ci: bump the actions-deps group with 7 updates - #480
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps the actions-deps group with 7 updates: | Package | From | To | | --- | --- | --- | | [actions/upload-code-coverage](https://github.com/actions/upload-code-coverage) | `1.4.1` | `1.4.2` | | [actions/labeler](https://github.com/actions/labeler) | `6.2.0` | `7.0.0` | | [actions/cache](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/cache/restore](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.4.0` | `4.6.0` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.1` | `4.2.2` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `6.0.9` | `6.0.10` | Updates `actions/upload-code-coverage` from 1.4.1 to 1.4.2 - [Commits](actions/upload-code-coverage@1c15be3...d8e3291) Updates `actions/labeler` from 6.2.0 to 7.0.0 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@b8dd2d9...bf12e9b) Updates `actions/cache` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@27d5ce7...55cc834) Updates `actions/cache/restore` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@27d5ce7...55cc834) Updates `docker/login-action` from 4.4.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@af1e73f...dbcb813) Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@0f67c3f...4d10147) Updates `pnpm/action-setup` from 6.0.9 to 6.0.10 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@0ebf471...0977fd9) --- updated-dependencies: - dependency-name: actions/upload-code-coverage dependency-version: 1.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps - dependency-name: actions/labeler dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: actions/cache/restore dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-deps - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-deps - dependency-name: pnpm/action-setup dependency-version: 6.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-deps ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Aug 18, 2026
EricAndrechek
added a commit
that referenced
this pull request
Aug 18, 2026
Folds the three open Dependabot PRs into one reviewable change, fixes the pnpm advisories from #486, and repairs the Dependabot config gap that let the `setup-env` composite action drift out of sync in the first place. Closes #486. Supersedes #480, #481, #482. ## Why one PR instead of merging the three They are not independent: - **#486 and #480 touch the same files.** The pnpm pin lives in `publish-npm.yml` and `.github/actions/setup-env/action.yml`; #480 bumps action SHAs in the same two files. Sequencing them costs a rebase either way. - **#480 alone would have made things worse.** Dependabot only sees `.github/workflows/` — see below — so #480 moves the workflows to `actions/cache` v6.1.0 while `setup-env`, which owns every cache in CI, stays on v5.0.5. Only a hand-written commit can close that. - **#482 cannot be rebased into a green state.** Its TypeScript 7 bump is blocked upstream, permanently for now — see below. - **#481 is trivially includable** (`go.mod` / `go.sum`, all patch/minor). One CI run, one review, no interleaving. ## 1. pnpm 11.1.3 → 11.21.0 (#486) **Eight declaration lines across six files**, not the four sites the issue listed: | Site | | | --- | --- | | `package.json` | `packageManager` | | `.github/workflows/publish-npm.yml` | dev + release jobs | | `.github/actions/setup-env/action.yml` | every CI job | | `docs/src/content/docs/development.md` | `corepack prepare` line, prerequisites table, **and** the "verify your setup" snippet | | `README.md` | the `pnpm 11+` floor in Local Development | | `AGENTS.md` | the `pnpm (≥ 11.1)` floor in the toolchain list | **The issue's advisory table is off by four.** #486 lists ten; the actual count affecting 11.1.3 is **fourteen** — 8 high, 6 medium. Its table includes [GHSA-v23m-ccfg-pq9h](GHSA-v23m-ccfg-pq9h), whose range is `>= 11.3.0, < 11.5.3` and so does *not* cover 11.1.3, and omits five that do: GHSA-hwx4-2j3j-g496 (**high**), GHSA-cjhr-43r9-cfmw, GHSA-p4xf-rf54-rj3x, GHSA-q6j5-fjx5-2mc3 and GHSA-54hh-g5mx-jqcp. "Eight high" happens to survive only because the wrongly-included high and the omitted high cancel out. All five were published 2026-06-26, so this was a counting slip when the issue was written, not new information. The remediation is unchanged — the highest `first_patched_version` is still **11.8.0**, and 11.21.0 clears all fourteen. Worth correcting the table on #486 so the issue and this PR agree. **Why 11.21.0 and not 11.22.0 (latest).** 11.22.0 shipped 2026-08-15, three days ago. `pnpm-workspace.yaml` sets `minimumReleaseAge: 10080` — a deliberate 7-day cooldown against compromised releases. That knob governs dependency resolution, not the `packageManager` pin, but the reasoning applies harder here: pnpm runs postinstall scripts under `allowBuilds:` in every CI job, and in `publish-npm.yml`, which holds `id-token: write` for npm trusted publishing. 11.21.0 is 9 days old and equally clear of every advisory. Say the word and I'll move it to 11.22.0. **`lockfileVersion` is unchanged at `9.0`.** The issue flagged a possible bump; 11.21.0 reads and writes the existing format, and `pnpm install --frozen-lockfile` passed against the *pre-existing* lockfile before it was regenerated. ## 2. Dependabot never scanned the composite action `directory: /` for `package-ecosystem: github-actions` reaches `.github/workflows/` and stops. It does **not** descend into `.github/actions/*/action.yml`. `setup-env` has been invisible to Dependabot since it was created. Its only caller is `ci.yml`, which pins none of these actions itself — they all live *inside* `setup-env` — so the staleness shows up against upstream, and against `publish-npm.yml`, a workflow Dependabot *does* track and which does **not** call `setup-env`: | Action | `setup-env` on `main` | elsewhere on `main` | | --- | --- | --- | | `actions/setup-node` | v6.4.0 | **v7.0.0** in `publish-npm.yml` | | `pnpm/action-setup` | v6.0.8 | v6.0.9 in `publish-npm.yml` | | `actions/cache` (×6) | v5.0.5 | v5.0.5 everywhere — no divergence, just a major behind upstream | The `setup-node` row is the tell: that major landed in `publish-npm.yml` in an earlier Dependabot PR and `setup-env`, being invisible, never followed. (#480 would then have *introduced* a cache skew, bumping `publish-dev.yml` to v6.1.0 while `setup-env` stayed on v5.0.5.) This PR aligns all three to the versions the workflows already use — no version is introduced here that Dependabot has not already proposed and CI has not already run — and switches the config to `directories: [/, /.github/actions/setup-env]` so the group covers it from now on. ## 3. actions-deps (#480), verbatim `upload-code-coverage` 1.4.1→1.4.2 · `labeler` 6.2.0→**7.0.0** · `cache` + `cache/restore` 5.0.5→**6.1.0** · `docker/login-action` 4.4.0→4.6.0 · `attest-build-provenance` 4.1.1→4.2.2 · `pnpm/action-setup` 6.0.9→6.0.10. Both majors are ESM migrations with no config surface change, and #480's own CI run was fully green on them. ## 4. go-deps (#481), verbatim `nats-server` 2.14.4→2.14.5 · `nats.go` 1.52.0→1.53.1 · `testify` 1.11.1→1.12.0 · `testcontainers-go` 0.43.0→0.44.0, plus indirects. All patch/minor. #481's only red check was `PR housekeeping` failing on a transient GitHub API 500 inside `actions/labeler` — not a code problem, and now not a red check either (see below). ## 5. npm-deps (#482), minus TypeScript 7 Taken: `tsx` 4.23.5→4.23.12 · `@astrojs/starlight` 0.41.6→0.41.7 · `katex` 0.18.1→0.18.4 · `@types/node` catalog ^26.1.2→^26.2.0. **Held: `typescript` ^6.0.3 → ^7.0.2.** This is why every Node job on #482 went red. Reproduced locally: ``` TypeError: Cannot read properties of undefined (reading 'useCaseSensitiveFileNames') at node_modules/.pnpm/rollup-plugin-dts@6.1.1_.../rollup-plugin-dts.cjs at .../tsup@8.5.1_.../tsup/dist/rollup.js:4857:37 ``` `tsup` 8.5.1 — the current release — **vendors** `rollup-plugin-dts` 6.1.1 into its own bundle, so it is not overridable from our side. 6.1.1 reaches for TS 5-era compiler internals and dies the moment `dts: true` runs. That is `clients/ts`'s `prepare` script, so the crash happens *inside* `pnpm install` and takes down Lint, Unit, E2E, Coverage and Docs build at once. `rollup-plugin-dts` **6.5.0** is the first release declaring `typescript: "^4.5 || ^5 || ^6 || ^7"` (6.4.0 stops at `^6.0`); we need a `tsup` release that vendors ≥ 6.5.0. No rebase of #482 can fix this, and left alone Dependabot re-proposes it every Monday — so `.github/dependabot.yml` now ignores `version-update:semver-major` for `typescript`, with the reason and the removal condition written next to it. The regenerated lockfile changes **exactly four** resolved packages and adds or drops none: ``` @astrojs/starlight: 0.41.6 -> 0.41.7 @types/node: + 26.2.0 (24.13.3, 26.1.2 remain as transitives) katex: 0.18.1 -> 0.18.4 tsx: 4.23.5 -> 4.23.12 ``` ## 6. One-line fix: labeling really is non-fatal now `housekeeping.yml`'s header has always claimed: > Labeling failures are non-fatal so a flaky API call can't block the title > mirror. It wasn't true — the `Apply file-path labels` step has never carried `continue-on-error`, in any revision. So when the labeler hit a transient 500 on #481: ``` ##[error]HttpError: No server is currently available to service your request. ``` the job aborted *before* the title mirror it exists to protect, and the check went red. Adding `continue-on-error: true` makes the documented contract real. In scope because it is the direct cause of one of the three red PRs this change set is meant to clear. `PR housekeeping` is not a required check — the `CI` aggregator is — so this was noise rather than a merge blocker, but it's noise that costs a re-run every time GitHub hiccups. ## What this PR's CI does *not* prove Worth stating rather than implying green means everything: - **`actions/labeler` 6.2.0 → 7.0.0 is not exercised here.** `housekeeping.yml` runs on `pull_request_target`, so GitHub loads that workflow file from `main`, not from the PR head. The `PR housekeeping` check on this PR — and on #480 — runs labeler **v6.2.0** regardless. v7.0.0 first executes on the PR *after* this merges. Mitigating: v7.0.0 is an ESM-migration-only release, `.github/labeler.yml` already uses the v5+ `changed-files` schema, and the labeling step is deliberately `continue-on-error` so a bad labeler cannot block a PR. - **`publish-npm.yml`, `publish-dev.yml` and `release.yml` are tag/release triggered**, so their action bumps (and the new pnpm pin in the publish jobs) first run on the next release, not here. - `actions/cache` 5.0.5 → 6.1.0 *is* covered — `ci.yml` runs on `pull_request`, so every cache in `setup-env` exercises v6.1.0 on this PR. ## Verification - `make ci` green locally with Docker up, running on pnpm 11.21.0 — all static checks, unit, integration, E2E and every coverage gate. - `pnpm install --frozen-lockfile` clean against the regenerated lockfile; `tsup` DTS build succeeds. - No action is pinned at two different versions anywhere under `.github/` any more (was: `cache`, `setup-node`, `pnpm/action-setup`). - `actionlint`, `shellcheck`, `biome` and `markdownlint` all pass over the workflow, config and CHANGELOG edits. - `CHANGELOG.md` updated under `[Unreleased]` — a Security entry for the pnpm bump and a Changed entry for the groups + Dependabot config. - Advisory count re-derived from `gh api "/advisories?ecosystem=npm&affects=pnpm" --paginate` with range matching against 11.1.3, not copied from the issue. Note that #480/#481/#482 are superseded rather than closed by me — Dependabot should retire them on its next run once these versions are on `main`. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Member
|
@dependabot rebase |
Contributor
Author
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/github_actions/actions-deps-8b42947210
branch
August 18, 2026 21:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions-deps group with 7 updates:
1.4.11.4.26.2.07.0.05.0.56.1.05.0.56.1.04.4.04.6.04.1.14.2.26.0.96.0.10Updates
actions/upload-code-coveragefrom 1.4.1 to 1.4.2Commits
d8e3291Merge pull request #25 from actions/cassiomarques/hnadle-skipped-stale-uploade59685bAddress PR feedback92d3d57Always use the warning message from the upload API response391a615Handle skipped stale coverage uploadsf8bb484Merge pull request #23 from actions/tjgurwara99/add-linting-to-the-project64b4088Apply suggestions from code review754cc6fPin checkout action to the SHA for the latest version of the checkout7cc12a3Update the main CI to use uv as well08d519aSetup linting with Ruff along with project setup using uvUpdates
actions/labelerfrom 6.2.0 to 7.0.0Release notes
Sourced from actions/labeler's releases.
Commits
bf12e9bfeat: migrate to ESM and update dependencies (#949)Updates
actions/cachefrom 5.0.5 to 6.1.0Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
actions/cache/restorefrom 5.0.5 to 6.1.0Release notes
Sourced from actions/cache/restore's releases.
Changelog
Sourced from actions/cache/restore's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
docker/login-actionfrom 4.4.0 to 4.6.0Release notes
Sourced from docker/login-action's releases.
Commits
dbcb813Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015[dependabot skip] chore: update generated contentb30b2f2build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...9087f1eMerge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830[dependabot skip] chore: update generated content2325523build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4aMerge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99baMerge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...e512bd5Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...a146c91Merge pull request #1059 from crazy-max/harden-buildx-scope-pathsUpdates
actions/attest-build-provenancefrom 4.1.1 to 4.2.2Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)Updates
pnpm/action-setupfrom 6.0.9 to 6.0.10Release notes
Sourced from pnpm/action-setup's releases.
Commits
0977fd9docs: Update README to include devEngines.packageManager (#273)48261acfix: update pnpm to v11.19.0 (#283)75677f7ci: use pnpm 11 forpr-check(#284)769ae71refactor: introduce restore keys for cache (#280)6fed91fdocs(README): point users to the successor pnpm/setup action (#282)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions