently never reaches the build container. id: sccache - uses: edera-dev/actions/configure-azure-sccache@6e6996f6fff5d6016bcdc097e9065da6fb33ac7f # v0.0.17 + uses: edera-dev/actions/configure-azure-sccache@faf60530c573a16a539da282eb6d17198a6d1416 # v0.0.19 with: connection-string-rw: ${{ secrets.SCCACHE_AZURE_CONNECTION_STRING }} connection-string-ro: ${{ secrets.SCCACHE_AZURE_CONNECTION_STRING_RO }} key-prefix: kernel - name: Install the latest version of uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: "3.14" - name: generate docker script @@ -172,7 +172,7 @@ jobs: - name: report disk space (after) # always() so ENOSPC failures still show where the disk went. if: always() - uses: edera-dev/actions/report-disk-space@6e6996f6fff5d6016bcdc097e9065da6fb33ac7f # v0.0.17 + uses: edera-dev/actions/report-disk-space@faf60530c573a16a539da282eb6d17198a6d1416 # v0.0.19 - name: upload digests # Only produced when publishing — push-by-digest path writes digests.json. if: ${{ inputs.publish }} @@ -208,13 +208,13 @@ jobs: DIGESTS_DIR: digests steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 - name: Install the latest version of uv - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: python-version: '3.14' - name: install python deps @@ -222,7 +222,7 @@ jobs: - name: install cosign uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - name: docker setup buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: docker login ghcr.io uses: Wandalen/wretry.action@e68c23e6309f2871ca8ae4763e7629b9c258e1ea # v3.8.0 with: diff --git a/.github/workflows/pr-review-selftest.yml b/.github/workflows/pr-review-selftest.yml index b7c7425..7b935e4 100644 --- a/.github/workflows/pr-review-selftest.yml +++ b/.github/workflows/pr-review-selftest.yml @@ -39,12 +39,12 @@ jobs: timeout-minutes: 10 steps: - name: Harden runner - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: Checkout - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false diff --git a/.github/workflows/pr-review-suggestions.yml b/.github/workflows/pr-review-suggestions.yml index 83849d8..5897c57 100644 --- a/.github/workflows/pr-review-suggestions.yml +++ b/.github/workflows/pr-review-suggestions.yml @@ -40,12 +40,12 @@ jobs: id-token: write steps: - name: Harden runner - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: Checkout - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 persist-credentials: false @@ -82,7 +82,7 @@ jobs: - name: Suggest id: suggest continue-on-error: true - uses: anthropics/claude-code-action@e8c2d7c16c018cf1e694711c1c07a5f5db2b5eb1 # v1 + uses: anthropics/claude-code-action@cab360f6565aa35a51d6ce9e43f1f4287c0a32ea # v1 env: GH_TOKEN: ${{ github.token }} with: diff --git a/.github/workflows/pr-test-coverage.yml b/.github/workflows/pr-test-coverage.yml index fbe6622..ab42019 100644 --- a/.github/workflows/pr-test-coverage.yml +++ b/.github/workflows/pr-test-coverage.yml @@ -39,12 +39,12 @@ jobs: id-token: write steps: - name: Harden runner - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: Checkout - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 persist-credentials: false @@ -87,7 +87,7 @@ jobs: - name: Review id: review continue-on-error: true - uses: anthropics/claude-code-action@e8c2d7c16c018cf1e694711c1c07a5f5db2b5eb1 # v1 + uses: anthropics/claude-code-action@cab360f6565aa35a51d6ce9e43f1f4287c0a32ea # v1 env: GH_TOKEN: ${{ github.token }} with: diff --git a/.github/workflows/refresh-nvidia.yml b/.github/workflows/refresh-nvidia.yml index 83d1cd4..bc565ce 100644 --- a/.github/workflows/refresh-nvidia.yml +++ b/.github/workflows/refresh-nvidia.yml @@ -15,7 +15,7 @@ jobs: labels: edera-16 steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1 + uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 with: egress-policy: audit - name: checkout repository