Skip to content

build(deps): bump the github-actions group across 1 directory with 12 updates - #112

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-cadf4d99b2
Open

build(deps): bump the github-actions group across 1 directory with 12 updates#112
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-cadf4d99b2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown

Bumps the github-actions group with 12 updates in the / directory:

Package From To
actions/checkout 4 7
cloudflare/wrangler-action 3 4
step-security/harden-runner 2.19.4 2.20.0
fallow-rs/fallow 2.89.0 3.9.1
The-PR-Agent/pr-agent 0.36.0 0.40.0
Raftersecurity/rafter-cli 0.8.4 0.9.1
softprops/action-gh-release 3.0.0 3.0.2
ossf/scorecard-action 2.4.3 2.4.4
actions/upload-artifact 4 7
github/codeql-action 4.36.2 4.37.3
actions/setup-python 5 7
actions/cache 4 6

Updates actions/checkout from 4 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates cloudflare/wrangler-action from 3 to 4

Release notes

Sourced from cloudflare/wrangler-action's releases.

v4.0.0

Major Changes

  • #412 1029e90 Thanks @​ericclemmons! - Update default Wrangler version to v4 (latest). The action now installs Wrangler v4 by default when no wranglerVersion input is specified. Users can still pin to v3 by setting wranglerVersion: "3.90.0" explicitly.

v3.15.0

Minor Changes

  • #426 febbda6 Thanks @​WillTaylorDev! - Support version ranges and tags in wranglerVersion input. You can now set wranglerVersion to values like 4, ^4.0.0, 4.x, or latest instead of only exact versions like 4.81.0.

v3.14.1

Patch Changes

v3.14.0

Minor Changes

Patch Changes

v3.13.1

Patch Changes

v3.13.0

Minor Changes

v3.12.1

Patch Changes

v3.12.0

Minor Changes

  • #312 122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42 Thanks @​Maximo-Guk! - This reapplies 303 add parity with pages-action for pages deploy outputs. Thanks @​courtney-sims! - Support pages-deployment-id, pages-environment, pages-deployment-alias-url and deployment-url outputs for Pages deploys when wrangler version is >=3.81.0. deployment-alias-url was also deprecated in favour of pages-deployment-alias.

v3.11.0

Minor Changes

... (truncated)

Changelog

Sourced from cloudflare/wrangler-action's changelog.

Changelog

4.0.0

Major Changes

  • #412 1029e90 Thanks @​ericclemmons! - Update default Wrangler version to v4 (latest). The action now installs Wrangler v4 by default when no wranglerVersion input is specified. Users can still pin to v3 by setting wranglerVersion: "3.90.0" explicitly.

3.15.0

Minor Changes

  • #426 febbda6 Thanks @​WillTaylorDev! - Support version ranges and tags in wranglerVersion input. You can now set wranglerVersion to values like 4, ^4.0.0, 4.x, or latest instead of only exact versions like 4.81.0.

3.14.1

Patch Changes

3.14.0

Minor Changes

Patch Changes

3.13.1

Patch Changes

3.13.0

Minor Changes

3.12.1

Patch Changes

... (truncated)

Commits
  • ebbaa15 Automatic compilation
  • a61fbea Merge pull request #429 from cloudflare/changeset-release/main
  • e804ea3 Version Packages
  • 8d0324a fix: update release workflow to v5 actions and regenerate lockfile
  • 2f18b18 Merge pull request #431 from cloudflare/fix/semgrep-blocking-findings
  • 622ff0d fix: upgrade checkout and setup-node to v5 for Node 24 runtime
  • f501f05 fix: force GitHub actions to run on Node 24 via env var
  • f990691 fix: resolve npm audit vulnerabilities via undici override and vitest v3
  • 652762d fix: migrate action runtime from node20 to node24
  • bd3f4f0 fix: add retry support to worker health check using better-result
  • Additional commits viewable in compare view

Updates step-security/harden-runner from 2.19.4 to 2.20.0

Release notes

Sourced from step-security/harden-runner's releases.

v2.20.0

What's Changed

  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0

Commits
  • bf7454d Merge pull request #673 from step-security/fix/aggregate-error-startup-hang
  • 1188420 Update non-TLS agent to v0.16.2
  • 162cfea Update non-TLS agent to v0.16.1
  • eb9e1f4 Bring macOS runner updates from PR 674
  • 1a10b01 Update Windows agent to v1.0.7
  • 8b4a105 Apply npm audit fixes with release-age cooldown
  • 3626e03 Default TLS status check failures to enabled
  • 100e08b Update agent-ebpf to v1.8.12
  • 774f75f Update agent to v1.8.9
  • f312657 Extend missing-agent-dir guard to Linux and macOS cleanup paths
  • Additional commits viewable in compare view

Updates fallow-rs/fallow from 2.89.0 to 3.9.1

Release notes

Sourced from fallow-rs/fallow's releases.

v3.9.1: Impact statusline for agents

Fallow Impact in your status line

fallow impact statusline gives agent and editor chrome one compact, path-free line with the latest whole-project issue count, its trend, and findings cleared while Impact was tracking. It reads local history only, never runs analysis, migrates data, records telemetry, or prints normal CLI notices.

The Fallow plugin for Claude Code can compose this line with an existing status line. Codex and other agents can use the same stable command through the bundled Fallow skill.

Cloud runtime confidence

Cloud never_called evidence now keeps its provenance. Runtime-observed functions can retain the existing high-confidence deletion recommendation, while inventory-backed, missing, and future provenance remains conservative.

Full Changelog: fallow-rs/fallow@v3.8.1...v3.9.1

v3.8.1: trustworthy cloud runtime evidence

Cloud runtime evidence

fallow coverage analyze --cloud now preserves the server's actionability decision, evidence reason, verdict, production classification, freshness, staleness, and source-resolution quality.

When the active deployment has not collected enough isolated production evidence, the CLI keeps the result non-actionable instead of treating any tracked function as sufficient proof. Once the evidence floor is met, the cloud verdict and deployment provenance pass through unchanged. Older cloud responses retain the existing tracked-function fallback.

Full Changelog: fallow-rs/fallow@v3.8.0...v3.8.1

v3.8.0: interactive codebase map (fallow viz)

fallow viz: your codebase as an interactive map

fallow viz runs one analysis and writes a single self-contained HTML file (no server, no external assets) styled like the rest of fallow. It gives you two views over the same project:

  • Treemap of files sized by bytes, nested by directory.
  • Force-directed import graph with directory and import-community clustering.

Both views share four lenses that recolor the same map:

  • Dead code: unused files, unused exports, entry points.
  • Duplication: share of duplicated lines per file, with clone previews.
  • Boundaries: architecture zones from your boundaries config, with violating imports drawn in red.
  • Complexity hotspots: per-function cyclomatic and cognitive scores, including React context (hook counts, JSX depth).

Click any file to open a detail panel with the evidence behind each finding: unused export names, clone groups and their other locations, boundary crossings, cycle membership, importers and imports as click-through navigation, and a runnable fallow ... --trace command to verify the finding yourself.

Search, breadcrumb drill-down, keyboard shortcuts, shareable URL deep links, and dark/light themes are built in. Findings carry a hatch texture and [E]/[W] prefixes so color is never the only signal, and all motion honors prefers-reduced-motion.

fallow viz                    # opens the HTML report in your browser
</tr></table> 

... (truncated)

Changelog

Sourced from fallow-rs/fallow's changelog.

[3.9.1] - 2026-07-24

Added

  • fallow impact statusline exposes a compact, read-only Impact summary for agent status lines. It reports the latest whole-project issue count, its trend from the prior full scan, and the number of findings cleared while Impact was tracking. The single-line output is path-free, skips normal CLI notices and telemetry, and stays useful in narrow terminals. Legacy changed-file snapshots remain visible but are explicitly labelled and never produce a misleading project-wide trend. (#2000)

Fixed

  • Cloud never_called evidence now keeps its confidence provenance. Runtime-observed functions can retain the existing high-confidence deletion recommendation, while inventory-backed, missing, and future provenance stays conservative.

[3.8.1] - 2026-07-23

Fixed

  • Cloud runtime analysis now preserves the server's evidence floor and provenance. fallow coverage analyze --cloud previously treated any tracked function as actionable, even when fallow.cloud explicitly reported that the active deployment had not collected enough isolated runtime observations. The CLI now carries through the cloud's actionability verdict, reason, production classification, freshness, staleness, and source-resolution quality. Older cloud responses keep the existing tracked-function fallback.

[3.8.0] - 2026-07-22

Added

  • fallow viz renders your codebase as an interactive map. A new command that runs one project analysis and writes a single self-contained HTML file (no server, no external assets) styled like the rest of fallow: a nested treemap of files sized by bytes, plus a force-directed import graph with directory and import-community clustering. Both views share four lenses that recolor the same map: dead code (unused files, unused exports, entry points), duplication (share of duplicated lines per file, with clone previews), boundaries (architecture zones from your boundaries config, with violating imports drawn in red), and complexity hotspots (per-function cyclomatic and cognitive scores, including React context such as hook counts and JSX depth). Clicking any file opens a detail panel with the evidence: unused export names, clone groups and their other locations, boundary crossings, cycle membership, importers and imports as click-through navigation, and a runnable fallow ... --trace command to verify each finding. Search, breadcrumb drill-down, keyboard shortcuts, shareable URL deep links, and dark/light themes are built in; findings carry a hatch texture and [E]/[W] prefixes so color is never the only signal, and all motion honors prefers-reduced-motion. The HTML opens in your browser by default (--no-open to skip, --out <path> to choose the file); --viz-format dot and --viz-format mermaid emit the import graph as text for piping into other tools. Read-only, and respects --production, --config, and --no-cache like the analysis commands.

Fixed

  • Next.js fallback metadata exports are no longer reported as unused. App Router not-found, default, forbidden, unauthorized, and experimental global-not-found files now credit metadata, generateMetadata, viewport, and generateViewport, matching the modules Next.js reads while resolving fallback head content. Arbitrary helper and route segment config exports remain reportable. Thanks @​BartWaardenburg for the report. (Closes #1987.)

  • Audit and dead-code results stay accurate across deeper class hierarchies and materialized project context. Multi-hop generic inheritance and

... (truncated)

Commits
  • 3f6d4a5 chore: release v3.9.1
  • b9f6515 chore: release v3.9.0
  • 3925887 docs: complete unreleased changelog
  • 77d56bb fix: keep Impact statusline epilogue-free
  • 88f297a docs: expose Impact statusline to agents
  • fad562d feat: add Impact statusline output
  • 27ab1fc chore: open impact statusline implementation branch
  • ddbdaa9 docs: harden maintainer knowledge architecture
  • fbe63e3 docs: establish portable knowledge architecture
  • 46297d2 chore: refresh vendored Fallow skill
  • Additional commits viewable in compare view

Updates The-PR-Agent/pr-agent from 0.36.0 to 0.40.0

Release notes

Sourced from The-PR-Agent/pr-agent's releases.

v0.40.0

[!NOTE] v0.40.0 isn't on PyPI yet. We're working on getting it published and will update this note as soon as it lands. In the meantime, pip install pr-agent==0.40.0 won't resolve — use one of these instead:

Docker — images for 0.40.0 are available now:

docker pull pragent/pr-agent:0.40.0                  # CLI
docker pull pragent/pr-agent:0.40.0-github_app       # per-target images use the same -<target> suffix

Install from source at the tag:

pip install "git+https://github.com/The-PR-Agent/pr-agent.git@v0.40.0"

This installs the v0.40.0 code, though it currently self-reports 0.39.0.

Or stay on pr-agent==0.39.0 until we confirm here that 0.40.0 is available.

What's Changed

🚀 Features

🐛 Bug Fixes

  • fix(gerrit): prevent path traversal in publish_code_suggestions by @​gvago in #2314
  • fix(litellm): flush deferred callbacks before the event loop closes by @​naorpeled in #2551
  • fix(litellm): stop the placeholder key from shadowing provider env vars by @​naorpeled in #2548
  • fix(servers): cap gunicorn workers and preload the app to stop OOMKills by @​naorpeled in #2550
  • fix(gitlab): preserve user-added labels by @​ashearin in #2484
  • fix(litellm): raise on empty content from non-streaming models by @​AmirF194 in #2542
  • fix(gitlab): allow overriding is_bot_user indicators by @​ashearin in #2528
  • fix(local): return language names from get_languages() by @​naorpeled in #2519
  • Honor reasoning_effort for Gemini 2.5 (and provider-prefixed reasoning models) by @​mpj in #2520
  • AI: fix(gitea): allow description updates without titles by @​brlin-tw in #2526

📚 Documentation

  • docs(tools): add consolidated usage examples for all tools by @​naorpeled in #2547
  • docs: Fix Dockerfile path in gitea installation instructions by @​brlin-tw in #2524
  • docs: add pull_request_target guide for fork contribution support by @​utsab345 in #2501

🧹 Maintenance

... (truncated)

Commits
  • 6ad7cf7 fix(litellm): flush deferred callbacks before the event loop closes (#2551)
  • 8da311d fix(gerrit): prevent path traversal in publish_code_suggestions (#2314)
  • 5bde2e3 fix(litellm): stop the placeholder key from shadowing provider env vars (#2548)
  • 4d5b6ee fix(servers): cap gunicorn workers and preload the app to stop OOMKills (#2550)
  • 8792c48 fix(gitlab): preserve user-added labels (#2484)
  • 6065794 test(github): fix build-and-test failure from _dedup_code_fp payload key (#2549)
  • c390d6c docs(tools): add consolidated usage examples for all tools (#2547)
  • f09a8f1 feat(config): update default model to OpenAI's GPT-5.6 (#2535)
  • e6429e6 feat: persistent inline comments to prevent cross-run duplicates (#2424)
  • 2ab06df fix(litellm): raise on empty content from non-streaming models (#2542)
  • Additional commits viewable in compare view

Updates Raftersecurity/rafter-cli from 0.8.4 to 0.9.1

Release notes

Sourced from Raftersecurity/rafter-cli's releases.

v0.9.1

Installation

Node.js:

npm install -g @rafter-security/cli@0.9.1

Python:

pip install rafter-cli==0.9.1

OpenClaw (via ClawHub):

clawhub skill install rafter-security

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: Raftersecurity/rafter-cli@v0.9.0...v0.9.1

v0.9.0

Installation

Node.js:

npm install -g @rafter-security/cli@0.9.0

... (truncated)

Changelog

Sourced from Raftersecurity/rafter-cli's changelog.

[0.9.1] - 2026-07-21

Added

  • Opt-in approval gate for paid Plus scans (sable-9ddf). New scan.plus_requires_approval config flag (.rafter.yml or global ~/.rafter/config.json), off by default so existing behavior is unchanged. When enabled, rafter run --mode plus (and the rafter scan / rafter scan remote aliases) requires explicit confirmation before spending credits: it prompts [y/N] on a TTY and refuses in a non-interactive/agent context with new exit code 5 unless --yes (-y) or RAFTER_CONFIRM=1 is passed. Fast scans are never gated. Precedence is additive (OR) — a project .rafter.yml can turn the gate on but can never turn off a gate the machine owner enabled globally, so a hostile repo can't silently re-open the credit-burn hole. The rafter agent skill and injected instruction block now tell agents Plus is a paid tier and to ask the user before running it. Node + Python, tests in both suites. Addresses an external user whose agent auto-ran a Plus scan and consumed credits without asking.
  • SendGrid API Key secret pattern (#24). New SG\.[a-zA-Z0-9_-]{22}\.[a-zA-Z0-9_-]{43} detection pattern (severity critical) added to the built-in regex scanner in both Node and Python, with tests in each suite. Thanks to @​perez-eduardo for the contribution.

[0.9.0] - 2026-07-08

Added

  • Native OpenCode support (sable-l8e5). rafter agent init --with-opencode registers the Rafter MCP server in OpenCode's config (~/.config/opencode/opencode.json, mcp block with type: "local"), and OpenCode is auto-detected on init. First-class platform support now spans 10 agents. Node + Python parity, with a recipes/opencode.md guide.
  • Multi-provider remote scan (sable-w79q). rafter run now infers the git remote's provider — GitLab, Gitea (codeberg.org / *.gitea.io), and Bitbucket, in addition to GitHub — and sends an additive provider + repo_url in the scan request. New optional --provider / --repo-url overrides. Fully backward-compatible: GitHub scans send a byte-identical request (no new fields). Non-GitHub scanning additionally depends on backend rollout.
  • DigitalOcean Personal Access Token secret pattern (#26, #189). New dop_v1_[a-f0-9]{64} detection pattern (severity critical) added to the built-in regex scanner in both Node and Python, with tests in each suite. Thanks to @​Minh-Nguyen-2k7 for the contribution.

[0.8.10] - 2026-06-28

Changed

  • Claude Code PostToolUse hook matcher narrowed from .* to Bash|Write|Edit|MultiEdit (Node + Python, sable-h0ah). rafter agent init --with-claude-code (and rafter agent enable claude-code.hooks) previously registered the rafter hook posttool redaction hook with a catch-all .* matcher, so it fired after every Claude Code tool call — including Read and MCP tools, which never produce secrets to redact — adding latency to every operation. The matcher now targets only the tools whose output is worth scanning: shell output (Bash) and file writes (Write/Edit/MultiEdit). PreToolUse matchers are unchanged. Codex (.* PostToolUse) and Gemini (.* AfterTool) have the same broad-matcher latency issue and are tracked separately for platform-correct narrow matchers.

Fixed

  • Hooks tolerate harness-appended flags (#180). rafter hook pretool / posttool read their input from stdin, so they now ignore unknown options and extra positional arguments that an agent platform appends to the hook command — e.g. Claude Code adds --hook-json <data>. Such extras are discarded rather than erroring; declared options like --format are still parsed normally.

Security

  • Dependency CVE updates (sable-qsig). Bumped vulnerable (mostly transitive) dependencies past their fixed versions via pnpm workspace overrides + a re-lock: axios 1.13.6→1.18.1, hono 4.12.8→4.12.27, tar→7.5.17, js-yaml→4.3.0, plus fast-uri, path-to-regexp, form-data, follow-redirects, ip-address, qs, and brace-expansion. Python direct-dep floors raised (requests, urllib3, python-dotenv); transitive Python bumps tracked separately. No CLI behavior change.
  • Hardened remote-skill tarball extraction (sable-qsig). rafter skill review / install now extracts only regular files and directories from a fetched npm tarball, skipping symlink/hardlink/device members that a malicious archive could use to redirect a later write outside the destination — defense-in-depth atop the existing zip-slip path check.

[0.8.9] - 2026-06-20

Added

  • Opt-in --deep skill-review engine (sable-7g7). rafter skill review <path|dir|github:/gitlab:/npm:|--installed> --deep (alias --engine skill-scanner) couples Cisco AI Defense's skill-scanner as a deeper pass — prompt injection, taint/dataflow exfiltration, YARA, and .pyc integrity — the blind spots the deterministic quick scan structurally cannot see. Couple, not swap: the zero-dependency quick scan stays the default; deep results attach a deepScan block (top-level for a single skill, per-skill for multi-skill / --installed), and only critical/high/medium deep findings are actionable (escalate severity + flip the exit code). Offline analyzers only — the argv never enables --use-llm/--use-virustotal/--use-aidefense/--use-behavioral, enforced by a FORBIDDEN_FLAGS test in both runtimes, so a regression that turns on a network analyzer fails CI. The engine is a heavy third-party package and is not bundled: the first --deep run offers to install it interactively (isolated, version-pinned uv tool install, pip --user fallback), or set it up ahead of time with rafter agent update-skill-scanner / rafter agent init --with-skill-scanner, and remove it with rafter agent remove-skill-scanner. Node + Python parity (both shell out to the same external CLI and parse identical JSON, mirroring the betterleaks pattern). rafter agent audit-skill --deep remains as a deprecated back-compat alias. Security-reviewed: list-form subprocess (no shell), version-pinned installer, untrusted skill paths passed as single argv elements.

Fixed

  • Hardened RAFTER_API_KEY handling (sable-q9to). Three credential gaps closed across Node + Python: (1) ~/.rafter/config.json is now written 0600 (dir 0700) and an existing looser-perm file is tightened on the next write; (2) config show/get/set, the MCP get_config tool, and the rafter://config / rafter://policy resources now redact values under credential-named keys (api_?key|token|secret|password|credentialabcd****) at every render path — the stored config is never mutated; (3) a key persisted via rafter agent config set backend.apiKey is now read as the lowest-precedence source (--api-key flag > RAFTER_API_KEY env > global config). Trust boundary verified: the config fallback is read only from the global config (getload, never loadWithPolicyDescription has been truncated

… updates

Bumps the github-actions group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |
| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `3` | `4` |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.4` | `2.20.0` |
| [fallow-rs/fallow](https://github.com/fallow-rs/fallow) | `2.89.0` | `3.9.1` |
| [The-PR-Agent/pr-agent](https://github.com/the-pr-agent/pr-agent) | `0.36.0` | `0.40.0` |
| [Raftersecurity/rafter-cli](https://github.com/raftersecurity/rafter-cli) | `0.8.4` | `0.9.1` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.0` | `3.0.2` |
| [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.3` | `2.4.4` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` |
| [github/codeql-action](https://github.com/github/codeql-action) | `4.36.2` | `4.37.3` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` |
| [actions/cache](https://github.com/actions/cache) | `4` | `6` |



Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

Updates `cloudflare/wrangler-action` from 3 to 4
- [Release notes](https://github.com/cloudflare/wrangler-action/releases)
- [Changelog](https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md)
- [Commits](cloudflare/wrangler-action@v3...v4)

Updates `step-security/harden-runner` from 2.19.4 to 2.20.0
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@v2.19.4...v2.20.0)

Updates `fallow-rs/fallow` from 2.89.0 to 3.9.1
- [Release notes](https://github.com/fallow-rs/fallow/releases)
- [Changelog](https://github.com/fallow-rs/fallow/blob/main/CHANGELOG.md)
- [Commits](fallow-rs/fallow@v2.89.0...v3.9.1)

Updates `The-PR-Agent/pr-agent` from 0.36.0 to 0.40.0
- [Release notes](https://github.com/the-pr-agent/pr-agent/releases)
- [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md)
- [Commits](The-PR-Agent/pr-agent@v0.36.0...v0.40.0)

Updates `Raftersecurity/rafter-cli` from 0.8.4 to 0.9.1
- [Release notes](https://github.com/raftersecurity/rafter-cli/releases)
- [Changelog](https://github.com/Raftersecurity/rafter-cli/blob/main/CHANGELOG.md)
- [Commits](Raftersecurity/rafter-cli@v0.8.4...v0.9.1)

Updates `softprops/action-gh-release` from 3.0.0 to 3.0.2
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v3.0.0...v3.0.2)

Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@v2.4.3...v2.4.4)

Updates `actions/upload-artifact` from 4 to 7
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

Updates `github/codeql-action` from 4.36.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.36.2...v4.37.3)

Updates `actions/setup-python` from 5 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

Updates `actions/cache` from 4 to 6
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: cloudflare/wrangler-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: step-security/harden-runner
  dependency-version: 2.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: fallow-rs/fallow
  dependency-version: 3.9.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: The-PR-Agent/pr-agent
  dependency-version: 0.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: Raftersecurity/rafter-cli
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: github/codeql-action
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants