Skip to content

chore(deps): update github-actions dependencies - #37

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions-dependencies
Open

chore(deps): update github-actions dependencies#37
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github/codeql-action v4.37.6v4.37.9 age confidence
orhun/git-cliff-action v4.8.0v4.9.0 age confidence
pnpm/action-setup v6.0.10v6.1.0 age confidence
step-security/harden-runner v2.20.1v2.21.1 age confidence
zizmorcore/zizmor-action v0.6.2v0.6.3 age confidence

Release Notes

github/codeql-action (github/codeql-action)

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

orhun/git-cliff-action (orhun/git-cliff-action)

v4.9.0

Compare Source

[4.9.0] - 2026-09-01

🐛 Bug Fixes
  • Use BSD-compatible stat format on macOS (#​80)
  • (action) Terminate content output with a newline (#​81)
⚙️ Miscellaneous Tasks
  • (sync) Resolve github cli login (#​79)
  • Bump git-cliff to v2.14.1 (#​85)
pnpm/action-setup (pnpm/action-setup)

v6.1.0

Compare Source

What's Changed

Full Changelog: pnpm/action-setup@v6.0.10...v6.1.0

step-security/harden-runner (step-security/harden-runner)

v2.21.1

Compare Source

What's Changed

  • Improved performance of the disable-sudo feature.
  • Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode.
  • Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners.
  • Documentation updates: clarified which features are in the Community (free) vs Enterprise tier.

Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1

v2.21.0

Compare Source

What's Changed
  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0

zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.6.3

Compare Source

zizmor 1.30.0 is now the default version.

Release notes: https://docs.zizmor.sh/release-notes/#​1300


Configuration

📅 Schedule: (in timezone Asia/Kolkata)

  • Branch creation
    • "on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate labels Aug 31, 2026
@vercel

vercel Bot commented Aug 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
ask-widget Ignored Ignored Sep 5, 2026 8:39am UTC

@renovate
renovate Bot enabled auto-merge (squash) August 31, 2026 19:16
@renovate
renovate Bot force-pushed the renovate/github-actions-dependencies branch from 2f9ebc9 to b08db89 Compare September 1, 2026 15:54
@renovate
renovate Bot force-pushed the renovate/github-actions-dependencies branch from b08db89 to 85d5047 Compare September 5, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci area/maintenance dependencies Pull requests that update a dependency file renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants