Skip to content

ci: bump the github-actions group across 1 directory with 2 updates - #49

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-0d58bbbfe5
Open

ci: bump the github-actions group across 1 directory with 2 updates#49
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-0d58bbbfe5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates in the / directory: actions/checkout and julia-actions/cache.

Updates actions/checkout from 7.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates julia-actions/cache from 3.2.0 to 3.3.0

Release notes

Sourced from julia-actions/cache's releases.

v3.3.0

What's Changed

We migrated this action from JavaScript to TypeScript. Users should not notice any difference.

We also updated some dependencies.

Full Changelog

Full Changelog: julia-actions/cache@v3.2.0...v3.3.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by cubic

Update GitHub Actions dependencies to improve CI reliability and security. Previously actions/checkout v7.0.0 and julia-actions/cache v3.2.0 were used; now actions/checkout v7.0.1 and julia-actions/cache v3.3.0 are pinned. No workflow behavior changes are expected.

  • Touches .github/workflows/ci.yml, .github/workflows/codecov.yml, and .github/workflows/gpu-ci.yml to update pinned SHAs only; no step or input changes.
  • actions/checkout v7.0.1 includes small safety and robustness fixes (unsafe PR check default handling, ASCII whitespace trimming, unset value escaping).
  • julia-actions/cache v3.3.0 migrates to TypeScript with no functional changes.
  • Action: Verify CI, code coverage, and GPU jobs pass on this PR. No migration required.

Written for commit 8dda07e. Summary will update on new commits.

Review in cubic

Bumps the github-actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [julia-actions/cache](https://github.com/julia-actions/cache).


Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v7...3d3c42e)

Updates `julia-actions/cache` from 3.2.0 to 3.3.0
- [Release notes](https://github.com/julia-actions/cache/releases)
- [Commits](julia-actions/cache@b7788ab...a7bed9d)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: julia-actions/cache
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@codeant-ai

codeant-ai Bot commented Aug 18, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@codecov

codecov Bot commented Aug 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants