Skip to content

chore(deps): Bump the github-actions-dependencies group with 2 updates - #570

Merged
JerrettDavis merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-f04ba6ba23
Aug 10, 2026
Merged

chore(deps): Bump the github-actions-dependencies group with 2 updates#570
JerrettDavis merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-f04ba6ba23

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-dependencies group with 2 updates: dotnet/nbgv and github/codeql-action.

Updates dotnet/nbgv from a83911429567d9af38fcddad180384f2c7970a1b to ac67c7ee2e5c3b12feb09df8af3484e4ecf009bb

Commits
  • ac67c7e Merge pull request #251 from dotnet/aarnott-migrate-to-pnpm
  • a8daa2e Merge remote-tracking branch 'origin/master' into aarnott-migrate-to-pnpm
  • 96bf31c Migrate to pnpm
  • b4aa313 Merge pull request #250 from dotnet/renovate/semver-7.x-lockfile
  • 3da2c3d Merge pull request #248 from dotnet/renovate/yarn-monorepo
  • dfb9a42 Merge pull request #249 from dotnet/renovate/lock-file-maintenance
  • 6161471 Update dependency @​types/semver to v7.8.0
  • eb650b1 Lock file maintenance
  • 12960b7 Update Yarn to v4.18.0
  • See full diff in compare view

Updates github/codeql-action from 4.37.4 to 4.37.6

Release notes

Sourced from github/codeql-action's releases.

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061
Changelog

Sourced from github/codeql-action's changelog.

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061
Commits
  • 5595cca Merge pull request #4071 from github/update-v4.37.6-6a9359a1b
  • ec9c757 Add change note for PR 4070
  • 45c8742 Update changelog for v4.37.6
  • 6a9359a Merge pull request #4070 from github/mbg/remote-address/change-file-default
  • 065cdc0 Change DEFAULT_CONFIG_FILE_NAME
  • f99dd5a Merge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 1804b21 Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a1
  • 3020a2f Rebuild
  • 93c3a5a Update changelog and version after v4.37.5
  • d1ba80a Merge pull request #4067 from github/update-v4.37.5-1cd4d01d5
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-dependencies group with 2 updates: [dotnet/nbgv](https://github.com/dotnet/nbgv) and [github/codeql-action](https://github.com/github/codeql-action).


Updates `dotnet/nbgv` from a83911429567d9af38fcddad180384f2c7970a1b to ac67c7ee2e5c3b12feb09df8af3484e4ecf009bb
- [Release notes](https://github.com/dotnet/nbgv/releases)
- [Commits](dotnet/nbgv@a839114...ac67c7e)

Updates `github/codeql-action` from 4.37.4 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.4...v4.37.6)

---
updated-dependencies:
- dependency-name: dotnet/nbgv
  dependency-version: ac67c7ee2e5c3b12feb09df8af3484e4ecf009bb
  dependency-type: direct:production
  dependency-group: github-actions-dependencies
- dependency-name: github/codeql-action
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/pr-validation.yml

PackageVersionLicenseIssue Type
dotnet/nbgvac67c7ee2e5c3b12feb09df8af3484e4ecf009bbNullUnknown License
Denied Licenses: GPL-2.0, GPL-3.0, AGPL-3.0

OpenSSF Scorecard

PackageVersionScoreDetails
actions/dotnet/nbgv ac67c7ee2e5c3b12feb09df8af3484e4ecf009bb 🟢 4.2
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/10 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • .github/workflows/pr-validation.yml

@github-actions

Copy link
Copy Markdown
Contributor

Test Results

7 641 tests   7 622 ✅  3m 42s ⏱️
    7 suites     19 💤
    7 files        0 ❌

Results for commit 957d506.

@github-actions

Copy link
Copy Markdown
Contributor

Code Coverage

Summary
  Generated on: 08/10/2026 - 11:41:09
  Coverage date: 08/10/2026 - 11:38:37 - 08/10/2026 - 11:41:00
  Parser: MultiReport (7x Cobertura)
  Assemblies: 23
  Classes: 1067
  Files: 591
  Line coverage: 74.7%
  Covered lines: 36879
  Uncovered lines: 12435
  Coverable lines: 49314
  Total lines: 97285
  Branch coverage: 61.7% (13895 of 22512)
  Covered branches: 13895
  Total branches: 22512
  Method coverage: 86.4% (6319 of 7308)
  Full method coverage: 74.2% (5427 of 7308)
  Covered methods: 6319
  Fully covered methods: 5427
  Total methods: 7308

@JerrettDavis
JerrettDavis merged commit 1749026 into main Aug 10, 2026
15 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-dependencies-f04ba6ba23 branch August 10, 2026 21:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant