Skip to content

chore(deps): update github actions#609

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

chore(deps): update github actions#609
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Apr 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
SonarSource/sonarqube-scan-action action major v7.1.0v8.1.0 v8.2.0 (+1)
actions/checkout action patch v6.0.2v6.0.3 v7.0.0 (+1)
actions/create-github-app-token action minor v3.1.1v3.2.0
anthropics/claude-code-action action patch v1.0.93v1.0.136 v1.0.152 (+15)
astral-sh/setup-uv action minor v8.0.0v8.2.0
codecov/codecov-action action patch v6.0.0v6.0.1 v7.0.0 (+2)
docker/build-push-action action minor v7.1.0v7.2.0
docker/login-action action minor v4.1.0v4.2.0
docker/metadata-action action minor v6.0.0v6.1.0
docker/setup-buildx-action action minor v4.0.0v4.1.0
docker/setup-qemu-action action minor v4.0.0v4.1.0
getsentry/action-release action minor v3.6.0v3.7.0
github/codeql-action action minor v4.35.1v4.36.2
orhun/git-cliff-action action minor v4.7.1v4.8.0
slackapi/slack-github-action action patch v3.0.1v3.0.3

Release Notes

SonarSource/sonarqube-scan-action (SonarSource/sonarqube-scan-action)

v8.1.0

Compare Source

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8...v8.1.0

v8.1

Compare Source

v8.0.0

Compare Source

What's Changed

Breaking change

Full Changelog: SonarSource/sonarqube-scan-action@v7...v8.0.0

v8.0

Compare Source

v8

Compare Source

v7.2.1

Compare Source

What's Changed

  • SQSCANGHA-140 Set skipSignatureVerification default value to true to avoid breaking change by @​gmmcal in #​240

Full Changelog: SonarSource/sonarqube-scan-action@v7...v7.2.1

v7.2.0

Compare Source

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v7...v7.2.0

v7.2

Compare Source

actions/checkout (actions/checkout)

v6.0.3

Compare Source

actions/create-github-app-token (actions/create-github-app-token)

v3.2.0

Compare Source

Features
Bug Fixes
anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.136

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.136

v1.0.135

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.135

v1.0.134

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.134

v1.0.133

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.133

v1.0.132

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.132

v1.0.131

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.131

v1.0.130

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.130

v1.0.129

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.129

v1.0.128

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.128

v1.0.127

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.127

v1.0.126

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.126

v1.0.125

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.125

v1.0.124

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.124

v1.0.123

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.123

v1.0.122

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.122

v1.0.121

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.121

v1.0.120

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.120

v1.0.119

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.119

v1.0.118

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.118

v1.0.117

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.117

v1.0.116

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.116

v1.0.115

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.115

v1.0.114

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.114

v1.0.113

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.113

v1.0.112

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.112

v1.0.111

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.111

v1.0.110

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.110

v1.0.109

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.109

v1.0.108

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.108

v1.0.107

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.107

v1.0.106

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.106

v1.0.105

Compare Source

What's Changed

  • fix: allow + in branch names (generated by Claude Code EnterWorktree) by @​awakia in #​1248

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.105

v1.0.104

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.104

v1.0.103

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.103

v1.0.102

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.102

v1.0.101

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.101

v1.0.100

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.100

v1.0.99

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.99

v1.0.98

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.98

v1.0.97

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.97

v1.0.96

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.96

v1.0.95

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.95

v1.0.94

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.94

astral-sh/setup-uv (astral-sh/setup-uv)

v8.2.0: 🌈 New inputs quiet and download-from-astral-mirror

Compare Source

Changes

This release brings two new inputs and a few bug fixes.

New inputs

Lets talk about the new inputs first.

quiet

Pretty simple. It turns of all info loggings. Useful if you use this in a composite action and are not interested in all the details.
In the upcoming releases we will add log groups to fully implement support for "less noise"

[!NOTE]
Warnings and errors are always logged.

download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting download-from-astral-mirror: false allows you to do that.

Bugfixes

When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.

🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
⬆️ Dependency updates

v8.1.0: 🌈 New input no-project

Compare Source

Changes

This add the a new boolean input no-project.
It only makes sense to use in combination with activate-environment: true and will append --no project to the uv venv call. This is for example useful if you have a pyproject.toml file with parts unparseable by uv

🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
codecov/codecov-action (codecov/codecov-action)

v6.0.1

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v6.0.0...v6.0.1

docker/build-push-action (docker/build-push-action)

v7.2.0

Compare Source

Full Changelog: docker/build-push-action@v7.1.0...v7.2.0

docker/login-action (docker/login-action)

v4.2.0

Compare Source

Full Changelog: docker/login-action@v4.1.0...v4.2.0

docker/metadata-action (docker/metadata-action)

v6.1.0

Compare Source

  • Bump @​docker/actions-toolkit from 0.79.0 to 0.90.0 in #​613
  • Bump brace-expansion from 1.1.12 to 5.0.6 in #​658 #​630
  • Bump csv-parse from 6.1.0 to 6.2.1 in #​617
  • Bump fast-xml-parser from 5.4.2 to 5.8.0 in #​620
  • Bump flatted from 3.3.3 to 3.4.2 in #​623
  • Bump glob from 10.3.15 to 10.5.0 in #​621
  • Bump handlebars from 4.7.8 to 4.7.9 in #​629
  • Bump lodash from 4.17.23 to 4.18.1 in #​639
  • Bump moment-timezone from 0.6.0 to 0.6.1 in #​619
  • Bump picomatch from 4.0.3 to 4.0.4 in #​626
  • Bump postcss from 8.5.6 to 8.5.10 in #​649
  • Bump tar from 6.2.1 to 7.5.15 in #​657
  • Bump undici from 6.23.0 to 6.25.0 in #​614
  • Bump vite from 7.3.1 to 7.3.2 in #​637

Full Changelog: docker/metadata-action@v6.0.0...v6.1.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.1.0

Compare Source

  • Bump @​docker/actions-toolkit from 0.79.0 to 0.90.0 in #​489
  • Bump brace-expansion from 1.1.12 to 5.0.6 in #​547 #​508
  • Bump fast-xml-builder from 1.0.0 to 1.2.0 in #​540
  • Bump fast-xml-parser from 5.4.2 to 5.8.0 in #​496
  • Bump flatted from 3.3.3 to 3.4.2 in #​499
  • Bump glob from 10.3.12 to 13.0.6 in #​495
  • Bump handlebars from 4.7.8 to 4.7.9 in #​504
  • Bump lodash from 4.17.23 to 4.18.1 in #​523
  • Bump picomatch from 4.0.3 to 4.0.4 in #​503
  • Bump postcss from 8.5.6 to 8.5.10 in #​537
  • Bump tar from 6.2.1 to 7.5.15 in #​545
  • Bump undici from 6.23.0 to 6.25.0 in #​492
  • Bump vite from 7.3.1 to 7.3.2 in #​520

Full Changelog: docker/setup-buildx-action@v4.0.0...v4.1.0

docker/setup-qemu-action (docker/setup-qemu-action)

v4.1.0

Compare Source

Full Changelog: docker/setup-qemu-action@v4.0.0...v4.1.0

getsentry/action-release (getsentry/action-release)

v3.7.0: 3.7.0

Compare Source

New Features ✨

v3.7

Compare Source

v3.6.1: 3.6.1

Compare Source

Bug Fixes 🐛
Documentation 📚
Internal Changes 🔧
github/codeql-action (github/codeql-action)

v4.36.2

Compare Source

  • Cache CodeQL CLI version information across Actions steps. #​3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #​3937
  • Update default CodeQL bundle version to 2.25.6. #​3948

v4.36.1

Compare Source

No user facing changes.

v4.36.0

Compare Source

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #​3894
  • Add support for SHA-256 Git object IDs. #​3893
  • Update default CodeQL bundle version to 2.25.5. #​3926

v4.35.5

Compare Source

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #​3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #​3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #​3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #​3880

v4.35.4

Compare Source

v4.35.3

Compare Source

  • *Upco

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • Between 12:00 AM and 05:59 AM (* 0-5 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added bot Automated pull requests or issues dependencies Pull requests that update a dependency file labels Apr 27, 2026
@renovate renovate Bot added renovate Pull requests from Renovate skip:codecov Skip Codecov reporting and check skip:test:long_running Skip long-running tests (≥5min) labels Apr 27, 2026
@renovate renovate Bot requested a review from a team as a code owner April 27, 2026 23:45
@renovate renovate Bot added dependencies Pull requests that update a dependency file bot Automated pull requests or issues renovate Pull requests from Renovate skip:test:long_running Skip long-running tests (≥5min) skip:codecov Skip Codecov reporting and check labels Apr 27, 2026
@helmut-hoffer-von-ankershoffen helmut-hoffer-von-ankershoffen changed the title chore(deps): update anthropics/claude-code-action action to v1.0.94 chore(deps): update anthropics/claude-code-action action to v1.0.94 [PYSDK-120] Apr 28, 2026
@helmut-hoffer-von-ankershoffen helmut-hoffer-von-ankershoffen added the sop:cc-sop-01 CC-SOP-01 Change Control (feature / planned change) label Apr 28, 2026
@helmut-hoffer-von-ankershoffen

helmut-hoffer-von-ankershoffen commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

⚠️ Change control gap: This PR was open for 1 day before a Ketryx CR was created.
CR PYSDK-120 has been opened retroactively per CC-SOP-01.

PR title and body updated to add the SOP shield line. Future Renovate PRs in this repo will follow the standard create-CR-first flow (or be brought into compliance at merge time).


Posted by Claude claude-opus-4-7 via Claude Code, applying skills cc-sop-01 on behalf of helmut@aignostics.com

@renovate renovate Bot changed the title chore(deps): update anthropics/claude-code-action action to v1.0.94 [PYSDK-120] chore(deps): update anthropics/claude-code-action action to v1.0.94 Apr 28, 2026
@renovate renovate Bot force-pushed the renovate/github-actions branch from 3e95605 to d01f391 Compare April 28, 2026 22:57
@renovate renovate Bot changed the title chore(deps): update anthropics/claude-code-action action to v1.0.94 chore(deps): update anthropics/claude-code-action action to v1.0.95 Apr 28, 2026
@renovate renovate Bot force-pushed the renovate/github-actions branch from d01f391 to 52d047e Compare April 29, 2026 04:50
@renovate renovate Bot changed the title chore(deps): update anthropics/claude-code-action action to v1.0.95 chore(deps): update anthropics/claude-code-action action to v1.0.96 Apr 29, 2026
@renovate renovate Bot force-pushed the renovate/github-actions branch from 52d047e to 3f5c5b8 Compare April 29, 2026 11:42
@renovate renovate Bot changed the title chore(deps): update anthropics/claude-code-action action to v1.0.96 chore(deps): update github actions Apr 29, 2026
@renovate renovate Bot force-pushed the renovate/github-actions branch 7 times, most recently from 09e85d3 to b7e9b0e Compare May 6, 2026 00:53
@renovate renovate Bot force-pushed the renovate/github-actions branch 9 times, most recently from 91396f5 to f85a5f3 Compare May 22, 2026 01:46
@renovate renovate Bot force-pushed the renovate/github-actions branch 6 times, most recently from 0a0386f to b5a11df Compare May 27, 2026 02:02
@sonarqubecloud

Copy link
Copy Markdown

@renovate renovate Bot force-pushed the renovate/github-actions branch from b5a11df to 00dcf4b Compare May 28, 2026 00:51
@sonarqubecloud

Copy link
Copy Markdown

@renovate renovate Bot force-pushed the renovate/github-actions branch 9 times, most recently from 27de82f to 6c531e8 Compare June 4, 2026 01:58
@renovate renovate Bot force-pushed the renovate/github-actions branch from 6c531e8 to 26efb06 Compare June 4, 2026 17:13
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot Automated pull requests or issues dependencies Pull requests that update a dependency file renovate Pull requests from Renovate skip:codecov Skip Codecov reporting and check skip:test:long_running Skip long-running tests (≥5min) sop:cc-sop-01 CC-SOP-01 Change Control (feature / planned change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant