Skip to content

ci: bump the github-actions group across 1 directory with 2 updates#1

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-37d7d335b6
Closed

ci: bump the github-actions group across 1 directory with 2 updates#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-37d7d335b6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 24, 2026

Copy link
Copy Markdown

Bumps the github-actions group with 2 updates in the / directory: dependabot/fetch-metadata and creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml.

Updates dependabot/fetch-metadata from 2 to 3

Release notes

Sourced from dependabot/fetch-metadata's releases.

v3.0.0

The breaking change is requiring Node.js version v24 as the Actions runtime.

What's Changed

New Contributors

Full Changelog: dependabot/fetch-metadata@v2...v3.0.0

v2.5.0

What's Changed

... (truncated)

Commits
  • 25dd0e3 v3.1.0 (#692)
  • e073f50 Merge pull request #705 from dependabot/dependabot/npm_and_yarn/hono-4.12.14
  • 0670e16 build(deps-dev): bump hono from 4.12.12 to 4.12.14
  • 7a7fe10 Merge pull request #702 from dependabot/dependabot/npm_and_yarn/dependencies-...
  • 5168191 Updating dist build
  • 23882e1 build(deps): bump @​actions/github in the dependencies group
  • 1072469 Merge pull request #701 from dependabot/dependabot/github_actions/actions/cre...
  • 43f8a00 build(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1
  • b4d904a Merge pull request #703 from dependabot/dependabot/npm_and_yarn/globals-17.5.0
  • c8046bb build(deps-dev): bump globals from 17.4.0 to 17.5.0
  • Additional commits viewable in compare view

Updates creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml from 0.1.0 to 0.2.0

Changelog

Sourced from creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml's changelog.

Changelog

All notable changes to oss-security-scan are documented in this file.

The format follows Keep a Changelog and the project adheres to Semantic Versioning.

Commits
  • 8aa8407 fix(osv): treat exit 128 as 'no manifests', not vulnerability
  • 9d6fc88 feat(osv): inline osv-scanner job to unblock callers ahead of Go 1.26.2
  • ce81d40 fix: harden tier-1 checkouts against transient github auth flake
  • 6d491a1 ci: add Dependabot auto-merge for high-trust updates
  • 8073837 ci: add workflow_dispatch to integration-test.yml
  • bf16446 ci: bump crate-ci/typos in the github-actions group (#1)
  • da1c688 chore: enable dependabot for github-actions + language ecosystem
  • 8ff88bf ci: add workflow_dispatch trigger + OSV-on-manual gating to self-scan
  • 320ab08 feat: rename leakguard references to textleaks
  • 24be6b7 fix(test): install leakguard + oss-twin from git, not PyPI
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 24, 2026
Bumps the github-actions group with 2 updates in the / directory: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) and [creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml](https://github.com/creatornader/oss-security-scan).


Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)

Updates `creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml` from 0.1.0 to 0.2.0
- [Changelog](https://github.com/creatornader/oss-security-scan/blob/main/CHANGELOG.md)
- [Commits](creatornader/oss-security-scan@v0.1.0...v0.2.0)

---
updated-dependencies:
- dependency-name: creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml
  dependency-version: 0.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: dependabot/fetch-metadata
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title ci: bump the github-actions group with 2 updates ci: bump the github-actions group across 1 directory with 2 updates May 31, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/github-actions-37d7d335b6 branch from 8cbae67 to c16f009 Compare May 31, 2026 08:13
@dependabot @github

dependabot Bot commented on behalf of github Jun 21, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 21, 2026
@dependabot dependabot Bot deleted the dependabot/github_actions/github-actions-37d7d335b6 branch June 21, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants