Skip to content

build(deps): bump berntpopp/genefoundry-router/.github/workflows/_container-ci.yml from 86b11f7ed062ed84dfddcbd309e34da88f3dae5b to 3a94e04441b9accabf533d8b46ce37eb08b0799a#117

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/berntpopp/genefoundry-router/dot-github/workflows/_container-ci.yml-3a94e04441b9accabf533d8b46ce37eb08b0799a
Open

build(deps): bump berntpopp/genefoundry-router/.github/workflows/_container-ci.yml from 86b11f7ed062ed84dfddcbd309e34da88f3dae5b to 3a94e04441b9accabf533d8b46ce37eb08b0799a#117
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/berntpopp/genefoundry-router/dot-github/workflows/_container-ci.yml-3a94e04441b9accabf533d8b46ce37eb08b0799a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps berntpopp/genefoundry-router/.github/workflows/_container-ci.yml from 86b11f7ed062ed84dfddcbd309e34da88f3dae5b to 3a94e04441b9accabf533d8b46ce37eb08b0799a.

Changelog

Sourced from berntpopp/genefoundry-router/.github/workflows/_container-ci.yml's changelog.

Changelog

All notable changes to genefoundry-router are documented here.

[0.7.0] - 2026-07-19

Added

  • Establish trusted-builder governance for reusable container releases, with immutable workflow provenance, protected-branch control audits, and sealed release manifests.
  • Publish the canonical Contract Truth v1 and Runtime Data Identity v1 conformance helpers, backed by router dogfood tests and rollout gates.

Changed

  • Require release evidence to bind observed runtime data identity while preserving explicit compatibility with historical release records.
  • Harden GitHub ruleset verification against permissive, unknown, and malformed branch-control policy representations.

[0.6.15] - 2026-07-18

Fixed

  • Re-pin the digest-locked Python runtime base image so the released container includes Debian's liblzma5 5.8.1-1+deb13u1 fix for CVE-2026-34743 (Trivy alert #5), without suppressing the vulnerability scanner.

Changed

  • Consolidate the reviewed Dependabot updates for FastAPI, Typer, Ruff, Mypy, and the pinned CI, attestation, and scanner actions.

[0.6.14] - 2026-07-16

Changed

  • Re-pin the reviewed runtime baseline, release-candidate inventory, and discoverability catalog to the fully deployed 21-backend fleet. The inventory carries the exact immutable application-release provenance for each backend, including ClinGen v4.0.1 and MetaDome v0.3.1.
  • Make fleet-level README and citation checks reliable from isolated Git worktrees by resolving the repository/fleet location from Git's main checkout.

[0.6.13] - 2026-07-16

Changed

... (truncated)

Commits
  • 3a94e04 Merge pull request #104 from berntpopp/docs/p0-dependabot-fleet-20260719
  • 5add2a1 docs: plan P0 Dependabot fleet completion
  • 2e27a1b Merge pull request #103 from berntpopp/feat/p0-release-truth-20260718
  • ee5fefb release: prepare v0.7.0
  • 36fbc37 fix(release): reject malformed ruleset types
  • 1bbeb3d fix(release): accept neutral GitHub ruleset fields
  • d40be48 fix(release): preserve legacy manifest serialization
  • 7241e8a fix(release): enforce exact main ruleset policy
  • 9ecfc43 fix(release): preserve legacy release evidence
  • 2f62be1 ci(release): verify observed runtime data identity
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…tainer-ci.yml

Bumps [berntpopp/genefoundry-router/.github/workflows/_container-ci.yml](https://github.com/berntpopp/genefoundry-router) from 86b11f7ed062ed84dfddcbd309e34da88f3dae5b to 3a94e04441b9accabf533d8b46ce37eb08b0799a.
- [Release notes](https://github.com/berntpopp/genefoundry-router/releases)
- [Changelog](https://github.com/berntpopp/genefoundry-router/blob/main/CHANGELOG.md)
- [Commits](berntpopp/genefoundry-router@86b11f7...3a94e04)

---
updated-dependencies:
- dependency-name: berntpopp/genefoundry-router/.github/workflows/_container-ci.yml
  dependency-version: 3a94e04441b9accabf533d8b46ce37eb08b0799a
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants